mirror of
https://github.com/Wei-Shaw/sub2api.git
synced 2026-10-07 17:08:33 +08:00
fix(config): 为 trusted_proxies 与 forwarded_client_ip_headers 注册 BindEnv,修复 env 可达性守卫测试
#4593 引入的 TestConfigKeysAreEnvReachable 与 #4604 新增的两个配置键语义相撞: 两键在 setDefaults 中无注册,守卫测试判定其环境变量不可达。 不能按守卫注释直接 SetDefault:viper 的 IsSet 会连同 defaults 一起上报, 任何已注册默认值都会让 load() 中 trustedProxiesConfigured 的显式配置探测 永远为真,摧毁 #4600 的 absent/empty 区分。改用 BindEnv 注册——绑定键同样 进入 AllKeys()(守卫测试与 Unmarshal 均可见),而变量缺席时不影响 IsSet。 两个环境变量本就由 load() 中 os.LookupEnv 手工解析,行为不变。
This commit is contained in:
@@ -2374,6 +2374,18 @@ func setEnvReachableDefaults() {
|
||||
viper.SetDefault("gateway.openai_scheduler.sticky_escape_error_rate", 0.0)
|
||||
viper.SetDefault("gateway.openai_scheduler.sticky_escape_ttft_ms", 0)
|
||||
|
||||
// server.trusted_proxies and security.forwarded_client_ip_headers are the
|
||||
// other exception: load() distinguishes explicit configuration from absence
|
||||
// (issue #4600), and viper.IsSet also reports registered defaults, so a
|
||||
// SetDefault would make trusted proxies look permanently configured. Both
|
||||
// environment variables are parsed by hand in load() via os.LookupEnv and
|
||||
// were never silently dropped; binding them here records that reachability
|
||||
// where AllKeys() — and the env-reachability guard — can see it, without
|
||||
// affecting IsSet while the variables are absent. BindEnv only errors when
|
||||
// called without arguments.
|
||||
_ = viper.BindEnv("server.trusted_proxies", "SERVER_TRUSTED_PROXIES")
|
||||
_ = viper.BindEnv("security.forwarded_client_ip_headers", "SECURITY_FORWARDED_CLIENT_IP_HEADERS")
|
||||
|
||||
// Third-party login providers. These carry client secrets and are exactly
|
||||
// the settings an operator expects to inject via the environment, but every
|
||||
// key here was previously unreachable that way.
|
||||
|
||||
Reference in New Issue
Block a user