- S2: logs.ts LIMIT/OFFSET SQL parameterization (? placeholders) - S3: checkTokenSecret() startup validation, JWT_SECRET→TOKEN_SECRET in backup.ts - S3: Access Token expiry shortened to 2h (from 30d) - S4: Export download uses HMAC signed short-term token (/prepare endpoint) - S4: Frontend export.ts adapted for prepare-then-download flow - .env.example reorganized with security notes - Added PRD and architecture docs for iteration v2
22 lines
361 B
Plaintext
22 lines
361 B
Plaintext
# Server
|
|
PORT=3000
|
|
|
|
# MySQL
|
|
DB_HOST=your_db_host
|
|
DB_USER=your_db_user
|
|
DB_PASSWORD=your_db_password
|
|
DB_NAME=xiaocai
|
|
|
|
# Uploads
|
|
UPLOAD_DIR=./uploads
|
|
|
|
# Backup
|
|
BACKUP_DIR=./backups
|
|
|
|
# Token (REQUIRED - server will not start with default value)
|
|
TOKEN_SECRET=change-me-to-a-secure-random-string
|
|
|
|
# WeChat Mini Program
|
|
WX_APPID=your_wx_appid
|
|
WX_SECRET=your_wx_secret
|