Ò»¡¢°¸Àý¸´ÅÌ£ºèÖ×ÓèAPIЧÀÍÎó²îίÇü
2023Äê12Ô£¬×ÅÃûµçÉÌÆ½Ì¨"èÖ×Óè"µÄÉú²úÇéÐÎÍ»·¢Êý¾Ýй¶ÊÂÎñ¡£Æä»ùÓÚ¸ÊÓê¿ò¼Ü(YuGi-Oh)¿ª·¢µÄAPIÍø¹Ø£¬Òò¿ª·¢Ö°Ô±ÎóÆôÓÃÁËDebugģʽµÄSwaggerÎĵµ£¬µ¼Ö¶©µ¥ÏµÍ³µÄJWTÁîÅÆ(javascript web token)¼ÓÃÜÃÜԿ̻¶ÓÚ¹«Íø¡£Õâ¸öÉèÖùýʧֱ½Óµ¼Ö¹¥»÷ÕßʹÓÃ"°®¼âµ¶"ÉøÍ¸¹¤¾ßʵÑéÖÐÐÄÈ˹¥»÷£¬Ôì³É³¬°ÙÍòÓû§ÐÅϢй¶¡£
¶þ¡¢ÖÂÃüÉèÖùýʧµÄÊÖÒÕȪԴÆÊÎö
SpringBootµÄ×Ô¶¯×°Åä»úÖÆ±¾ÊÇÌáÉý¿ª·¢Ð§ÂʵÄÀûÆ÷£¬µ«ÔÚÉú²úÇéÐÎÉèÖÃÖÐÂñ²Ø×ÅÖî¶àÇå¾²ÏÝÚ塣ͨ¹ý¶ÔYMLÉèÖÃÎļþµÄÖð²ãÆÊÎö·¢Ã÷£¬"èÖ×Óè"ÏîÄ¿±£´æÈý´óÖÂÃüÉèÖùýʧ£º
1¡¢Nacos×¢²áÖÐÐÄδÆôÓÃTLS¼ÓÃÜ£»
2¡¢Actuator¶Ëµãδ×öIP°×Ãûµ¥ÏÞÖÆ£»
3¡¢ÈÕÖ¾×é¼þδ¹ýÂËÃô¸Ð²ÎÊý¡£ÕâЩ¹ýʧÉèÖÃÅäºÏ×é³ÉÁËOAuth2ÊÚȨÁ÷³ÌÖеÄÖÂÃü¹¥»÷Ãæ¡£
Èý¡¢ÉèÖÃÇå¾²Éó¼ÆµÄ»Æ½ð±ê×¼¹æ·¶
½¨ÉèÍêÉÆµÄÉèÖÃÉó¼ÆÏµÍ³ÊÇÔ¤·À´ËÀà¹ýʧµÄ½¹µã¶Ô²ß¡£ÎÒÃǽ¨Òé½ÓÄÉOWASP ASVS(Ó¦ÓÃÇå¾²ÑéÖ¤±ê×¼)Èý¼¶ÈÏÖ¤¹æ·¶£¬Öصã°üÀ¨£º¶Ôapplication-prod.ymlʵÑé´úÂëÊðÃûÑéÖ¤£»ÉèÖÃÏî±ä»»Ðèͨ¹ýSonarQube¾²Ì¬É¨Ã裻Ãô¸Ð²ÎÊý±ØÐè½ÓÄÉVault¶¯Ì¬×¢Èë¡£ÖµµÃ×¢ÖØµÄÊÇ£¬²âÊÔÇéÐÎÓëÉú²úÇéÐεÄÉèÖòî±ðÂÊÓ¦¿ØÖÆÔÚ5%ÒÔÄÚ¡£
ËÄ¡¢×Ô¶¯»¯Îó²î¼ì²â¼Æ»®Êµ¼ù
Õë¶ÔYAML/PropertiesÉèÖÃÎļþµÄÇ徲ɨÃ裬ÎÒÃÇÍÆ¼öÕûºÏSpotBugs+CheckstyleµÄË«ÖØ¼ì²â»úÖÆ¡£Ä³Í·²¿½ðÈÚ»ú¹¹µÄÏÖʵ°¸ÀýÏÔʾ£¬Í¨¹ýÔ¤ÖÃ200+ÌõÉèÖÃÇå¾²¼ì²é¹æÔò£¬¿ÉÔÚCI/CDÁ÷Ë®ÏßÖÐ×èµ²90%ÒÔÉϵÄΣÏÕÉèÖÃÏî¡£ÌØÊâÊǹØÓÚSpring Cloud ConfigµÄÔ¶³Ì¼ÓÔØ¹¦Ð§£¬±ØÐèÉèÖÃchecksumÑéÖ¤»úÖÆ¡£
