[GH-ISSUE #7] 佬考虑区分管理员密钥和请求密钥吗 #8

Closed
opened 2026-02-26 12:18:57 +03:00 by kerem · 2 comments
Owner

Originally created by @tongguang on GitHub (Feb 25, 2026).
Original GitHub issue: https://github.com/BenedictKing/ccx/issues/7

如题。出于安全考虑,会不会拆分下管理员密钥和请求密钥比较好一点?这样子万一不小心密钥泄露了,也不至于整个渠道信息全部泄露了。

Originally created by @tongguang on GitHub (Feb 25, 2026). Original GitHub issue: https://github.com/BenedictKing/ccx/issues/7 如题。出于安全考虑,会不会拆分下管理员密钥和请求密钥比较好一点?这样子万一不小心密钥泄露了,也不至于整个渠道信息全部泄露了。
kerem closed this issue 2026-02-26 12:18:57 +03:00
Author
Owner

@BenedictKing commented on GitHub (Feb 26, 2026):

对的,新版有加这个

# ============ 访问控制 ============
# 代理访问密钥(必须修改!)
PROXY_ACCESS_KEY=your-secure-access-key-here
# 管理 API 独立密钥(可选,未设置时回退到 PROXY_ACCESS_KEY)
# 设置后,管理界面和 /api/* 端点将使用此密钥认证,与代理密钥隔离
# ADMIN_ACCESS_KEY=your-admin-access-key-here
<!-- gh-comment-id:3963405959 --> @BenedictKing commented on GitHub (Feb 26, 2026): 对的,新版有加这个 ``` # ============ 访问控制 ============ # 代理访问密钥(必须修改!) PROXY_ACCESS_KEY=your-secure-access-key-here # 管理 API 独立密钥(可选,未设置时回退到 PROXY_ACCESS_KEY) # 设置后,管理界面和 /api/* 端点将使用此密钥认证,与代理密钥隔离 # ADMIN_ACCESS_KEY=your-admin-access-key-here ```
Author
Owner

@tongguang commented on GitHub (Feb 26, 2026):

可以了,感谢回复

<!-- gh-comment-id:3963560407 --> @tongguang commented on GitHub (Feb 26, 2026): 可以了,感谢回复
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/ccx#8
No description provided.