P2: 清理与一致性

- CLI: --preset 实际生效;--directory-listing/--enable-stats/--enable-*/--ignore-hidden 支持 true/false(修复 type=bool 陷阱),未显式传入时不再覆盖 settings.json
- 版本号统一 v2.3(settings.json/config.py/v1/v2/Dockerfile)
- 移除硬编码 /tmp/pypi_debug.log 写文件;v2 裸 except 改记录错误返回 500
- webhook id 非法输入返回 400;下载趋势 timedelta 导入提升修复 NameError
- 打包模式 auth_token 写入 exe 目录(不再写入 _MEIPASS)
- README 修正: 线程池架构、pyinstaller 构建方式
- mirrors/__init__.py ' Quay.io' 笔误;chunked 响应去掉 Content-Length;docs/ui realpath 边界
- SQLite WAL+busy_timeout;下载计数原子 UPDATE
- requirements 移除未使用的 cachetools/apscheduler
This commit is contained in:
HYC Fixer
2026-08-30 12:25:26 +08:00
parent 237b99b480
commit dfae749612
12 changed files with 4020 additions and 3968 deletions
+3 -3
View File
@@ -668,7 +668,7 @@ class MirrorServerHandler(BaseHTTPRequestHandler):
file_path = os.path.join(docs_dir, rel_path)
# 防止目录遍历
if not os.path.realpath(file_path).startswith(os.path.realpath(docs_dir)):
if not os.path.realpath(file_path).startswith(os.path.realpath(docs_dir) + os.sep):
self.send_error(403, "Access denied")
return
@@ -765,7 +765,7 @@ class MirrorServerHandler(BaseHTTPRequestHandler):
file_path = os.path.join(ui_dir, rel_path)
# 防止目录遍历
if not os.path.realpath(file_path).startswith(os.path.realpath(ui_dir)):
if not os.path.realpath(file_path).startswith(os.path.realpath(ui_dir) + os.sep):
self.send_error(403, "Access denied")
return
@@ -1200,7 +1200,7 @@ class MirrorServerHandler(BaseHTTPRequestHandler):
mime_type, _ = mimetypes.guess_type(file_path)
self.send_response(200)
self.send_header("Content-Type", mime_type)
self.send_header("Content-Length", str(file_size))
# 使用 chunked 时不发送 Content-Length(协议不允许同时存在)
self.send_header("Content-Disposition",
f'attachment; filename="{self._safe_disposition_filename(file_path)}"')
self.send_header("Accept-Ranges", "bytes")