diff --git a/docs/DEV_SETUP.md b/docs/DEV_SETUP.md index ff11791d..742678ba 100644 --- a/docs/DEV_SETUP.md +++ b/docs/DEV_SETUP.md @@ -171,9 +171,11 @@ RELEASE_REMOTE_URL=https://peilian.njzhmj.top ./scripts/release-preflight.sh RELEASE_REMOTE_URL=https://peilian.njzhmj.top RELEASE_VERIFY_REMOTE_MATCH=true ./scripts/release-preflight.sh # 同时校验线上 schema、资料处理连接 SQL 与后端 jar;后端发布验收不得省略 schema 门禁 RELEASE_REMOTE_URL=https://peilian.njzhmj.top RELEASE_VERIFY_REMOTE_MATCH=true RELEASE_VERIFY_REMOTE_SCHEMA=true RELEASE_VERIFY_REMOTE_BACKEND=true ./scripts/release-preflight.sh +# 仅发布后端时,显式跳过未发布的管理端/H5 hash;后端模块和 schema 仍会严格校验 +RELEASE_REMOTE_URL=https://peilian.njzhmj.top RELEASE_VERIFY_REMOTE_MATCH=true RELEASE_VERIFY_REMOTE_STATIC=false RELEASE_VERIFY_REMOTE_SCHEMA=true RELEASE_VERIFY_REMOTE_BACKEND=true ./scripts/release-preflight.sh ``` -`RELEASE_VERIFY_REMOTE_BACKEND=true` 必须与 `RELEASE_VERIFY_REMOTE_MATCH=true`、`RELEASE_VERIFY_REMOTE_SCHEMA=true` 同时使用;预检会同时打印整包 jar SHA-256 和 `ruoyi-aihr` 模块内容 SHA-256,实际匹配以模块内容 hash 为准。schema 门禁会拒绝 AIHR 与框架租户字段排序规则不一致,并执行资料处理页依赖的 `aihr_knowledge_attach`/`sys_oss` 连接检查。远端后端默认核对 `/opt/wygj/app/ruoyi-admin.jar`,如发布路径不同可通过 `RELEASE_REMOTE_BACKEND_PATH` 覆盖;路径必须是安全的绝对路径。 +`RELEASE_VERIFY_REMOTE_BACKEND=true` 必须与 `RELEASE_VERIFY_REMOTE_MATCH=true`、`RELEASE_VERIFY_REMOTE_SCHEMA=true` 同时使用;预检会同时打印整包 jar SHA-256 和 `ruoyi-aihr` 模块内容 SHA-256,实际匹配以模块内容 hash 为准。schema 门禁会拒绝 AIHR 与框架租户字段排序规则不一致,并执行资料处理页依赖的 `aihr_knowledge_attach`/`sys_oss` 连接检查。`RELEASE_VERIFY_REMOTE_STATIC=false` 只允许用于后端单组件发布,避免用未发布的本地静态包覆盖或阻断线上前端;默认仍严格核对管理端和 H5。远端后端默认核对 `/opt/wygj/app/ruoyi-admin.jar`,如发布路径不同可通过 `RELEASE_REMOTE_BACKEND_PATH` 覆盖;路径必须是安全的绝对路径。 带 `RELEASE_REMOTE_URL` 时,预检同时校验租户接口 JSON 的业务 `code=200`;HTTP 200 但业务返回 401/405 会判定失败。 diff --git a/scripts/release-preflight.sh b/scripts/release-preflight.sh index d04fac0a..feb0fe6c 100755 --- a/scripts/release-preflight.sh +++ b/scripts/release-preflight.sh @@ -217,22 +217,26 @@ if [[ -n "${RELEASE_REMOTE_URL:-}" ]]; then fi if [[ "${RELEASE_VERIFY_REMOTE_MATCH:-false}" == "true" ]]; then - remote_frontend_asset="$(curl -fsS --max-time 15 "$remote/" | sed -nE 's/.*src="(\/assets\/[^" ]+\.js)".*/\1/p' | head -n 1)" - remote_mobile_asset="$(curl -fsS --max-time 15 "$remote/h5/" | sed -nE 's/.*src="(\/h5\/assets\/[^" ]+\.js)".*/\1/p' | head -n 1)" - [[ "$remote_frontend_asset" == /assets/*.js ]] || fail "remote frontend entry asset not found" - [[ "$remote_mobile_asset" == /h5/assets/*.js ]] || fail "remote mobile H5 entry asset not found" + if [[ "${RELEASE_VERIFY_REMOTE_STATIC:-true}" == "true" ]]; then + remote_frontend_asset="$(curl -fsS --max-time 15 "$remote/" | sed -nE 's/.*src="(\/assets\/[^" ]+\.js)".*/\1/p' | head -n 1)" + remote_mobile_asset="$(curl -fsS --max-time 15 "$remote/h5/" | sed -nE 's/.*src="(\/h5\/assets\/[^" ]+\.js)".*/\1/p' | head -n 1)" + [[ "$remote_frontend_asset" == /assets/*.js ]] || fail "remote frontend entry asset not found" + [[ "$remote_mobile_asset" == /h5/assets/*.js ]] || fail "remote mobile H5 entry asset not found" - remote_frontend_sha256="$(curl -fsS --max-time 15 "$remote$remote_frontend_asset" | sha256_stream)" - remote_mobile_sha256="$(curl -fsS --max-time 15 "$remote$remote_mobile_asset" | sha256_stream)" - local_frontend_sha256="$(sha256 "$frontend_asset_path")" - local_mobile_sha256="$(sha256 "$mobile_asset_path")" - echo "remote_frontend_asset=$remote_frontend_asset" - echo "remote_frontend_asset_sha256=$remote_frontend_sha256" - echo "remote_mobile_asset=$remote_mobile_asset" - echo "remote_mobile_asset_sha256=$remote_mobile_sha256" - [[ "$remote_frontend_sha256" == "$local_frontend_sha256" ]] || fail "remote frontend asset does not match local build" - [[ "$remote_mobile_sha256" == "$local_mobile_sha256" ]] || fail "remote mobile H5 asset does not match local build" - echo "remote_asset_match=true" + remote_frontend_sha256="$(curl -fsS --max-time 15 "$remote$remote_frontend_asset" | sha256_stream)" + remote_mobile_sha256="$(curl -fsS --max-time 15 "$remote$remote_mobile_asset" | sha256_stream)" + local_frontend_sha256="$(sha256 "$frontend_asset_path")" + local_mobile_sha256="$(sha256 "$mobile_asset_path")" + echo "remote_frontend_asset=$remote_frontend_asset" + echo "remote_frontend_asset_sha256=$remote_frontend_sha256" + echo "remote_mobile_asset=$remote_mobile_asset" + echo "remote_mobile_asset_sha256=$remote_mobile_sha256" + [[ "$remote_frontend_sha256" == "$local_frontend_sha256" ]] || fail "remote frontend asset does not match local build" + [[ "$remote_mobile_sha256" == "$local_mobile_sha256" ]] || fail "remote mobile H5 asset does not match local build" + echo "remote_asset_match=true" + else + echo "remote_static_match=skipped" + fi if [[ "${RELEASE_VERIFY_REMOTE_BACKEND:-false}" == "true" ]]; then command -v ssh >/dev/null 2>&1 || fail "ssh is required for remote backend verification"