Skip to content

Commit e27dfe2

Browse files
authored
Merge pull request #201 from HackForger/v0.1-dev/hackforger
chore(security): promote public boundary cleanup to prod
2 parents 219c98f + a341cc3 commit e27dfe2

294 files changed

Lines changed: 235 additions & 60992 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.claude/hookify.protect-archive-branches.local.md‎

Lines changed: 0 additions & 33 deletions
This file was deleted.

‎.claude/hookify.protect-worktrees.local.md‎

Lines changed: 0 additions & 32 deletions
This file was deleted.

‎.claude/projects/-Users-h2oslabs-Workspace-hackforger/memory/feedback_e2e_web_mandatory.md‎

Lines changed: 0 additions & 15 deletions
This file was deleted.

‎.claude/settings.json‎

Lines changed: 1 addition & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -4,9 +4,7 @@
44
"Bash(bash scripts/restart-gitea.sh)",
55
"Bash(bash scripts/restart-gitea.sh *)",
66
"Bash(./scripts/restart-gitea.sh)",
7-
"Bash(./scripts/restart-gitea.sh *)",
8-
"Bash(/Users/h2oslabs/Workspace/hackforger/scripts/restart-gitea.sh)",
9-
"Bash(/Users/h2oslabs/Workspace/hackforger/scripts/restart-gitea.sh *)"
7+
"Bash(./scripts/restart-gitea.sh *)"
108
]
119
},
1210
"hooks": {
@@ -17,14 +15,6 @@
1715
{
1816
"type": "command",
1917
"command": "if echo \"$CLAUDE_TOOL_INPUT\" | grep -qE '\\btea\\s+(issue|pr|repo|release|login)'; then echo 'BLOCKED: Please use `gh` instead of `tea`. tea is the Forgejo/Codeberg CLI; we develop on GitHub. Equivalent: gh issue / gh pr / gh repo.' >&2; exit 2; fi"
20-
},
21-
{
22-
"type": "command",
23-
"command": "if echo \"$CLAUDE_TOOL_INPUT\" | grep -qE 'codeberg\\.org/(Synnovator|HackForge)'; then echo 'BLOCKED: The project is hosted on GitHub, not Codeberg. Correct address: github.com/HackForger/hackforger' >&2; exit 2; fi"
24-
},
25-
{
26-
"type": "command",
27-
"command": "if echo \"$CLAUDE_TOOL_INPUT\" | grep -qE 'hackforge\\.inside\\.h2os\\.cloud'; then echo 'BLOCKED: The internal instance address is hackforger.inside.h2os.cloud (with r). Please update the URL.' >&2; exit 2; fi"
2818
}
2919
]
3020
},

‎.github/ISSUE_TEMPLATE/1-bug.yml‎

Lines changed: 19 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -14,17 +14,17 @@ body:
1414
id: page_url
1515
attributes:
1616
label: 出问题的页面 URL
17-
description: 完整地址。如果是登录后才能看到的页面,**也直接贴 URL**,我们能猜到要登录哪个账户。
18-
placeholder: "https://www.synnovator.com/hackathon/opc-2026-xxxxx"
17+
description: 请使用中立测试实例或脱敏路径;不要公开生产域名、内部地址、查询参数中的令牌或客户标识。
18+
placeholder: "https://hackforger.example.invalid/hackathon/example-event"
1919
validations:
2020
required: true
2121

2222
- type: input
2323
id: account
2424
attributes:
2525
label: 你用什么账号操作的?
26-
description: 用户名(不要填密码)。如果是匿名访问,写 `匿名`。
27-
placeholder: "linyilun"
26+
description: 只填写可公开的测试用户名(绝不填写密码、真实生产账号或个人身份);匿名访问写 `匿名`。
27+
placeholder: "example-user"
2828
validations:
2929
required: true
3030

