diff --git a/README.md b/README.md index 9aafad6264..eb24b0d3d6 100644 --- a/README.md +++ b/README.md @@ -523,20 +523,20 @@ Additional security-related options are available in `config.yaml`: **⚠️ Security Warning: HTTP URL Configuration** -When `security.url_allowlist.enabled=false`, the system performs minimal URL validation by default, **rejecting HTTP URLs** and only allowing HTTPS. To allow HTTP URLs (e.g., for development or internal testing), you must explicitly set: +When `security.url_allowlist.enabled=false`, the system performs minimal URL validation and **allows HTTP URLs by default** (dev-friendly mode; Docker Compose deployments use the same default). For production, explicitly tighten this to HTTPS-only: ```yaml security: url_allowlist: enabled: false # Disable allowlist checks - allow_insecure_http: true # Allow HTTP URLs (⚠️ INSECURE) + allow_insecure_http: false # HTTPS only (recommended for production) ``` **Or via environment variable:** ```bash SECURITY_URL_ALLOWLIST_ENABLED=false -SECURITY_URL_ALLOWLIST_ALLOW_INSECURE_HTTP=true +SECURITY_URL_ALLOWLIST_ALLOW_INSECURE_HTTP=false ``` **Risks of allowing HTTP:** @@ -550,7 +550,7 @@ SECURITY_URL_ALLOWLIST_ALLOW_INSECURE_HTTP=true - ✅ Testing account connectivity before obtaining HTTPS - ❌ Production environments (use HTTPS only) -**Example error without this setting:** +**Example error for HTTP URLs when `allow_insecure_http: false` is set:** ``` Invalid base URL: invalid url scheme: http ``` diff --git a/README_CN.md b/README_CN.md index 1f8cac8b03..a93056282b 100644 --- a/README_CN.md +++ b/README_CN.md @@ -568,20 +568,20 @@ gateway: **⚠️ 安全警告:HTTP URL 配置** -当 `security.url_allowlist.enabled=false` 时,系统默认执行最小 URL 校验,**拒绝 HTTP URL**,仅允许 HTTPS。要允许 HTTP URL(例如用于开发或内网测试),必须显式设置: +当 `security.url_allowlist.enabled=false` 时,系统仅执行最小 URL 校验,且**默认允许 HTTP URL**(开发友好模式,Docker Compose 部署的默认值一致)。生产环境建议显式收紧为仅允许 HTTPS: ```yaml security: url_allowlist: enabled: false # 禁用白名单检查 - allow_insecure_http: true # 允许 HTTP URL(⚠️ 不安全) + allow_insecure_http: false # 仅允许 HTTPS(生产环境推荐) ``` **或通过环境变量:** ```bash SECURITY_URL_ALLOWLIST_ENABLED=false -SECURITY_URL_ALLOWLIST_ALLOW_INSECURE_HTTP=true +SECURITY_URL_ALLOWLIST_ALLOW_INSECURE_HTTP=false ``` **允许 HTTP 的风险:** @@ -595,7 +595,7 @@ SECURITY_URL_ALLOWLIST_ALLOW_INSECURE_HTTP=true - ✅ 获取 HTTPS 前测试账号连通性 - ❌ 生产环境(仅使用 HTTPS) -**未设置此项时的错误示例:** +**设置 `allow_insecure_http: false` 后,HTTP URL 会返回如下错误:** ``` Invalid base URL: invalid url scheme: http ``` diff --git a/README_JA.md b/README_JA.md index 684e685c8f..bd154a9a6b 100644 --- a/README_JA.md +++ b/README_JA.md @@ -521,20 +521,20 @@ default: **⚠️ セキュリティ警告: HTTP URL 設定** -`security.url_allowlist.enabled=false` の場合、システムはデフォルトで最小限の URL バリデーションを行い、**HTTP URL を拒否**して HTTPS のみを許可します。HTTP URL を許可するには(開発環境や内部テスト用など)、以下を明示的に設定する必要があります: +`security.url_allowlist.enabled=false` の場合、システムは最小限の URL バリデーションのみを行い、**デフォルトで HTTP URL を許可**します(開発フレンドリーモード。Docker Compose デプロイのデフォルトも同じです)。本番環境では、以下のように明示的に HTTPS のみに制限することを推奨します: ```yaml security: url_allowlist: enabled: false # 許可リストチェックを無効化 - allow_insecure_http: true # HTTP URL を許可(⚠️ セキュリティリスクあり) + allow_insecure_http: false # HTTPS のみ許可(本番環境推奨) ``` **または環境変数で設定:** ```bash SECURITY_URL_ALLOWLIST_ENABLED=false -SECURITY_URL_ALLOWLIST_ALLOW_INSECURE_HTTP=true +SECURITY_URL_ALLOWLIST_ALLOW_INSECURE_HTTP=false ``` **HTTP を許可するリスク:** @@ -548,7 +548,7 @@ SECURITY_URL_ALLOWLIST_ALLOW_INSECURE_HTTP=true - ✅ HTTPS 取得前のアカウント接続テスト - ❌ 本番環境(HTTPS のみを使用) -**この設定なしで表示されるエラー例:** +**`allow_insecure_http: false` 設定時に HTTP URL で表示されるエラー例:** ``` Invalid base URL: invalid url scheme: http ``` diff --git a/deploy/.env.example b/deploy/.env.example index d8892dbecf..5925f0abb4 100644 --- a/deploy/.env.example +++ b/deploy/.env.example @@ -359,11 +359,11 @@ DASHBOARD_AGGREGATION_RETENTION_DAILY_DAYS=730 # 启用 URL 白名单验证(false 则跳过白名单检查,仅做基本格式校验) SECURITY_URL_ALLOWLIST_ENABLED=false -# 关闭白名单时,是否允许 http:// URL(默认 false,只允许 https://) -# ⚠️ 警告:允许 HTTP 存在安全风险(明文传输),仅建议在开发/测试环境或可信内网中使用 -# Allow insecure