feat: add secrets-mcp-local gateway (proxy, unlock cache, plaintext tool gate)

This commit is contained in:
voson
2026-04-12 12:46:15 +08:00
parent 0bf06bbc73
commit 34093b0e23
8 changed files with 555 additions and 3 deletions

View File

@@ -56,3 +56,12 @@ GOOGLE_CLIENT_SECRET=
# 设为 1/true/yes 时从 X-Forwarded-For / X-Real-IP 提取客户端 IP
# 仅在反代环境下启用,否则客户端可伪造 IP 绕过限流
# TRUST_PROXY=1
# ─── 本机 MCP gatewaysecrets-mcp-local可选────────────────────────
# 在开发者机器上运行,与上方服务端 .env 通常分开配置;用于代理远程 /mcp 并缓存解锁状态。
# SECRETS_REMOTE_MCP_URL=https://secrets.example.com/mcp
# SECRETS_MCP_LOCAL_BIND=127.0.0.1:9316
# SECRETS_LOCAL_API_KEY=
# SECRETS_LOCAL_UNLOCK_TTL_SECS=3600
# SECRETS_LOCAL_ALLOW_PLAINTEXT_TOOLS=0
# SECRETS_REMOTE_DASHBOARD_URL=https://secrets.example.com/dashboard