fix(security): 移除硬编码凭据与内网信息,改为环境变量注入

这个提交包含在:
2026-09-07 09:20:28 +08:00
父节点 20aec2bf26
当前提交 2383cd6e21
共修改 7 个文件,包含 113 行新增和 19 行删除
+17 -7
查看文件
@@ -1,4 +1,6 @@
from flask import Flask, render_template, request, redirect, url_for,jsonify
import json
import os
import threading
import time
import logging
@@ -46,12 +48,18 @@ def setup_logging():
setup_logging()
# 模拟的服务器信息,可以根据实际需求进行动态配置
servers = [
{"name": "现场端侧070", "ip": "***REMOVED***", "username": "root", "password": "***REMOVED***"},
{"name": "测试服务器", "ip": "***REMOVED***", "username": "root", "password": "***REMOVED***"},
{"name": "Server2", "ip": "192.168.1.2", "username": "user2", "password": "password2"},
]
# 服务器列表通过环境变量 SERVERS_JSON 注入(JSON 数组),避免在代码中硬编码 IP / 账号 / 密码
# 格式: [{"name": "web1", "ip": "192.168.1.10", "username": "root", "password": "xxx"}]
# 配置方式参考 .env.example
_servers_env = os.environ.get("SERVERS_JSON", "").strip()
if _servers_env:
try:
servers = json.loads(_servers_env)
except json.JSONDecodeError as e:
raise SystemExit(f"SERVERS_JSON 环境变量不是合法 JSON: {e}")
else:
servers = []
logging.warning("未设置 SERVERS_JSON 环境变量,服务器列表为空,请参考 .env.example 进行配置")
# 全局变量存储服务器状态
server_status = {}
@@ -249,4 +257,6 @@ def control():
if __name__ == '__main__':
# 启动定时任务
start_scheduler()
app.run(host='0.0.0.0',port=8090,debug=True)
# debug 模式默认关闭:开启后 Werkzeug 调试器会暴露在网络上,存在远程代码执行风险
debug = os.environ.get("FLASK_DEBUG", "0").lower() in ("1", "true", "yes")
app.run(host='0.0.0.0', port=8090, debug=debug)