Skip to content

【规划】Issue #15 — 敏感配置加密存储 #64

Description

@suantea

背景

当前域名 API token、frp token、证书私钥等敏感信息以明文或简单 base64 存储。如果数据库泄露,所有凭据暴露。

目标

  • 所有敏感字段使用 AES-256-GCM 加密后落库
  • 解密密钥从环境变量 NETPANEL_SECRET_KEY 读取(启动时校验长度 ≥ 32 字节)
  • 加密/解密逻辑封装在 pkg/crypto/ 包,ORM hook 自动处理
  • 数据库迁移脚本自动加密已有明文数据(detected by 字段特征)

改动范围

  • pkg/crypto/aes.go:新增加密工具函数
  • model/models.go:敏感字段改为加密存储(DB tag encrypt:true)
  • backend/service/*/manager.go:读取时自动解密,写入时自动加密
  • API 响应中敏感字段返回 *** 而非明文(仅创建/编辑时回显一次)

关联 Issue

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions