mirror of
https://github.com/truewhile/MeBox.git
synced 2026-10-01 12:06:38 +08:00
优化,排查项目问题
This commit is contained in:
@@ -51,6 +51,19 @@ func EmbyAuthRequired(secret string) gin.HandlerFunc {
|
||||
return
|
||||
}
|
||||
|
||||
// 用途限定令牌(如 external_play,签发给外链播放器且绑定单一
|
||||
// media)只允许走 /api/stream|/hls|/cloud/play,绝不能作为全功能
|
||||
// 凭据访问 Emby 兼容面;否则外链 URL 一旦泄漏,持有者可获得
|
||||
// 该用户最长 24h 的全部 Emby API 权限。
|
||||
if strings.TrimSpace(claims.Purpose) != "" {
|
||||
c.JSON(http.StatusUnauthorized, gin.H{
|
||||
"Code": 40101,
|
||||
"Message": "Invalid token",
|
||||
})
|
||||
c.Abort()
|
||||
return
|
||||
}
|
||||
|
||||
c.Set(EmbyCtxUserID, claims.UserID)
|
||||
c.Set(CtxUserID, claims.UserID)
|
||||
c.Set(CtxUserRole, claims.Role)
|
||||
|
||||
@@ -16,6 +16,8 @@ type RateLimiter struct {
|
||||
window time.Duration
|
||||
max int
|
||||
requests map[string][]time.Time
|
||||
stop chan struct{}
|
||||
stopped sync.Once
|
||||
}
|
||||
|
||||
// NewRateLimiter creates a rate limiter allowing max requests per window
|
||||
@@ -25,14 +27,27 @@ func NewRateLimiter(max int, window time.Duration) *RateLimiter {
|
||||
window: window,
|
||||
max: max,
|
||||
requests: make(map[string][]time.Time),
|
||||
stop: make(chan struct{}),
|
||||
}
|
||||
go rl.cleanup()
|
||||
return rl
|
||||
}
|
||||
|
||||
// Close 停止后台清理 goroutine:清理循环此前无停止机制,每建一个实例
|
||||
// 就永久滞留一条 goroutine(测试场景会随实例创建不断累积)。
|
||||
func (rl *RateLimiter) Close() {
|
||||
rl.stopped.Do(func() { close(rl.stop) })
|
||||
}
|
||||
|
||||
func (rl *RateLimiter) cleanup() {
|
||||
ticker := time.NewTicker(5 * time.Minute)
|
||||
defer ticker.Stop()
|
||||
for {
|
||||
time.Sleep(5 * time.Minute)
|
||||
select {
|
||||
case <-rl.stop:
|
||||
return
|
||||
case <-ticker.C:
|
||||
}
|
||||
rl.mu.Lock()
|
||||
now := time.Now()
|
||||
for ip, times := range rl.requests {
|
||||
|
||||
Reference in New Issue
Block a user