chore: 上线前加固——调度器/登录限流/env 模板补全

- routes/console.php:注册每日数据库备份(03:00)+ 前台页面缓存清理(04:00)
- 前台登录/注册 POST 加 throttle:6,1 防爆破
- .env.example 补 S3/LLM/MARKET/UPLOAD_DISK 配置项,新部署不再漏配
This commit is contained in:
ak
2026-08-13 03:32:27 +08:00
parent f1b9d1e1c3
commit 6f13d13d5a
3 changed files with 41 additions and 9 deletions
+19
View File
@@ -76,3 +76,22 @@ WORKERMAN_QUEUE_CONNECTION=database
WORKERMAN_QUEUES=default,ai
WORKERMAN_MAX_TRIES=3
WORKERMAN_TIMEOUT=60
# ---- 附件 S3 兼容存储(R2 / COS / OSS / MinIO),不配置则回退本地 public ----
UPLOAD_DISK=uploads
S3_ACCESS_KEY=
S3_SECRET_KEY=
S3_REGION=auto
S3_BUCKET=
S3_ENDPOINT=
S3_USE_PATH_STYLE_ENDPOINT=false
S3_URL=
# ---- LLMOpenAI 兼容:DeepSeek / 通义 / 自建代理),AI 评论审核与润色 ----
LLM_BASE_URL=https://api.openai.com/v1
LLM_API_KEY=
LLM_MODEL=gpt-4o-mini
# ---- 插件/主题市场(可选,本地 ZIP 安装无需配置)----
MARKET_URL=
MARKET_TOKEN=
+18 -5
View File
@@ -1,8 +1,21 @@
<?php
use Illuminate\Foundation\Inspiring;
use Illuminate\Support\Facades\Artisan;
declare(strict_types=1);
Artisan::command('inspire', function () {
$this->comment(Inspiring::quote());
})->purpose('Display an inspiring quote');
use Illuminate\Support\Facades\Schedule;
/*
|--------------------------------------------------------------------------
| 调度器(生产需配置 cron* * * * * php artisan schedule:run
|--------------------------------------------------------------------------
*/
// 数据库每日备份(保留 7 天;spatie/laravel-backup
Schedule::command('backup:run --only-db')
->dailyAt('03:00')
->withoutOverlapping()
->appendOutputTo(storage_path('logs/backup.log'));
// 每日清理前台页面缓存(避免旧缓存长期驻留)
Schedule::call(fn () => \App\Blog\Support\PageCacheMiddleware::flush())
->dailyAt('04:00');
+4 -4
View File
@@ -66,15 +66,15 @@ Route::get('/comments', fn () => redirect()->route('comments', [], 301));
Route::get('/login.shtml', [AuthController::class, 'showLogin'])->name('login');
Route::get('/login', fn () => redirect()->route('login', [], 301));
Route::post('/login.shtml', [AuthController::class, 'login']);
Route::post('/login', [AuthController::class, 'login']);
Route::post('/login.shtml', [AuthController::class, 'login'])->middleware('throttle:6,1');
Route::post('/login', [AuthController::class, 'login'])->middleware('throttle:6,1');
Route::post('/logout.shtml', [AuthController::class, 'logout'])->name('logout');
Route::post('/logout', [AuthController::class, 'logout']);
Route::get('/register.shtml', [AuthController::class, 'showRegister'])->name('register');
Route::get('/register', fn () => redirect()->route('register', [], 301));
Route::post('/register.shtml', [AuthController::class, 'register']);
Route::post('/register', [AuthController::class, 'register']);
Route::post('/register.shtml', [AuthController::class, 'register'])->middleware('throttle:6,1');
Route::post('/register', [AuthController::class, 'register'])->middleware('throttle:6,1');
Route::get('/profile.shtml', [AuthController::class, 'profile'])->middleware('auth')->name('profile');
Route::get('/profile', fn () => redirect()->route('profile', [], 301))->middleware('auth');