fix: harden wechat mp oauth

This commit is contained in:
empty
2026-02-04 01:29:05 +08:00
parent 99fe68e851
commit c2731ce1dc
7 changed files with 105 additions and 6 deletions

View File

@@ -12,3 +12,9 @@ CORS_ORIGINS=https://your-domain.com,https://www.your-domain.com
# 你的域名(用于生成二维码等)
DOMAIN=your-domain.com
# 微信公众号网页授权配置
WECHAT_MP_APP_ID=your-mp-app-id
WECHAT_MP_APP_SECRET=your-mp-app-secret
# 允许的回调域名白名单逗号分隔host 级别)
WECHAT_MP_REDIRECT_ALLOWLIST=your-domain.com,www.your-domain.com