mirror of
https://github.com/truewhile/MeBox.git
synced 2026-10-02 12:26:36 +08:00
feat: verify license responses with public key
This commit is contained in:
@@ -25,7 +25,7 @@ const (
|
||||
defaultDatabaseMaxOpenConns = 4
|
||||
defaultDatabaseMaxIdleConns = 2
|
||||
defaultLicenseServerURL = "https://mgosever.3jzs.com"
|
||||
defaultLicenseHMACSecret = "ms-shared-hmac-secret-key-Mgo-testing" // #nosec G101 -- shared response-signature key for the bundled license bridge.
|
||||
defaultLicensePublicKey = "MCowBQYDK2VwAyEABRXnXy+urjrbKit6Yu/HiezWgP0NdsZW3tsegJWRrtI="
|
||||
)
|
||||
|
||||
// Config 是根配置聚合。
|
||||
@@ -172,6 +172,7 @@ type AIConfig struct {
|
||||
type LicenseConfig struct {
|
||||
ServerURL string `mapstructure:"server_url"`
|
||||
HMACSecret string `mapstructure:"hmac_secret"`
|
||||
PublicKey string `mapstructure:"public_key"`
|
||||
}
|
||||
|
||||
// OrganizerConfig 配置媒体文件智能分类整理。
|
||||
@@ -333,7 +334,8 @@ func setDefaults(v *viper.Viper) {
|
||||
v.SetDefault("api_config.default_timeout", 30)
|
||||
|
||||
v.SetDefault("license.server_url", defaultLicenseServerURL)
|
||||
v.SetDefault("license.hmac_secret", defaultLicenseHMACSecret)
|
||||
v.SetDefault("license.hmac_secret", "")
|
||||
v.SetDefault("license.public_key", defaultLicensePublicKey)
|
||||
}
|
||||
|
||||
// normalize 填充派生默认值并自愈空的关键字段。
|
||||
|
||||
@@ -58,8 +58,8 @@ func TestLoadDefaults(t *testing.T) {
|
||||
if !cfg.Organizer.SmartClassify {
|
||||
t.Fatalf("expected organizer smart classify enabled by default")
|
||||
}
|
||||
if cfg.License.ServerURL != defaultLicenseServerURL || cfg.License.HMACSecret != defaultLicenseHMACSecret {
|
||||
t.Fatalf("expected bundled license bridge defaults, got url=%q secret=%q", cfg.License.ServerURL, cfg.License.HMACSecret)
|
||||
if cfg.License.ServerURL != defaultLicenseServerURL || cfg.License.PublicKey != defaultLicensePublicKey || cfg.License.HMACSecret != "" {
|
||||
t.Fatalf("expected bundled license bridge defaults, got url=%q public_key=%q hmac=%q", cfg.License.ServerURL, cfg.License.PublicKey, cfg.License.HMACSecret)
|
||||
}
|
||||
// Re-loading must reuse the persisted secret on disk.
|
||||
cfg2, err := Load()
|
||||
@@ -92,6 +92,7 @@ func TestEnvOverride(t *testing.T) {
|
||||
t.Setenv("MEDIASTATION_SEARCH_OPENSEARCH_URL", "http://opensearch:9200")
|
||||
t.Setenv("MEDIASTATION_LICENSE_SERVER_URL", "https://license.example.com")
|
||||
t.Setenv("MEDIASTATION_LICENSE_HMAC_SECRET", "override-secret")
|
||||
t.Setenv("MEDIASTATION_LICENSE_PUBLIC_KEY", "override-public-key")
|
||||
cfg, err := Load()
|
||||
if err != nil {
|
||||
t.Fatalf("Load() error: %v", err)
|
||||
@@ -108,8 +109,8 @@ func TestEnvOverride(t *testing.T) {
|
||||
if cfg.Search.Backend != "opensearch" || cfg.Search.OpenSearchURL != "http://opensearch:9200" {
|
||||
t.Fatalf("expected opensearch config from env, got backend=%q url=%q", cfg.Search.Backend, cfg.Search.OpenSearchURL)
|
||||
}
|
||||
if cfg.License.ServerURL != "https://license.example.com" || cfg.License.HMACSecret != "override-secret" {
|
||||
t.Fatalf("expected license config from env, got url=%q secret=%q", cfg.License.ServerURL, cfg.License.HMACSecret)
|
||||
if cfg.License.ServerURL != "https://license.example.com" || cfg.License.HMACSecret != "override-secret" || cfg.License.PublicKey != "override-public-key" {
|
||||
t.Fatalf("expected license config from env, got url=%q secret=%q public_key=%q", cfg.License.ServerURL, cfg.License.HMACSecret, cfg.License.PublicKey)
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user