@@ -35,10 +35,10 @@ body:
3535
description: |
3636
从打开浏览器开始一步一步写。最理想是别人按你这个步骤一定能看到同样的现象。
3737
placeholder: |
38-
1. 用 linyilun 账号登录
39-
2. 打开 https://www.synnovator.com/hackathon/opc-2026-shuzhi-w1
38+
1. 用测试账号登录
39+
2. 打开对应活动页面
4040
3. 点页面右下角"报名"区
41-
4. 在"选择仓库"下拉框里找 H2OSLabs/page.h2oslabs.com
41+
4. 在"选择仓库"下拉框里查找有权限的组织仓库
4242
value: |
4343
1.
4444
2.
@@ -51,7 +51,7 @@ body:
5151
attributes:
5252
label: 期望看到 / 期望发生的事
5353
description: 一两句话即可。
54-
placeholder: 下拉里应该列出我所属的 H2OSLabs 组织的所有可写仓库,包括 page.h2oslabs.com
54+
placeholder: 下拉里应该列出我所属组织的所有可写仓库
5555
validations:
5656
required: true
5757

@@ -71,6 +71,7 @@ body:
7171
description: |
7272
**强烈建议**贴 1-3 张截图(直接拖图到这个框里就会自动上传)。一张图胜过一千字。
7373
如果是涉及多步操作的 bug,请截图关键步骤;如果有错误弹窗 / 红字提示,必须截图。
74+
上传前必须遮盖真实用户名、邮箱、令牌、内部域名、客户数据和其他非公开信息。
7475
placeholder: 直接拖拽图片到这里
7576
validations:
7677
required: false
@@ -93,8 +94,8 @@ body:
9394
attributes:
9495
label: 你在哪个环境测的?
9596
options:
96-
- "线上 https://www.synnovator.com"
97-
- "内网 https://hackforger.inside.h2os.cloud"
97+
- "生产实例"
98+
- "预发布 / 测试实例"
9899
- "本地开发实例"
99100
- "其他(请在描述里说明)"
100101
validations:
@@ -116,3 +117,11 @@ body:
116117
description: 比如"以前能用,今天突然不行"、"换个账号就好了"、"前几天 #134 改了相关功能可能有影响"等线索都欢迎写在这里。
117118
validations:
118119
required: false
120+
121+
- type: checkboxes
122+
id: public-boundary
123+
attributes:
124+
label: 公开信息确认
125+
options:
126+
- label: 我已确认本 issue 不含凭据、内部地址、真实生产账号、客户数据或未脱敏截图。
127+
required: true

‎.github/ISSUE_TEMPLATE/2-feature.yml‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ body:
88
value: |
99
> 提需求前先想想:是 **现有功能不好用**(→ 用 Bug 模板更合适),还是 **完全新功能**(→ 用这个模板)?
1010
> 如果是想让 HackForger 多支持一种使用场景,欢迎在下面描述清楚。
11+
> 本仓库公开且业务中立;请用脱敏示例,不要提交客户内容、内部拓扑、真实账号或凭据。
1112
1213
- type: textarea
1314
id: problem
@@ -47,3 +48,11 @@ body:
4748
- "只是建议 — 觉得这样会更好"
4849
validations:
4950
required: true
51+
52+
- type: checkboxes
53+
id: public-boundary
54+
attributes:
55+
label: 公开信息确认
56+
options:
57+
- label: 我已确认本需求使用中立示例,不含凭据、内部地址、真实生产账号或客户私有内容。
58+
required: true

‎.github/ISSUE_TEMPLATE/config.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,5 +4,5 @@ contact_links:
44
url: https://github.com/HackForger/hackforger/discussions
55
about: 不确定是 bug 还是需求?想先聊聊?欢迎到 Discussions。
66
- name: 🚨 安全漏洞
7-
url: mailto:security@h2os.cloud
8-
about: 安全问题请直接邮件联系,不要在公开 issue 里发。
7+
url: https://github.com/HackForger/hackforger/security/advisories/new
8+
about: 安全问题请使用私密安全公告,不要在公开 issue 里发。

‎.gitignore‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -176,6 +176,7 @@ docs/tests/e2e/*.pdf
176176
.claude/projects/
177177
.claude/worktrees/
178178
.claude/scheduled_tasks.lock
179+
/.remember/
179180

180181
# E2E test screenshots (temporary artifacts, hosted on GitHub Releases if needed)
181182
tests/screenshots/

0 commit comments

Comments
 (0)