fix(httpapi): no-store 接线、图片缓存头时序、解压炸弹上限与 RSS 空日期

/api/admin/* 挂 NoStore、/api/me 内联 no-store(P1-3); 图片缓存头移至数据读取成功后,404 不携带 public immutable(P2-9); 上传先 DecodeConfig 限制像素 ≤2^25 再解码(P2-12); 无公开笔记时省略 lastBuildDate(P2-10)。
This commit is contained in:
2026-09-08 17:32:52 +08:00
parent ba7d5dd01f
commit 1272d680a8
6 changed files with 153 additions and 13 deletions
+6 -1
View File
@@ -65,6 +65,11 @@ func (s *Server) handleRSS(w http.ResponseWriter, r *http.Request) {
Description: html,
})
}
// 无公开笔记时省略 lastBuildDate(零值 Format 会产出公元 1 年的非法日期)
lastBuildStr := ""
if !lastBuild.IsZero() {
lastBuildStr = lastBuild.Format(time.RFC1123Z)
}
feed := rssFeed{
Version: "2.0",
Channel: rssChannel{
@@ -72,7 +77,7 @@ func (s *Server) handleRSS(w http.ResponseWriter, r *http.Request) {
Link: base + "/",
Description: ss.SiteDesc,
Language: "zh-CN",
LastBuild: lastBuild.Format(time.RFC1123Z),
LastBuild: lastBuildStr,
Items: items,
},
}