HTTP URLs when allowlist is disabled (default: false, requires https) +# 关闭白名单时,是否允许 http:// URL(默认 true,设为 false 则只允许 https://) +# ⚠️ 警告:允许 HTTP 存在安全风险(明文传输),生产环境建议设为 false +# Allow insecure HTTP URLs when allowlist is disabled (default: true; set to false to require https) # ⚠️ WARNING: Allowing HTTP has security risks (plaintext transmission) -# Only recommended for dev/test environments or trusted networks +# Recommended to set false in production SECURITY_URL_ALLOWLIST_ALLOW_INSECURE_HTTP=true # 是否允许本地/私有 IP 地址用于上游/定价/CRS(仅在可信网络中使用) diff --git a/deploy/config.example.yaml b/deploy/config.example.yaml index 5a3afb0315..eff4bfb598 100644 --- a/deploy/config.example.yaml +++ b/deploy/config.example.yaml @@ -108,8 +108,8 @@ security: # Allow localhost/private IPs for upstream/pricing/CRS (use only in trusted networks) # 允许本地/私有 IP 地址用于上游/定价/CRS(仅在可信网络中使用) allow_private_hosts: true - # Allow http:// URLs when allowlist is disabled (default: false, require https) - # 白名单禁用时是否允许 http:// URL(默认: false,要求 https) + # Allow http:// URLs when allowlist is disabled (default: true; set to false to require https) + # 白名单禁用时是否允许 http:// URL(默认: true,设为 false 则仅允许 https) allow_insecure_http: true response_headers: # Enable configurable response header filtering (default: true) diff --git a/deploy/docker-compose.local.yml b/deploy/docker-compose.local.yml index 21f46e3760..042752e857 100644 --- a/deploy/docker-compose.local.yml +++ b/deploy/docker-compose.local.yml @@ -139,10 +139,10 @@ services: # ======================================================================= # Enable URL allowlist validation (false to skip allowlist checks) - SECURITY_URL_ALLOWLIST_ENABLED=${SECURITY_URL_ALLOWLIST_ENABLED:-false} - # Allow insecure HTTP URLs when allowlist is disabled (default: false, requires https) - - SECURITY_URL_ALLOWLIST_ALLOW_INSECURE_HTTP=${SECURITY_URL_ALLOWLIST_ALLOW_INSECURE_HTTP:-false} - # Allow private IP addresses for upstream/pricing/CRS (for internal deployments) - - SECURITY_URL_ALLOWLIST_ALLOW_PRIVATE_HOSTS=${SECURITY_URL_ALLOWLIST_ALLOW_PRIVATE_HOSTS:-false} + # Allow insecure HTTP URLs when allowlist is disabled (default: true; set to false to require https) + - SECURITY_URL_ALLOWLIST_ALLOW_INSECURE_HTTP=${SECURITY_URL_ALLOWLIST_ALLOW_INSECURE_HTTP:-true} + # Allow private IP addresses for upstream/pricing/CRS (default: true; set to false to block private hosts) + - SECURITY_URL_ALLOWLIST_ALLOW_PRIVATE_HOSTS=${SECURITY_URL_ALLOWLIST_ALLOW_PRIVATE_HOSTS:-true} # Upstream hosts whitelist (comma-separated, only used when enabled=true) - SECURITY_URL_ALLOWLIST_UPSTREAM_HOSTS=${SECURITY_URL_ALLOWLIST_UPSTREAM_HOSTS:-} diff --git a/deploy/docker-compose.yml b/deploy/docker-compose.yml index 3da3bcbfb0..22713c59aa 100644 --- a/deploy/docker-compose.yml +++ b/deploy/docker-compose.yml @@ -135,10 +135,10 @@ services: # ======================================================================= # Enable URL allowlist validation (false to skip allowlist checks) - SECURITY_URL_ALLOWLIST_ENABLED=${SECURITY_URL_ALLOWLIST_ENABLED:-false} - # Allow insecure HTTP URLs when allowlist is disabled (default: false, requires https) - - SECURITY_URL_ALLOWLIST_ALLOW_INSECURE_HTTP=${SECURITY_URL_ALLOWLIST_ALLOW_INSECURE_HTTP:-false} - # Allow private IP addresses for upstream/pricing/CRS (for internal deployments) - - SECURITY_URL_ALLOWLIST_ALLOW_PRIVATE_HOSTS=${SECURITY_URL_ALLOWLIST_ALLOW_PRIVATE_HOSTS:-false} + # Allow insecure HTTP URLs when allowlist is disabled (default: true; set to false to require https) + - SECURITY_URL_ALLOWLIST_ALLOW_INSECURE_HTTP=${SECURITY_URL_ALLOWLIST_ALLOW_INSECURE_HTTP:-true} + # Allow private IP addresses for upstream/pricing/CRS (default: true; set to false to block private hosts) + - SECURITY_URL_ALLOWLIST_ALLOW_PRIVATE_HOSTS=${SECURITY_URL_ALLOWLIST_ALLOW_PRIVATE_HOSTS:-true} # Upstream hosts whitelist (comma-separated, only used when enabled=true) - SECURITY_URL_ALLOWLIST_UPSTREAM_HOSTS=${SECURITY_URL_ALLOWLIST_UPSTREAM_HOSTS:-}