fix(security): harden auth and secret handling (HH-444) (#101)

* fix(security): harden auth and credential handling (HH-444)

* fix(security): address HH-444 review blockers

* fix(security): close remaining HH-444 review blockers

---------

Co-authored-by: Rogee <rogee@ipao.vip>
This commit is contained in:
Rogee
2026-08-22 15:45:06 +08:00
committed by GitHub
co-authored by rogee
parent e1557e7f21
commit f719529d66
81 changed files with 2149 additions and 474 deletions
+12 -2
View File
@@ -5,12 +5,14 @@ GOCHAT_ENV=production
GOCHAT_PORT=3000
GOCHAT_SERVER_MODE=release
GOCHAT_SERVER_CORS_ALLOWED_ORIGINS=https://chat.CHANGE_ME.example.com
GOCHAT_SERVER_TRUSTED_PROXIES=10.0.0.0/8
GOCHAT_DATABASE_DSN=postgres://gochat:CHANGE_ME@db.CHANGE_ME.example.com:5432/gochat_production?sslmode=verify-full
GOCHAT_REDIS_DSN=rediss://:CHANGE_ME@redis.CHANGE_ME.example.com:6380/0
POSTGRES_DB=gochat_production
POSTGRES_USER=gochat
POSTGRES_PASSWORD=CHANGE_ME
# The built-in PostgreSQL service is non-TLS. For an external database, set a
# complete GOCHAT_DATABASE_DSN with sslmode=require, verify-ca, or verify-full.
# Release mode requires external PostgreSQL/Redis endpoints with verified TLS.
POSTGRES_IMAGE_REF=pgvector/pgvector:pg16@sha256:ccc6e83d6e35e931dc7c5def2022729d5a6c370318d099181995567ff1fb4d6b
REDIS_IMAGE_REF=redis:7-alpine@sha256:ff02b58f971e7d7d156a1267e283fcbbeee91773b6aa36c49dac28ecfe28eadf
@@ -22,6 +24,14 @@ GOCHAT_JWT_SECRET=CHANGE_ME_WITH_AT_LEAST_32_RANDOM_CHARACTERS
# Optional during a bounded rotation window; comma-separated old 32+ byte secrets.
GOCHAT_JWT_PREVIOUS_SECRETS=
GOCHAT_JWT_ALLOW_INSECURE_HEADER_AUTH=false
GOCHAT_JWT_ACCESS_EXPIRY_MINUTES=15
GOCHAT_JWT_REFRESH_EXPIRY_HOURS=168
GOCHAT_JWT_WS_TICKET_TTL_SECONDS=30
# Generate with: openssl rand -base64 32
GOCHAT_ENCRYPTION_ENABLED=true
GOCHAT_ENCRYPTION_CURRENT_KEY_VERSION=1
GOCHAT_ENCRYPTION_AES_KEY=CHANGE_ME
# Optional connector. Supply the digest published by its release pipeline.
SHANGWUTONG_IMAGE_REF=ghcr.io/rogeecn/shangwutong@sha256:CHANGE_ME