fix(run): 增强数据库初始化与安全配置
- 从环境变量读取密钥,未设置时随机生成 - 自动初始化数据库并显式使用 UTF-8 读取 schema - 移除默认管理员账号,更新页面署名与链接 - 新增 .gitignore、LICENSE 和 README
这个提交包含在:
@@ -1,11 +1,14 @@
|
||||
import datetime,time
|
||||
import os
|
||||
import sqlite3
|
||||
from gevent.pywsgi import WSGIServer
|
||||
from flask import Flask, abort, render_template, g, escape, request, make_response, session, redirect, url_for
|
||||
from flask_caching import Cache
|
||||
|
||||
app = Flask(__name__)
|
||||
app.secret_key = b'f98d5992f84753d9004ef6b86f8dc603e105d6f201b3a7ac0e0d6d674e3b71a3'
|
||||
# 从环境变量读取密钥,未设置时生成临时随机密钥(重启后失效,生产环境请务必设置)
|
||||
import os
|
||||
app.secret_key = os.environ.get('NAVI_SECRET_KEY') or os.urandom(24)
|
||||
# ===========db
|
||||
DATABASE = './navi.db'
|
||||
cache = Cache(config={"DEBUG": True,'CACHE_TYPE': 'SimpleCache',"CACHE_DEFAULT_TIMEOUT": 300})
|
||||
@@ -29,12 +32,22 @@ def close_connection(exception):
|
||||
def init_db():
|
||||
with app.app_context():
|
||||
db = get_db()
|
||||
with app.open_resource('./schema.sql', mode='r') as f:
|
||||
# 显式以 utf-8 读取,避免 Windows(GBK) 下因中文注释解码失败
|
||||
with app.open_resource('./schema.sql', mode='r', encoding='utf-8') as f:
|
||||
db.cursor().executescript(f.read())
|
||||
db.commit()
|
||||
|
||||
|
||||
# init_db()
|
||||
def ensure_db():
|
||||
"""确保数据库文件及表结构存在,首次运行自动按 schema.sql 初始化。"""
|
||||
if not os.path.exists(DATABASE):
|
||||
print("数据库不存在,正在初始化:%s" % DATABASE)
|
||||
init_db()
|
||||
|
||||
|
||||
# 启动时检查并初始化数据库
|
||||
ensure_db()
|
||||
# init_db() # 如需重置数据库结构可手动调用
|
||||
|
||||
def query_db(query, args=(), one=False):
|
||||
cur = get_db().execute(query, args)
|
||||
@@ -385,10 +398,11 @@ def sitemap():
|
||||
pages = []
|
||||
ten_days_ago = (datetime.datetime.now() - datetime.timedelta(days=7)).date().isoformat()
|
||||
# static pages
|
||||
site_url = os.environ.get('NAVI_SITE_URL', '').rstrip('/')
|
||||
for rule in app.url_map.iter_rules():
|
||||
if "GET" in rule.methods and len(rule.arguments) == 0:
|
||||
pages.append(
|
||||
["https://nav.iwali.top" + str(rule.rule), ten_days_ago]
|
||||
[site_url + str(rule.rule), ten_days_ago]
|
||||
)
|
||||
sitemap_xml = render_template('sitemap_template.xml', pages=pages)
|
||||
response = make_response(sitemap_xml)
|
||||
|
||||
在新工单中引用
屏蔽一个用户