Files
ONE/backend/internal/config/config.go
T
Sakurasan cfd6948987 评论阶段二:GitHub OAuth 登录 + 评论表/用户表 + 先审后显开关 + 禁言 + 后台评论管理页
- auth 包:读者会话(one_reader,与后台令牌互斥)+ GitHub OAuth 客户端;Verify 校验 HMAC 与 reader: 前缀
- 公开 API:auth 五端点、评论列表(顶层可见+自己待审、回复内嵌)、发表(登录/禁言/开关/500 字校验)、10 分钟编辑窗、软删墓碑
- 管理端:评论列表(待审/已通过/全部)、通过、软删、读者列表、禁言切换
- 前台:登录卡/禁言卡;后台:评论管理页 + 设置页审核开关
2026-09-27 23:41:40 +08:00

141 lines
4.1 KiB
Go
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
package config
import (
"crypto/rand"
"encoding/hex"
"log"
"os"
"path/filepath"
"strings"
)
type Config struct {
Addr string
Driver string // sqlite | postgres
DSN string
AdminUser string
AdminPass string
SessionSec string
WebDist string
DataDir string
SiteURL string
InsecureDev bool
// 评论区 GitHub 登录(OAuth App 凭据,站主在 GitHub 上创建后填入)
GitHubClientID string
GitHubClientSecret string
// 对象存储(文件上传)。变量名与站主 .env 里的写法一致(站主已整理):
// S3Api = R2 的 S3 API 端点(https://<账户ID>.r2.cloudflarestorage.com,
// 控制台 R2 概览可复制),上传走它 —— 公开域名收不了上传请求
// PublicURL = 公开访问域名(r2.dev / 绑定的自定义域名),文件直链走它
// AccessKey / SecretAccessKey / Bucket = R2 凭据与桶名
// 五项齐全 → 上传走 R2、直链走 PublicURL;缺任一项回落本地磁盘
// (DataDir/uploads),并在启动日志提示一句。
StorageDriver string // r2 | local
S3Endpoint string // env: S3Api
R2Bucket string
R2AccessKey string
R2SecretKey string
UploadsPublicBase string // env: PublicURL
}
func getenv(k, def string) string {
if v := strings.TrimSpace(os.Getenv(k)); v != "" {
return v
}
return def
}
func Load() (*Config, error) {
root := getenv("ONE_ROOT", "")
if root == "" {
if wd, err := os.Getwd(); err == nil {
root = filepath.Dir(wd) // server/ -> repo root
} else {
root = "."
}
}
c := &Config{
Addr: getenv("ONE_ADDR", ":8080"),
Driver: strings.ToLower(getenv("ONE_DB_DRIVER", "sqlite")),
AdminUser: getenv("ONE_ADMIN_USER", "admin"),
AdminPass: getenv("ONE_ADMIN_PASSWORD", "admin"),
SessionSec: getenv("ONE_SECRET", ""),
WebDist: getenv("ONE_WEB_DIST", filepath.Join(root, "frontend", "dist")),
DataDir: getenv("ONE_DATA_DIR", filepath.Join(root, "data")),
SiteURL: getenv("ONE_SITE_URL", "http://localhost:8080"),
}
if c.Driver == "" {
c.Driver = "sqlite"
}
if c.Driver != "sqlite" && c.Driver != "postgres" && c.Driver != "postgresql" {
return nil, &badDriver{c.Driver}
}
if c.Driver == "postgresql" {
c.Driver = "postgres"
}
if c.DSN = getenv("ONE_DB_DSN", ""); c.DSN == "" {
if c.Driver == "sqlite" {
c.DSN = filepath.Join(c.DataDir, "one.db")
} else {
c.DSN = "postgres://localhost/one?sslmode=disable"
}
}
if c.SessionSec == "" {
b := make([]byte, 32)
if _, err := rand.Read(b); err != nil {
return nil, err
}
c.SessionSec = hex.EncodeToString(b)
}
c.InsecureDev = os.Getenv("ONE_ADMIN_PASSWORD") == ""
// 对象存储:变量名按站主 .env 里整理好的来(无 ONE_ 前缀)。
c.UploadsPublicBase = strings.TrimRight(getenv("PublicURL", ""), "/")
c.S3Endpoint = getenv("S3Api", "")
c.R2AccessKey = getenv("AccessKey", "")
c.R2SecretKey = getenv("SecretAccessKey", "")
c.R2Bucket = getenv("Bucket", "")
if c.S3Endpoint != "" && c.R2Bucket != "" && c.R2AccessKey != "" && c.R2SecretKey != "" {
c.StorageDriver = "r2"
} else {
c.StorageDriver = "local"
// 配了一半(有凭据没端点之类)时给一句启动日志,别让站主猜。
// 只报字段名,不报值。
var missing []string
if c.S3Endpoint == "" {
missing = append(missing, "S3Api")
}
if c.R2Bucket == "" {
missing = append(missing, "Bucket")
}
if c.R2AccessKey == "" {
missing = append(missing, "AccessKey")
}
if c.R2SecretKey == "" {
missing = append(missing, "SecretAccessKey")
}
if len(missing) > 0 {
log.Printf("storage: R2 配置缺 %s,上传回落本地磁盘", strings.Join(missing, "、"))
}
}
// 评论区 GitHub 登录(OAuth App 凭据,站主在 GitHub 上创建后填入)
c.GitHubClientID = getenv("ONE_GITHUB_CLIENT_ID", "")
c.GitHubClientSecret = getenv("ONE_GITHUB_CLIENT_SECRET", "")
return c, nil
}
type badDriver struct{ d string }
func (e *badDriver) Error() string {
return "unsupported ONE_DB_DRIVER: " + e.d + " (use sqlite or postgres)"
}