fix: 收紧本地开发服务器的内容边界并默认只监听本机 - #64
Merged
Merged
Conversation
`bun run dev` 之前把整个仓库目录当成静态根:`/.git/config`、`/.git/HEAD`、 `/package.json`、`/AGENTS.md`、`/wrangler.jsonc` 都能直接下载,且 `Bun.serve` 没有传 `hostname`,监听的是全部网卡,同一局域网内任何设备都能读到仓库和 .git。 - 新增 src/site.ts 作为唯一的内容边界定义(SITE_SOURCES/SITE_ENTRY/ NOT_FOUND_BODY/resolveSitePath),构建脚本、开发服务器与 Worker 共用同一份来源; - scripts/dev.ts 改为默认只监听 127.0.0.1,只服务 index.html、glossary、lessons, 目录地址返回 307 且只在目录真实存在时跳转,越界与缺失一律返回中文 404, 与生产环境(Cloudflare Worker)行为一致; - PORT/HOST 非法与端口占用改为中文可操作提示,不再直接抛 Bun 的英文报错; - 新增 tests/dev-server.test.ts(8 个测试)锁定边界、只监听本机、重定向与入参校验; - README、docs/roadmap.md 验收矩阵、docs/feature-checklist.md 与 tests/e2e/manual-checklist.md 同步补齐(E2E-08)。 bun test: 768 pass / 0 fail。 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
问题
bun run dev把整个仓库目录当静态根:/package.json、/AGENTS.md、/wrangler.jsonc同样是 200,而线上这些地址都是 404 —— 同一个地址在本地与线上表现不一致。Bun.serve又没有传hostname:于是同一局域网内的任何设备都能把仓库连同
.git读走。改动
src/site.ts(新增):SITE_SOURCES/SITE_ENTRY/NOT_FOUND_BODY/resolveSitePath,内容边界只定义一次,构建脚本、开发服务器与线上 Worker 共用同一份来源,避免再次漂移。scripts/dev.ts:默认只监听127.0.0.1(HOST可覆盖,要给别人看必须显式写0.0.0.0);只服务index.html、glossary/、lessons/;越界与缺失一律返回与线上一致的中文 404;/lessons/s1-01这类少了末尾斜杠的地址 307 跳转,且只在目录真实存在时跳(缺课地址直接 404,不绕弯);PORT/HOST非法与端口占用改成中文可操作提示,不再直接抛 Bun 的英文报错。scripts/build.ts/src/index.ts:改为引用同一份来源与同一句 404 文案。tests/dev-server.test.ts(新增,8 个测试):锁定只监听本机、站点内容 200、17 个仓库地址中文 404、19 种越界/编码写法全部挡下、重定向与 404 行为、PORT/HOST校验。README.md、docs/roadmap.md验收矩阵(新增中风险行)、docs/feature-checklist.md、tests/e2e/manual-checklist.md(新增 E2E-08)。验证
bun test:774 pass / 0 fail(62 个文件),基线 754,改动后逐轮上升。127.0.0.1:4173只监听回环;.git/config、.git/HEAD、package.json、AGENTS.md、wrangler.jsonc全部 404;/lessons/s1-01→ 307;bun run dev(--watch路径)与HOST=0.0.0.0 PORT=4199覆盖均正常,三种错误入参都给出中文提示。e2e:typed659/659、e2e:flow741/741、e2e:keyboard328/328、s1-01 88/88。边界
不涉及在线判题、账号、视频资产或 Node 工具链;仍全部使用 Bun。