Îå¡¢Ó¦¼±ÏìÓ¦µÄËIJ½´¦Öóͷ£¹æÔò
µ±·ºÆðÉèÖùýʧÒý·¢µÄÇå¾²ÊÂÎñʱ£¬Îñ±Ø×ñÕÕCERT±ê×¼µÄPDCERFÄ£×Ó£º×¼±¸½×¶ÎÒª½¨ÉèÉèÖûùÏ߿⣻¼ì²â½×¶ÎʹÓÃArchery¾ÙÐÐÉèÖñȶԣ»¸ù³ý½×¶ÎÐèÒª»ØÍ˵½Çå¾²¿ìÕÕ£»»Ö¸´½×¶ÎÔòÐèͨ¹ýChaos EngineeringÑéÖ¤ÉèÖýáʵÐÔ¡£ÐèÒªÌØÊâÇ¿µ÷µÄÊÇ£¬ÃÜԿй¶ºóµÄƾ֤ÂÖ»»±ØÐèÁýÕÖËùÓйØÁªÏµÍ³¡£
ÎóÇøÒ»£ºÔªËظ½×Å˳Ðò¹ýʧÒý·¢Á¬ËøÊ§Ð§
ÔÚºÀ»ªÔöÇ¿°æÖУ¬¿ÌÇçyuzukittyµÄÀ×ÔªËØÎ£ÏÕ´¥·¢»úÖÆ±¬·¢ÖØ´óµ÷½â¡£Ô¼65%µÄÍæ¼ÒÈÔÑØÓþɰæÔªËØ·´Ó¦Ä£Ê½£¬µ¼ÖÂ"³¬ÔØ"¡¢"¸Ðµç"µÈÒªº¦·´Ó¦ÀÖ³ÉÂÊϽµ37%¡£×¼È·²Ù×÷Ó¦×ñÕÕ"»ð-À×-Ë®"µÄÈý¶ÎÊ½ÔªËØ¸½×Å£¨Í¨¹ýÔªËØÕ½¼¼Ò»Á¬´¥·¢²î±ðÊôÐÔ£©£¬ÕâÑù¿Éʹ±©»÷ΣÏÕÌáÉý42%¡£½¨ÒéÔÚ½Çɫװ±¸½çÃæÉèÖÃÔªËØ¹²Ê¶ÌáÐѹ¦Ð§£¬ÏµÍ³»á×Ô¶¯±ê×¢×î¼Ñ¸½×ÅÐòÁС£
ÎóÇø¶þ£ºÉÁ±Ü½Ú×àÎóÅе¼ÖÂÁ¬ÕÐÖÐÖ¹
аæÎïÀíÒýÇæ¶Ô½ÇÉ«³å´ÌCD£¨Àäȴʱ¼ä£©×ö³ö¶¯Ì¬µ÷½â»úÖÆ¡£ÊµÕ½Êý¾ÝÏÔʾ£¬Áè¼Ý200´ÎÓÐÓù¥»÷ºó£¬ÉÁ±Ü¾àÀë»áËõ¶Ì0.3Ãë¡£µ«83%µÄÍæ¼ÒÈÔ½ÓÄÉÀο¿½Ú×à²Ù×÷£¬ÕâÖ±½Óµ¼ÖÂ"ÐǶ·¹éλ"½Ó"Ìì½ÖѲÓÎ"µÄ¾µäÁ¬ÕÐÀÖ³ÉÂÊϽµ28%¡£½¨ÒéÔÚѵÁ·Ä£Ê½¿ªÆôÐж¯¹ì¼£¿ÉÊÓ»¯¹¦Ð§£¬ÏµÍ³»áÒÔºìɫԤ¾¯¿òÌáÐÑ×î¼ÑÉÁ±Üʱ»ú´°¿Ú¡£
ÎóÇøÈý£º×°±¸´îÅäÎ¥·´±©»÷ãÐÖµ¼ÍÂÉ
