Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

🔥紧急重大bug修复 #152

Closed
Dooy opened this issue Feb 8, 2024 · 5 comments
Closed

🔥紧急重大bug修复 #152

Dooy opened this issue Feb 8, 2024 · 5 comments

Comments

@Dooy
Copy link
Owner

Dooy commented Feb 8, 2024

1 v2.15.3 修复AUTH_SECRET_KEY 后端验证
2 vercel由于验证复杂 后端也未验证 AUTH_SECRET_KEY
3 尽量使用ui来设置服务端 base_urlkey
4 保护好你的密码 尽量不分享你的网址、密码 和key
5 v2.15.6版本 增加了 防爆破 AUTH_SECRET_ERROR_COUNT=3 AUTH_SECRET_ERROR_TIME=10
image

@Dooy Dooy pinned this issue Feb 8, 2024
@Dooy Dooy changed the title 重大bug修复 🔥重大bug修复 Feb 8, 2024
@Dooy Dooy changed the title 🔥重大bug修复 🔥紧急重大bug修复 Feb 8, 2024
@Dooy Dooy closed this as completed Feb 14, 2024
@bbb3n
Copy link

bbb3n commented Feb 16, 2024

请问意思以前的版本,如果 Vercel 环境变量设置了 key ,会被偷取嘛?

@Dooy
Copy link
Owner Author

Dooy commented Feb 16, 2024

最好 别用vercel 目前 后端没去做认证,看看有人pr上来否
docker的后端有做

其实如果 只在ui端填 base_url 跟 key是无所谓的

@usawjq
Copy link

usawjq commented Feb 29, 2024

坐等修复,话说有交流群吗 @Dooy

@gpxin
Copy link

gpxin commented Mar 25, 2024

最近已经被连续两次偷取key了,用的是老版镜像,望周知

@xixingya
Copy link

xixingya commented Aug 20, 2024

请问在ui上面填写baseurl也会被盗吗,为什么我在演示站点填写了baseurl使用,然后今天就被盗用了。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants