Files
dsh_shenxian/dsh-server-docs/ops/nginx/alotbuy.com.conf
T
admin 971ccc3703 feat(auth): 注册页人机验证 + 邮箱验证码;品牌标识去 DeepSeek(附域名迁移线 序㊿ 补提交)
三条线合并入库 —— 均已完成并上线(源码与生产一致,此前只部署未入仓)。
⚠️ 其中域名迁移线为**另一会话**产出,本会话只做入库、**未复验其正确性**(它自报零回归)。

【档案 134 · 注册页人机验证 + 邮箱验证码】
- DB 迁移 v10:users.email(唯一索引 LOWER(email))+ email_codes 事件表(2 索引)
- 新增模块 src/web/{register-guard,mail,turnstile,email-code}.ts
- routes/auth.ts:新增 GET /api/auth/register/config、POST /api/auth/register/email-code;
  注册接口加人机验证与验证码校验;config.ts 新增 12 项配置(默认空 ⇒ 不配 = 老行为)
- 邮件走**可插拔驱动**(brevo/http/log),发件人 [email protected](Brevo 域名已认证 + DKIM + SPF)
- 防爆破:三层配额(邮箱 6/h、8/天;IP 20/h;全局 200/h)+ 递增冷却阶梯
  (60→60→180→300→900→1800s)+ 试错 5 次作废 + 码只存哈希 + 单次使用 + 与用户名绑定
- Turnstile 服务端校 **success + action + hostname 三项**:sitekey 是公开的,
  只校 success 时"拿我们的 sitekey 在自己站点替真人取合法 token 再打我们接口"这条路是通的
- 新增 test/register-guard.test.mjs(19 用例)

【档案 137 · 品牌标识改造 — 去 DeepSeek 图形】
- login/register/admin 页头:删 DeepSeek 鲸鱼图标 + 「DeepSeek」文字图形
  → 平台标识(中文「能力枢纽」/英语及其他语言「CapabilityNet」,走 i18n 词条 brand.name)
- portal 顶栏换图标(页面名「管理门户」保留)
- 新建 web/favicon.svg(平台自有 hub 图标,避开 DeepSeek 蓝)+ 四页 favicon 指向它
- 新增 test/i18n-brand.test.mjs(node:vm 跑真实 i18n.js,六条语言路径断言渲染结果)
- scripts/verify-static.mjs 新增 SVG 段:XML 注释不得含 ASCII 双连字符(否则整份 SVG
  解析失败、图标静默不显示 —— 实际踩到过)
- 🔴 会话页面(实例内官方 dsh 界面)的标识**按用户要求未动**(也受 R2 约束)

【档案 135/136 · 域名迁移线(另一会话产出)】
- 域名收敛为 ai1net.com;旧域 alotbuy.com 降级为 301 过渡装置
- src/net/relay/{addr-override,directory,rendezvous,switcher}.ts 种子与候选链更新;
  src/web/server.ts、src/worker/relay-tunnel.ts、scripts/verify-cluster-domain.mjs
- 档案 136 = 控制面按两台中继取并集(**已立项、未落地**)

验证(本会话两条线):新增单测 21 条全通过|全量 221 pass / 0 fail / 1 skipped|
verify-static 全合格|其余 10 个 verify 脚本全 OK|线上实测:Turnstile 假 token 403、
发码 delivered、四页 deepseek 命中 0、favicon 200。
2026-09-19 09:11:24 +08:00

149 lines
5.9 KiB
Plaintext
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# alotbuy.com —— 旧域(2026-09-10 建立为门户站点;**2026-09-19 降级为 301 过渡装置**)
#
# 为什么"降级"而不是"删除"(判据见 04-调整方案/135):
# ① 老书签 / 外链不 404(301 到新域**同名子域**,保留用户名映射)
# ② 已入网节点的**旧域中继入口**仍可透传 ⇒ 不断线(见下方保留的 location)
# ③ 软回滚路径保留:`cp alotbuy.com.conf.bak-dompurge-<ts> alotbuy.com.conf && nginx -t && nginx -s reload`
# ⛔ 退役条件 = **旧域 30 天访问量为 0**(看 /www/wwwlogs/alotbuy.com.log)→ 连
# `dsh.alotbuy.com.conf`、`relay-direct.conf` 一并删。
#
# 唯三**不** 301 的路径(其余一律 301 到新域):
# /dshs-relay → 127.0.0.1:20080(自研 relay WebSocket;旧域入口,SEEDS 已不再引导)
# /dshs-overlay/bootstrap → 127.0.0.1:3080(覆盖网络目录只读路由)
# /.well-known/acme-challenge/(ACME 落点,续期不掉链)
#
# map 必须位于 http 上下文 —— 面板 vhost 文件正是被 include 在 http{} 内,故写在本文件顶层。
# ⚠️ 与 `dsh.alotbuy.com.conf` 的 map 是**两个不同变量名**,不冲突;
# `*.dsh.alotbuy.com` 由那个文件**更长的通配 server_name** 接管,不进本文件的 map。
# ⚠️ 301 目标是**不同主机**(ai1net.com,CF 侧已是 Full(strict))⇒ 不存在"源站 301 造成 CF 循环"。
# 故 80 端口可以直接 301(原门户块当年为兼容 CF Flexible 才用代理)。
map $host $alotbuy_301_host {
default ai1net.com;
~^(?<lb301>[^.]+)\.alotbuy\.com$ $lb301.ai1net.com;
}
# ---- HTTP:301 到新域(旧域不再承载门户)----
server {
# CF 回源 IP → 还原真实客户端 IP(仅本 server 生效)
set_real_ip_from 173.245.48.0/20;
set_real_ip_from 103.21.244.0/22;
set_real_ip_from 103.22.200.0/22;
set_real_ip_from 103.31.4.0/22;
set_real_ip_from 141.101.64.0/18;
set_real_ip_from 108.162.192.0/18;
set_real_ip_from 190.93.240.0/20;
set_real_ip_from 188.114.96.0/20;
set_real_ip_from 197.234.240.0/22;
set_real_ip_from 198.41.128.0/17;
set_real_ip_from 162.158.0.0/15;
set_real_ip_from 104.16.0.0/13;
set_real_ip_from 104.24.0.0/14;
set_real_ip_from 172.64.0.0/13;
set_real_ip_from 131.0.72.0/22;
set_real_ip_from 2400:cb00::/32;
set_real_ip_from 2606:4700::/32;
set_real_ip_from 2803:f800::/32;
set_real_ip_from 2405:b500::/32;
set_real_ip_from 2405:8100::/32;
set_real_ip_from 2a06:98c0::/29;
set_real_ip_from 2c0f:f248::/32;
real_ip_header CF-Connecting-IP;
listen 80;
server_name alotbuy.com www.alotbuy.com *.alotbuy.com;
# ── ACME 挑战(续期用;`^~` 优先于下面的 `location /`)──
location ^~ /.well-known/acme-challenge/ {
root /www/server/nginx/html;
default_type text/plain;
access_log off;
}
# ── 覆盖网络中继(保留:已入网节点仍可能持旧域地址)──
location /dshs-relay {
proxy_pass http://127.0.0.1:20080;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_set_header Host $host;
proxy_read_timeout 3600s;
proxy_send_timeout 3600s;
proxy_buffering off;
}
location = /dshs-overlay/bootstrap {
proxy_pass http://127.0.0.1:3080;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
proxy_buffering off;
}
location / { return 301 https://$alotbuy_301_host$request_uri; }
access_log /www/wwwlogs/alotbuy.com.log;
error_log /www/wwwlogs/alotbuy.com.error.log;
}
# ---- HTTPS:301 到新域(同上)----
server {
# CF 回源 IP → 还原真实客户端 IP(仅本 server 生效)
set_real_ip_from 173.245.48.0/20;
set_real_ip_from 103.21.244.0/22;
set_real_ip_from 103.22.200.0/22;
set_real_ip_from 103.31.4.0/22;
set_real_ip_from 141.101.64.0/18;
set_real_ip_from 108.162.192.0/18;
set_real_ip_from 190.93.240.0/20;
set_real_ip_from 188.114.96.0/20;
set_real_ip_from 197.234.240.0/22;
set_real_ip_from 198.41.128.0/17;
set_real_ip_from 162.158.0.0/15;
set_real_ip_from 104.16.0.0/13;
set_real_ip_from 104.24.0.0/14;
set_real_ip_from 172.64.0.0/13;
set_real_ip_from 131.0.72.0/22;
set_real_ip_from 2400:cb00::/32;
set_real_ip_from 2606:4700::/32;
set_real_ip_from 2803:f800::/32;
set_real_ip_from 2405:b500::/32;
set_real_ip_from 2405:8100::/32;
set_real_ip_from 2a06:98c0::/29;
set_real_ip_from 2c0f:f248::/32;
real_ip_header CF-Connecting-IP;
listen 443 ssl;
http2 on;
server_name alotbuy.com www.alotbuy.com *.alotbuy.com;
ssl_certificate /etc/letsencrypt/live/alotbuy.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/alotbuy.com/privkey.pem;
location ^~ /.well-known/acme-challenge/ {
root /www/server/nginx/html;
default_type text/plain;
access_log off;
}
# ── 覆盖网络中继(保留)──
location /dshs-relay {
proxy_pass http://127.0.0.1:20080;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_set_header Host $host;
proxy_read_timeout 3600s;
proxy_send_timeout 3600s;
proxy_buffering off;
}
location = /dshs-overlay/bootstrap {
proxy_pass http://127.0.0.1:3080;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
proxy_buffering off;
}
location / { return 301 https://$alotbuy_301_host$request_uri; }
access_log /www/wwwlogs/alotbuy.com.log;
error_log /www/wwwlogs/alotbuy.com.error.log;
}