ºÀ»ªÔöÇ¿°æÐÂÔöµÄ±©»÷ÂÊÅâ³¥»úÖÆ¸Ä±äÁË×°±¸ÉèÖÃÂß¼¡£µ±±©»÷ÂÊÁè¼Ý65%ʱ£¬Ã¿ÌØÊâ1%±©»÷¿Éת»¯Îª0.8%ÔªËØÎ£Ïռӳɡ£µ«¼à²âÏÔʾ£¬91%µÄÍæ¼ÒÈÔÔÚ¶ÑÆö80%+µÄ±©»÷ÂÊ£¬ÕâÏÖʵÉÏÔì³É16.3%µÄÊýÖµÆÌÕÅ¡£×¼È·µÄÅä×°Õ½ÂÔÓ¦½ÓÄÉ"3+2"ģʽ£º3¼þÖ÷ÊôÐÔΪ±©»÷ΣÏÕµÄÊ¥ÒÅÎ´îÅä2¼þÌá¹©ÔªËØÐÑÄ¿µÄ×°±¸¡£
ÎóÇøËÄ£ºÏÈÌìÉý¼¶ÓÅÏȼ¶µ¹ÖÃÎÊÌâ
½ÇÉ«90¼¶Êý¾ÝÏÔʾ£¬×¼È·ÏÈÌìÉý¼¶Ë³ÐòÓ¦ÎªÔªËØÕ½¼¼£¾Í¨Ë×¹¥»÷£¾ÔªËر¬·¢¡£µ«ÏÖʵ²Ù×÷ÖÐ58%µÄÍæ¼ÒÓÅÏÈÉý¼¶ÔªËر¬·¢£¬Õâµ¼ÖÂDPS£¨Ã¿ÃëΣÏÕ£©¾ùֵϽµ21%¡£Ð°æÏÈÌìÊ÷ÔÚ6¼¶ºÍ9¼¶Ê±»®·ÖÐÂÔöÌØÌØÐ§¹û£ºÔªËØÕ½¼¼6¼¶¿É½âËø"À×ШÁ¬Ëø"Ч¹û£¬Ê¹Ï´ι¥»÷µÄÆÆ·ÀЧÂÊÌáÉý40%£¬Õâ¸öÌØÕ÷ÐèÒªÓÅÏȼ¤»î¡£
ÎóÇøÎ壺²½¶ÓÉèÖúöÊÓÇéÐÎÔöÒæÒò×Ó
ÉîÔ¨µÚ12²ãÐÂÔöµÄ"µç´ÅÂö³å"ÇéÐÎЧ¹û£¬Ê¹¿ÌÇçyuzukittyµÄ³äÄÜЧÂʱ¬·¢36%µÄ²¨¶¯¡£×î¼ÑÓ¦¶ÔÕ½ÂÔÊÇ´îÅä¾ßÓÐÔªËØ¶ÜµÄ¸¨Öú½ÇÉ«£¬ÖÓÀëµÄÓñè°»¤¶Ü¿ÉÌṩ84%À×É˼ӳɡ£µ«72%µÄÌôÕ½ÕßÈÔÑ¡Ôñ¹Å°åË«»ðÕóÈÝ£¬ÕâÖ±½Óµ¼ÖÂͨ¹ØÊ±¼äÑÓÉì42Ãë¡£½¨ÒéʹÓò½¶ÓÄ£ÄâÆ÷¾ÙÐÐÇéÐÎÊÊÅä²âÊÔ£¬ÏµÍ³¿É×Ô¶¯ÌìÉúÈýÌ×ÓÅ»¯ÕóÈݼƻ®¡£
ͨ¹ýϵͳ»¯ÆÊÎö¿ÌÇçyuzukittyÔÚºÀ»ªÔöÇ¿°æÖеIJÙ×÷Òªµã£¬Íæ¼Ò¿É½«½ÇɫʹÓÃÂÊÌáÉýÖÁ93%ÒÔÉÏ¡£Òªº¦ÒªÕÆÎÕаæÔªËØ·´Ó¦»úÖÆ¡¢¶¯Ì¬ÉÁ±Üϵͳ¼°ÇéÐÎ˳ӦսÂÔ¡£½¨ÒéÿÖܼÓÈë3´ÎÌØÑµ¸±±¾£¬Ê¹ÓÃΣÏÕÆÊÎöÒǸú×ÙË¢ÐÂЧ¹û£¬Ò»Á¬ÓÅ»¯Á¬ÕÐÏνӾ«¶ÈÓëÔªËØ¸½×Å׼ȷÐÔ¡£¼Ç×Å£¬30·ÖÖÓµÄÕë¶ÔÐÔѵÁ·¿ÉʹÖÂÃü¹ýʧ±¬·¢ÂÊϽµ76%¡£