- admin.py:HTTP Basic Auth + 服务端渲染单页,概览统计 / 用户与当前授权 / 最近使用记录 / 会话令牌 / 扫码场景五个区块 - ADMIN_PASSWORD 为空时返回 503 而非放行,避免漏配密码导致全库数据公开 - 不引模板引擎与 CDN,所有入库文本经 html.escape;令牌只显示首尾便于比对 - config.py / .env.example 新增 ADMIN_USER / ADMIN_PASSWORD - wechat.py 挂载 admin.router;CODEBUDDY.md 补充文档
38 lines
917 B
Bash
38 lines
917 B
Bash
# 环境变量模板
|
|
#
|
|
# 使用方法:
|
|
# 1. 复制此文件为 .env
|
|
# 2. 填入你的实际值
|
|
# 3. .env 不会进 Git(已在 .gitignore 中排除)
|
|
#
|
|
# cp .env.example .env
|
|
|
|
# 微信测试号 - 从 https://mp.weixin.qq.com/debug/cgi-bin/sandbox?t=sandbox/login 获取
|
|
WECHAT_TOKEN=your_custom_token_here
|
|
WECHAT_APPID=your_appid_here
|
|
WECHAT_SECRET=your_secret_here
|
|
|
|
# MySQL
|
|
MYSQL_HOST=127.0.0.1
|
|
MYSQL_PORT=3306
|
|
MYSQL_USER=root
|
|
MYSQL_PASSWORD=your_mysql_password_here
|
|
MYSQL_DB=wechat_api
|
|
|
|
# Redis
|
|
REDIS_HOST=127.0.0.1
|
|
REDIS_PORT=6379
|
|
REDIS_PASSWORD=your_redis_password_here
|
|
|
|
# 业务配置
|
|
FREE_AUTH_DAYS=7
|
|
SCENE_TTL_SECONDS=300
|
|
SESSION_TTL_HOURS=24
|
|
# 时间授权 usage_logs 节流窗口(秒)
|
|
USAGE_LOG_THROTTLE_SECONDS=60
|
|
|
|
# 管理后台 /admin 的 HTTP Basic Auth 凭据
|
|
# ADMIN_PASSWORD 留空时 /admin 返回 503(不鉴权放行),务必填一个长随机串
|
|
ADMIN_USER=admin
|
|
ADMIN_PASSWORD=
|