全面审查优化: 43项修复(安全/性能/可靠性)+ 文档更新

🔴 P0 安全: .env入gitignore, CSP/HSTS, Logo安全(5MB限制+SVG消毒+SHA256), middleware权限收紧(VIP不能访问admin), 发布去重, GitHub认证, 删除危险API, skill-discoverer绕过审核修复, prisma默认连接修复
🔴 P0 可靠性: deepseek/github超时重试, 脚本层DeepSeek保护, 脚本启动验证, OAuth竞态修复
🔴 P0 性能: skill-discoverer N+1优化(↓94%), 后台API分页限制, getUserStats聚合优化
🟡 P1: 分类动态加载, 星级字段统一, fetch-logos并发Bug修复, 批量发布冲突不删除, check-tools重试, 前端空指针修复(13处), logo-fetcher日志, rate-limit清理, 公开API缓存
This commit is contained in:
ZhuiGuangAI Dev
2026-05-26 00:30:36 +08:00
parent 9bf3e7574a
commit e263e28c81
47 changed files with 1212 additions and 788 deletions
+10 -9
View File
@@ -96,7 +96,7 @@ async function getConfig(): Promise<LogoFetchConfig> {
if (row?.value && typeof row.value === "object") {
return { ...DEFAULT_CONFIG, ...(row.value as Partial<LogoFetchConfig>) };
}
} catch { /* */ }
} catch (err) { console.warn("logo-fetcher: Failed to load logoFetchConfig from database, using defaults", err); }
return DEFAULT_CONFIG;
}
@@ -129,7 +129,7 @@ async function checkImageUrl(url: string, timeout: number, minSize: number): Pro
}
}
}
} catch { /* */ }
} catch (err) { console.warn("logo-fetcher: Failed to check image URL", err); }
return "";
}
@@ -160,7 +160,7 @@ async function fetchManifestIcons(origin: string, html: string, timeout: number,
manifestHref = `${origin}${candidate}`;
break;
}
} catch { /* */ }
} catch (err) { console.warn("logo-fetcher: Failed to probe manifest candidate path", err); }
}
}
@@ -188,7 +188,7 @@ async function fetchManifestIcons(origin: string, html: string, timeout: number,
if (valid) return valid;
}
}
} catch { /* */ }
} catch (err) { console.warn("logo-fetcher: Failed to fetch manifest icons", err); }
return "";
}
@@ -258,7 +258,7 @@ async function fetchSvgLogo(origin: string, html: string, timeout: number, minSi
}
}
}
} catch { /* */ }
} catch (err) { console.warn("logo-fetcher: Failed to fetch SVG logo candidate", err); }
}
return "";
@@ -329,7 +329,7 @@ async function fetchBrandfetch(domain: string, timeout: number): Promise<string>
if (best?.src) return best.src;
}
}
} catch { /* */ }
} catch (err) { console.warn("logo-fetcher: Failed to fetch brand from Brandfetch", err); }
return "";
}
@@ -361,7 +361,7 @@ async function fetchScreenshotFallback(domain: string, timeout: number): Promise
}
}
}
} catch { /* */ }
} catch (err) { console.warn("logo-fetcher: Failed to fetch screenshot fallback", err); }
}
return "";
@@ -559,7 +559,7 @@ export async function fetchLogoWithMethod(websiteUrl: string, html?: string): Pr
return { url: valid, method: `Favicon服务(${svc.name})` };
}
}
} catch { /* */ }
} catch (err) { console.warn("logo-fetcher: Failed to fetch favicon from service", err); }
}
}
@@ -588,7 +588,8 @@ export async function fetchLogoWithMethod(websiteUrl: string, html?: string): Pr
setCachedLogo(domain, "");
return { url: "", method: "" };
} catch {
} catch (err) {
console.warn("logo-fetcher: Failed to fetch logo for URL", err);
return { url: "", method: "" };
}
}