feat: 证书探测改走国内机真 Node —— Workers 拿不到证书正文的兜底方案
根因:Workers 上 cloudflare:sockets 没有 getPeerCertificate, node:tls 的同名方法是桩函数(调用即抛 not implemented)。 - editor-api 新增 /ssl-probe 本地端点(真 Node,读对端证书正文): 不外发、不落盘;ssl 白名单放行,admin/ssl 可用,editor/匿名拒绝 - certprobe 改两级:首选国内机(带 X-Editor-Token),失败自动降级本地握手 - certProbe/certCheck 接线 EDITOR_API_BASE + EDITOR_TOKEN,撤掉 ?debug 诊断 - wrangler.toml 显式开 nodejs_compat(compat date 早于默认启用阈值) - 手写 node:tls 最小类型声明(保持零依赖) - seed-ssl-config.mjs 净化:真实凭据移到 secrets-backup/certkeeper-seeds.json, TOKEN_SECRET 改从 .dev.vars 读;脚本本体不含任何凭据 - role-perm 新增第 9 节 12 项(59/59),UI 探测 37 项全过
This commit is contained in:
1 parent
a40a92f526
commit
432cf5e398
9 files changed
+688
-63
No files matched your search
@@ -2,6 +2,13 @@ name = "artalk-cf"
|
||||
main = "src/index.ts"
|
||||
compatibility_date = "2026-07-24"
|
||||
|
||||
# ★ 证书探针需要 node:tls —— 只有它能在 Workers 里拿到**对端证书正文**
|
||||
# (`cloudflare:sockets` 的 Socket 接口没有 getPeerCertificate,
|
||||
# 实测线上只能确认「可达」但读不到 notAfter/SAN/issuer,那样证书管家等于瞎的)。
|
||||
# 2026-08-04 之后的 compatibility_date 才默认带 nodejs_compat,
|
||||
# 本项目定在 2026-07-24,所以必须显式打开这个 flag。
|
||||
compatibility_flags = ["nodejs_compat"]
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# ★ Workers Cache —— 缓存 Worker 自己生成的响应(无需回源 fetch)
|
||||
#
|
||||
|
||||
Reference in new issue
Block a user