diff --git a/backend/app/core/auth.py b/backend/app/core/auth.py index 602723a..2fe7a71 100644 --- a/backend/app/core/auth.py +++ b/backend/app/core/auth.py @@ -11,7 +11,9 @@ from app.core.database import SessionLocal from app.models.models import User # 配置 -SECRET_KEY = os.getenv("SECRET_KEY", "your-secret-key-change-in-production") +SECRET_KEY = os.getenv("SECRET_KEY") +if not SECRET_KEY: + raise ValueError("SECRET_KEY environment variable is not set. Please configure it in production!") ALGORITHM = "HS256" ACCESS_TOKEN_EXPIRE_MINUTES = int(os.getenv("ACCESS_TOKEN_EXPIRE_MINUTES", "10080")) # 7天 diff --git a/backend/app/main.py b/backend/app/main.py index 2ec184f..73ade76 100644 --- a/backend/app/main.py +++ b/backend/app/main.py @@ -52,10 +52,11 @@ app = FastAPI( # 设置全局错误处理器 setup_error_handlers(app) -# CORS 配置 +# CORS 配置 - 生产环境限制域名 +ALLOWED_ORIGINS = os.getenv("ALLOWED_ORIGINS", "http://47.103.29.111,http://120.55.81.21,https://socoolbot.com").split(",") app.add_middleware( CORSMiddleware, - allow_origins=["*"], # 生产环境应该限制域名 + allow_origins=ALLOWED_ORIGINS, allow_credentials=True, allow_methods=["*"], allow_headers=["*"],