Files
pangolin/ci/scan-redline.sh
T
wangjia c92cd11cc5 feat: CI 流水线 — lint + 单测 + OpenAPI 校验 + 脱敏扫描 + 镜像构建 [tsk_P5b5nIrEsfrV]
新增 .gitea/workflows/ci.yml 五个 Job:
  1. lint        — shellcheck -S warning 扫描全部 deploy/ shell 脚本
  2. unit-test   — docker-compose config 语法校验 + nginx -t(桩证书)
  3. openapi-check — openapi-spec-validator 验证 design/server/openapi.yaml
  4. redline-scan  — ci/scan-redline.sh 扫描 UI 文案红线词(design/ jsx/dart/html)
  5. image-build   — docker build pangolin-edge:ci

附带:
  - ci/scan-redline.sh:脱敏扫描脚本,过滤注释行与外部渠道 handle
  - ci/nginx-test.sh:自签桩证书 + nginx -t,CI 免依赖真实 Let's Encrypt
  - design/server/openapi.yaml:依据 ARCHITECTURE.md §3 展开的 OAS 3.0 完整契约
  - dparts.jsx / parts.jsx:修复 killSwitchSub EN 文案「the VPN drops」红线词
    → 改为「connection drops」(行为描述,不提产品类别)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-13 01:19:28 +08:00

85 lines
2.7 KiB
Bash

#!/usr/bin/env bash
# scan-redline.sh — 脱敏红线词扫描(UI 文案资源)。
#
# 扫描范围: design/ui_kits/**/*.{jsx,js,html}
# design/flutter/**/*.{dart,html}
# 不扫描: README.md、CLAUDE.md 等纯文档文件
#
# 红线词(来源: design/CLAUDE.md §1 铁律 13):
# VPN 翻墙 科学上网 突破封锁 自由穿越 Go anywhere
#
# 允许例外:
# - 纯注释行 (// ... 或 /* ... 或 * ... 开头)
# - 外部渠道 handle (@PangolinVPN_bot / @pangolinvpn 等)
#
# 发现违规 → 非零退出码 (CI fail)。
set -euo pipefail
REPO_ROOT="$(cd "$(dirname "$0")/.." && pwd)"
cd "$REPO_ROOT"
VIOLATIONS=0
SCANNED=0
# 逐文件扫描函数
# 用法: scan_file <文件路径>
scan_file() {
local file="$1"
local file_violations=0
# 逐个红线词扫描
for word in 'VPN' '翻墙' '科学上网' '突破封锁' '自由穿越' '[Gg]o anywhere'; do
# 1. 找出含有红线词的行
# 2. 排除纯注释行 (行首可选空白 + // 或 /* 或 *)
# 3. 排除外部渠道 handle 行 (@PangolinVPN_bot / @pangolinvpn)
local hits
hits="$(grep -nE "$word" "$file" 2>/dev/null \
| grep -vE '^[0-9]+:[[:space:]]*(//|/\*|\*)' \
| grep -vE '@[Pp]angolin[Vv][Pp][Nn]_?[Bb]ot' \
| grep -vE '@pangolinvpn' \
|| true)"
if [ -n "$hits" ]; then
if [ "$file_violations" -eq 0 ]; then
echo "$file" >&2
fi
echo "$hits" | while IFS= read -r line; do
printf ' 红线词 [%s] %s\n' "$word" "$line" >&2
done
file_violations=1
fi
done
return "$file_violations"
}
echo "→ 开始脱敏扫描 ..."
# 扫描 design/ui_kits 下的 jsx / js / html 文件
while IFS= read -r -d '' f; do
SCANNED=$((SCANNED + 1))
if ! scan_file "$f"; then
VIOLATIONS=$((VIOLATIONS + 1))
fi
done < <(find design/ui_kits -type f \( -name "*.jsx" -o -name "*.js" -o -name "*.html" \) -not -name "README.md" -print0)
# 扫描 design/flutter 下的 dart / html 文件
while IFS= read -r -d '' f; do
SCANNED=$((SCANNED + 1))
if ! scan_file "$f"; then
VIOLATIONS=$((VIOLATIONS + 1))
fi
done < <(find design/flutter -type f \( -name "*.dart" -o -name "*.html" \) -not -name "README.md" -print0)
echo "→ 扫描完成:共 ${SCANNED} 个文件,${VIOLATIONS} 个违规。"
echo ""
if [ "$VIOLATIONS" -ne 0 ]; then
echo "脱敏检查失败!请根据 design/CLAUDE.md §1 铁律 13 修改以上文案:" >&2
echo " - 禁用词:VPN、翻墙、科学上网、突破封锁、自由穿越、Go anywhere" >&2
echo " - 代用词:网络加速、极速畅连、稳定、加速线路、隐私保护、无日志" >&2
exit 1
fi
echo "✅ 脱敏扫描通过 — 未发现红线词。"