feat: verify license responses with public key

This commit is contained in:
ShukeBta
2026-06-25 14:46:28 +08:00
parent a4a93b7fed
commit 0da96f7e4e
12 changed files with 200 additions and 44 deletions
+4 -2
View File
@@ -25,7 +25,7 @@ const (
defaultDatabaseMaxOpenConns = 4
defaultDatabaseMaxIdleConns = 2
defaultLicenseServerURL = "https://mgosever.3jzs.com"
defaultLicenseHMACSecret = "ms-shared-hmac-secret-key-Mgo-testing" // #nosec G101 -- shared response-signature key for the bundled license bridge.
defaultLicensePublicKey = "MCowBQYDK2VwAyEABRXnXy+urjrbKit6Yu/HiezWgP0NdsZW3tsegJWRrtI="
)
// Config 是根配置聚合。
@@ -172,6 +172,7 @@ type AIConfig struct {
type LicenseConfig struct {
ServerURL string `mapstructure:"server_url"`
HMACSecret string `mapstructure:"hmac_secret"`
PublicKey string `mapstructure:"public_key"`
}
// OrganizerConfig 配置媒体文件智能分类整理。
@@ -333,7 +334,8 @@ func setDefaults(v *viper.Viper) {
v.SetDefault("api_config.default_timeout", 30)
v.SetDefault("license.server_url", defaultLicenseServerURL)
v.SetDefault("license.hmac_secret", defaultLicenseHMACSecret)
v.SetDefault("license.hmac_secret", "")
v.SetDefault("license.public_key", defaultLicensePublicKey)
}
// normalize 填充派生默认值并自愈空的关键字段。
+5 -4
View File
@@ -58,8 +58,8 @@ func TestLoadDefaults(t *testing.T) {
if !cfg.Organizer.SmartClassify {
t.Fatalf("expected organizer smart classify enabled by default")
}
if cfg.License.ServerURL != defaultLicenseServerURL || cfg.License.HMACSecret != defaultLicenseHMACSecret {
t.Fatalf("expected bundled license bridge defaults, got url=%q secret=%q", cfg.License.ServerURL, cfg.License.HMACSecret)
if cfg.License.ServerURL != defaultLicenseServerURL || cfg.License.PublicKey != defaultLicensePublicKey || cfg.License.HMACSecret != "" {
t.Fatalf("expected bundled license bridge defaults, got url=%q public_key=%q hmac=%q", cfg.License.ServerURL, cfg.License.PublicKey, cfg.License.HMACSecret)
}
// Re-loading must reuse the persisted secret on disk.
cfg2, err := Load()
@@ -92,6 +92,7 @@ func TestEnvOverride(t *testing.T) {
t.Setenv("MEDIASTATION_SEARCH_OPENSEARCH_URL", "http://opensearch:9200")
t.Setenv("MEDIASTATION_LICENSE_SERVER_URL", "https://license.example.com")
t.Setenv("MEDIASTATION_LICENSE_HMAC_SECRET", "override-secret")
t.Setenv("MEDIASTATION_LICENSE_PUBLIC_KEY", "override-public-key")
cfg, err := Load()
if err != nil {
t.Fatalf("Load() error: %v", err)
@@ -108,8 +109,8 @@ func TestEnvOverride(t *testing.T) {
if cfg.Search.Backend != "opensearch" || cfg.Search.OpenSearchURL != "http://opensearch:9200" {
t.Fatalf("expected opensearch config from env, got backend=%q url=%q", cfg.Search.Backend, cfg.Search.OpenSearchURL)
}
if cfg.License.ServerURL != "https://license.example.com" || cfg.License.HMACSecret != "override-secret" {
t.Fatalf("expected license config from env, got url=%q secret=%q", cfg.License.ServerURL, cfg.License.HMACSecret)
if cfg.License.ServerURL != "https://license.example.com" || cfg.License.HMACSecret != "override-secret" || cfg.License.PublicKey != "override-public-key" {
t.Fatalf("expected license config from env, got url=%q secret=%q public_key=%q", cfg.License.ServerURL, cfg.License.HMACSecret, cfg.License.PublicKey)
}
}