feat(backend): 出入库汇总近30天滚动窗口 + 跨租户安全加固
- summaryBounds:本月/近30天滚动双口径(stock-in/out Summary ?window=rolling30) - security(SEC-001):新增 ownership.go ensureShopRef 写入侧防线(stock-in/out/finance/ 盘点建单的 warehouse/partner/product 外键归属校验);读取侧全部 Preload 补 shop_id 作用域,finance Summary JOIN 补租户条件;回归测试 CrossTenantRefs - security(SEC-002):release 模式 JWT 密钥为空/默认值时拒绝启动 - gofmt 对齐若干 model/cmd 文件 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JJ1g8XV1YhhmHRzhwWEW7o
This commit is contained in:
@@ -25,6 +25,12 @@ func main() {
|
||||
if config.C.Server.CORSOrigin == "*" {
|
||||
log.Fatal("server.cors_origin must not be '*' in production — set it to the actual frontend origin")
|
||||
}
|
||||
// SEC-002:默认/空 JWT 密钥随仓库公开,任何人可自签 superadmin token。
|
||||
// 漏配 JWT_SECRET 时必须拒绝启动,而不是带公开密钥上线。
|
||||
if config.C.JWT.Secret == "" ||
|
||||
config.C.JWT.Secret == "change-this-to-a-random-secret-in-production" {
|
||||
log.Fatal("jwt.secret is empty or still the repo default — set JWT_SECRET in production")
|
||||
}
|
||||
}
|
||||
|
||||
// 初始化数据库
|
||||
|
||||
Reference in New Issue
Block a user