# 生产环境配置 - PostgreSQL 数据库 [server] host = "0.0.0.0" # 服务器监听地址(0.0.0.0=允许所有网络访问) port = 3000 # 服务器监听端口(确保防火墙已开放) request_timeout_seconds = 30 max_body_bytes = 1048576 concurrency_limit = 256 rate_limit_per_minute = 120 cors_origins = ["https://example.com"] [database] database_type = "postgresql" # 数据库类型:sqlite/mysql/postgresql host = "localhost" # PostgreSQL 服务器地址 port = 5432 # PostgreSQL 端口(默认 5432) user = "postgres" # PostgreSQL 用户名(请创建专用用户) password = "postgres" # PostgreSQL 密码(请修改为强密码) database = "web_template" # 数据库名称(不存在会自动创建) max_connections = 20 # 最大连接数(生产环境建议 20-100) [auth] jwt_secret = "CHANGE_ME_WITH_AT_LEAST_32_RANDOM_CHARACTERS" # 必须通过部署配置替换 access_token_expiration_minutes = 15 # Access Token 过期时间(分钟) refresh_token_expiration_days = 7 # Refresh Token 过期时间(天) registration_open = true # 生产建议改为 false 或配合邀请码 invite_code = "" # 设置非空值则注册需邀请码(如 "shenjianl-2026") bootstrap_admin_email = "" # 首次部署可配置管理员邮箱,并同时设置强邀请码 [redis] enabled = true host = "localhost" # Redis 服务器地址 port = 6379 # Redis 端口(默认 6379) password = "" # Redis 密码(强烈建议设置密码) db = 0 # Redis 数据库编号(0-15) [email] enabled = false smtp_host = "smtp.example.com" smtp_port = 587 smtp_username = "" smtp_password = "" from_email = "noreply@example.com" from_name = "Email Unlimited" verification_code_ttl_seconds = 600 queue_enabled = true worker_pool_size = 4 # SMTP 收信服务(临时邮箱核心) [smtp] enabled = true listen_host = "0.0.0.0" listen_port = 25 hostname = "mail.shenjianl.cn" local_domains = ["mail.shenjianl.cn", "shenjianl.cn"] max_message_bytes = 1048576 connection_timeout_seconds = 30 max_recipients_per_message = 1 ip_connect_per_min = 20 domain_per_min = 10 rcpt_per_min = 10 require_ptr = true # 生产环境要求 PTR 记录 email_ttl_days = 7 mailbox_ttl_hours = 24 mailbox_max_quota_bytes = 10485760 address_local_part_len = 10 sender_per_min = 10 pair_per_10min = 5 greylist_enabled = true # 生产环境启用灰名单 greylist_retry_delay_seconds = 300 greylist_entry_ttl_seconds = 86400 quarantine_threshold = 60 score_weight_subject_code = 30 score_weight_spf_fail = 20 score_weight_ptr_missing = 15 score_weight_bad_attachment = 25 body_encryption_key = "" # 生产环境必须通过 SMTP__BODY_ENCRYPTION_KEY 注入 32 字节随机密钥 [abuse] domain_emails_threshold_10min = 50 ip_connects_threshold_1min = 60 auto_block_ttl_seconds = 3600 honeypot_addresses = ["admin@mail.shenjianl.cn", "noreply@mail.shenjianl.cn", "test@mail.shenjianl.cn"] alert_webhook_url = "" # 安全检查清单:部署前请确认 # ✅ 1. 已修改 jwt_secret 为强随机字符串 # ✅ 2. 已修改数据库密码为强密码 # ✅ 3. 已设置 Redis 密码 # ✅ 4. 已配置防火墙规则 # ✅ 5. 已启用 HTTPS(使用 Nginx/Caddy 等反向代理) # ✅ 6. 已设置数据库定期备份