Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug] 为什么要把api路由暴露出来? #2714

Closed
crazyming9528 opened this issue Aug 26, 2023 · 3 comments
Closed

[Bug] 为什么要把api路由暴露出来? #2714

crazyming9528 opened this issue Aug 26, 2023 · 3 comments

Comments

@crazyming9528
Copy link

描述问题
将项目部署到公网,发现被盗刷,排查日志发现,有人在 通过工具请求 项目地址.com/api/xxx 的接口,api接口会直接转发到openai,请问为什么这么设计?也没有关闭的地方

如何复现
例如请求 项目地址/api/openai/v1/chat/completions

看到之前的 issues ,想必是接口被盗刷造成的:#518

@Issues-translate-bot
Copy link

Bot detected the issue body's language is not English, translate it automatically.


Title: [Bug] Why should the api route be exposed?

Describe problem
After deploying the project to the public network, it was found that it was stolen. After checking the logs, it was found that someone was requesting the interface of the project address.com/api/xxx through the tool, and the api interface would be forwarded directly to openai. Why is this design? no place to close

How ​​to reproduce
For example, request project address /api/openai/v1/chat/completions

Seeing the previous issues, it must be caused by the interface being stolen: #518

@crazyming9528 crazyming9528 changed the title [Bug] 为什么要不api路由暴露出来? [Bug] 为什么要把api路由暴露出来? Aug 26, 2023
@ChatGPTNextWeb ChatGPTNextWeb deleted a comment from reece00 Aug 27, 2023
@Yidadaa
Copy link
Collaborator

Yidadaa commented Aug 27, 2023

请使用项目 README 中介绍的密码功能防护你的 api 接口。

@Yidadaa Yidadaa closed this as completed Aug 27, 2023
@Issues-translate-bot
Copy link

Bot detected the issue body's language is not English, translate it automatically.


Please use the password function introduced in the project README to protect your api interface.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants