[优化] 更换 JWT 认证机制

This commit is contained in:
ryan
2026-06-04 11:30:44 +08:00
parent 3dbc7b3045
commit 161e6c4e86
20 changed files with 629 additions and 76 deletions
+1 -1
View File
@@ -54,7 +54,7 @@ services:
ports:
- "3000:3000"
environment:
SESSION_SECRET: replace-with-a-long-random-string
JWT_SECRET: replace-with-a-long-random-string
DSN: postgres://openflare:replace-with-strong-password@postgres:5432/openflare?sslmode=disable
GIN_MODE: release
LOG_LEVEL: info
+1 -1
View File
@@ -164,7 +164,7 @@ WAF 规则组、网站绑定或 PoW 配置修改后,需要重新发布并激
## 推荐实践
* 生产环境显式配置 `SESSION_SECRET`,并优先使用 PostgreSQL。
* 生产环境必须显式配置 `JWT_SECRET`,并优先使用 PostgreSQL。
* 修改网站配置后先看预览或 diff,再发布。
* 每次发布后检查节点详情与应用记录。
* 多节点部署时保持 Agent 到 Server 的网络路径稳定。