Task 1.1 疏漏:只更新了 AGENTS.md,漏了 .env.example。补上本次 review 引入及 原先缺失的 security 变量: - APP_BASE_URL(CSRF 校验的可信 origin,1.1 引入) - STATEMENT_TIMEOUT_SECS(慢查询超时,2.4 引入) - COOKIE_SECURE / TRUSTED_PROXY_COUNT(原先就缺,一并补全)
61 lines
2.5 KiB
Plaintext
61 lines
2.5 KiB
Plaintext
DATABASE_URL=postgres://postgres:postgres@localhost:5432/yggdrasil
|
||
RUST_LOG=info
|
||
|
||
# Rate Limit — 严格限流(登录、注册)
|
||
RATE_LIMIT_STRICT_PER_SEC=1
|
||
RATE_LIMIT_STRICT_BURST=5
|
||
# Rate Limit — 上传限流(图片上传)
|
||
RATE_LIMIT_UPLOAD_PER_SEC=2
|
||
RATE_LIMIT_UPLOAD_BURST=15
|
||
# Rate Limit — 图片访问限流(/uploads/*)
|
||
RATE_LIMIT_IMAGE_PER_SEC=10
|
||
RATE_LIMIT_IMAGE_BURST=50
|
||
|
||
# Security
|
||
# Trusted origin for CSRF checks on write requests (POST/PUT/PATCH/DELETE).
|
||
# Set to your production origin, e.g. https://your-domain.example.
|
||
# Unset: falls back to the request Host header + X-Forwarded-Proto (behind a reverse proxy).
|
||
APP_BASE_URL=
|
||
# Set true/1/yes to add the Secure flag to the session cookie (enable in HTTPS production).
|
||
COOKIE_SECURE=false
|
||
# Number of reverse proxies in front of the app; used to extract the real client IP
|
||
# from X-Forwarded-For. 0 when serving directly; 1 behind one proxy (e.g. nginx/Caddy).
|
||
TRUSTED_PROXY_COUNT=0
|
||
# Per-query timeout in seconds; slow queries are canceled to protect the connection pool.
|
||
STATEMENT_TIMEOUT_SECS=30
|
||
|
||
# WebP encoding configuration
|
||
# Quality: 0.0 (smallest) to 100.0 (best), default 85.0
|
||
WEBP_QUALITY=85.0
|
||
# Method: 0 (fastest) to 6 (best quality), default 2
|
||
WEBP_METHOD=2
|
||
|
||
# Maximum concurrent sessions per user (default: 5, minimum: 1)
|
||
MAX_SESSIONS_PER_USER=5
|
||
|
||
# Database connection pool size (default: 20)
|
||
DB_POOL_SIZE=20
|
||
|
||
# SSR page cache duration in seconds (default: 3600).
|
||
# src/ssr_cache.rs maintains a global generation counter bumped on every post write, but
|
||
# Dioxus 0.7 does not expose an API to wire it into the incremental SSR cache key. Until such
|
||
# an API is available, this TTL is the only effective SSR cache invalidation mechanism.
|
||
SSR_CACHE_SECS=3600
|
||
|
||
# Compression algorithms for HTTP responses.
|
||
# Comma-separated list, case-insensitive. Supported: gzip, brotli (or br), deflate, zstd.
|
||
# Use "all" to enable everything (default when unset); use "none" or "off" to disable.
|
||
COMPRESSION_ALGORITHMS=gzip,brotli,deflate,zstd
|
||
|
||
# Image serving cache headers (hardcoded defaults)
|
||
# Uploaded image assets are served with Cache-Control: public, max-age=31536000, immutable.
|
||
# Processed variants (?w=, ?format=, etc.) are cached for 24 hours.
|
||
# To invalidate a cached raw upload, change its file path.
|
||
# To refresh a processed variant, change its processing parameters.
|
||
|
||
# Image disk cache limits
|
||
# Max total size in MB (default: 1024)
|
||
IMAGE_DISK_CACHE_MAX_MB=1024
|
||
# Max file age in hours before forced deletion (default: 168)
|
||
IMAGE_DISK_CACHE_MAX_AGE_HOURS=168
|