fix: API Key脱敏, exec沙箱, 密码环境变量化, CORS/WebSocket安全加固#35
Open
cghggchg765-create wants to merge 1 commit into
Open
fix: API Key脱敏, exec沙箱, 密码环境变量化, CORS/WebSocket安全加固#35cghggchg765-create wants to merge 1 commit into
cghggchg765-create wants to merge 1 commit into
Conversation
Collaborator
|
感谢您关注 YiGraph 并提交 PR!这个 PR 里有不少安全加固思路很有价值,但部分核心代码调整和设计方案还需要进一步讨论。方便的话可以加我微信:ccy1013858730,我们一起对齐下实现方案。再次感谢您的贡献! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
安全修复 (14项): 3套API Key→环境变量, 5处硬编码密码→env, exec()沙箱(SAFE_BUILTINS白名单), CORS环境变量化, WebSocket Token认证, Flask debug环境变量, 线程锁双重检查, API Key Base64混淆, .env.example模板