Seefs
a073f74b38
refactor: deprecate int32 ( #7025 )
...
* refactor: deprecate int32
* fix(db): reject legacy user quota schemas at startup
* fix(quota): enforce wallet bounds and saturating billing conversions
* fix(rate-limit): keep count*duration from wrapping int64
* fix: error message
2026-08-26 20:57:54 +08:00
feitianbubu
c3db41407d
fix: 慢查询/错误 SQL 日志参数化 ( #6493 )
...
* fix: parameterize slow/error SQL logs to avoid leaking credentials
* fix: validate SQL_SLOW_THRESHOLD_MS range
* fix: sanitize database driver error messages in SQL logs
* refactor: sanitize at gorm log writer seam to keep caller attribution
2026-07-27 22:21:31 +08:00
Calcium-Ion
31d70fca39
refactor(auth): replace dashboard sessions with stateless tokens and session control ( #6329 )
...
* refactor(auth): replace dashboard sessions with stateless tokens
* feat(auth): harden session issuance and distributed enforcement
* fix(proxy): preserve trusted proxy compatibility defaults
* refactor: address dashboard auth review feedback
* refactor: remove classic frontend and flatten web app
2026-07-20 16:48:43 +08:00
CaIon
56dbaab1d4
feat(session): support opt-in Secure session cookies
...
- add SESSION_COOKIE_SECURE / SESSION_COOKIE_TRUSTED_URL env vars with
startup validation: enabling Secure requires at least one trusted
HTTPS entry URL
- wire common.SessionCookieSecure into the session cookie store instead
of a hardcoded Secure=false
- print a startup warning when Secure session cookies are disabled
- document the new settings in .env.example and docker-compose files
Secure stays off by default because many deployments front new-api with
plain-HTTP reverse proxies, where a hardcoded Secure default would break
logins entirely; enabling it safely depends on the deployment's TLS
setup, so it ships as an opt-in deployment-hardening flag.
2026-07-05 13:53:16 +08:00
Seefs
933ea0cddc
fix: add relay idle connection timeout config ( #5309 )
2026-06-05 11:30:08 +08:00
borx
cf1b485389
add 添加 启用错误日志记录到env配置中
2026-04-07 21:12:13 +08:00
mehunk
db5b07bf98
feat: Add trusted redirect domains.
2026-01-26 22:18:04 +09:00
Seefs
980af061fd
feat: TLS_INSECURE_SKIP_VERIFY env
2026-01-15 14:43:53 +08:00
Seefs
a78fd2dae6
docs: document pyroscope env var
2025-12-19 23:16:56 +08:00
Seefs
fb0ffe8c95
docs: document pyroscope env var
2025-12-19 23:03:04 +08:00
CaIon
4dbbf06adc
fix: Update GET_MEDIA_TOKEN_NOT_STREAM default value to false
2025-11-22 16:23:37 +08:00
Seefs
2a7260208b
feat: linuxdo oauth endpoint -> environment
2025-11-16 14:50:59 +08:00
CaIon
f0183785c9
feat(option): enhance UpdateOption to handle various value types and improve validation
2025-09-03 14:30:25 +08:00
CaIon
c7281a353f
fix(env): update STREAMING_TIMEOUT default value to 300 seconds
2025-08-12 19:58:04 +08:00
CaIon
2f04ab0daf
✨ feat: enhance environment configuration and resource initialization
2025-07-01 13:13:30 +08:00
CaIon
8a1e437ce9
🔧 chore: update STREAMING_TIMEOUT default value to 120 seconds in configuration
2025-06-22 18:47:40 +08:00
1808837298@qq.com
8a30d64a75
feat: Add Gemini version settings configuration support ( close #568 )
2025-02-26 18:19:09 +08:00
lgphone
10311f60e1
Update .env.example
...
修复示例配置中MySQL的DSN错误问题
2025-02-18 19:18:54 +08:00
HowieWood
4e531938ee
Modify the default gemini API to v1beta
2024-11-16 12:21:50 +00:00
CalciumIon
0351baa7b3
chore: update .env.example
2024-11-11 22:05:29 +08:00
CalciumIon
f7aef17a02
chore: update .env.example
2024-11-11 22:04:51 +08:00
lianghaoyuan
9e345b222d
refactor(config): 调整配置文件,优化注释和变量命名
2024-09-25 17:03:06 +08:00
lianghaoyuan
9076ec5c63
feat: 添加.env配置文件和初始化环境变量
2024-09-24 11:39:02 +08:00