使用文档

时光授权系统文档

从快速开始到 API 对接,全面了解授权系统的使用与集成

部署上线

本章讲解生产环境部署授权系统的最佳实践,包括服务器选型、Nginx 配置、HTTPS、数据库备份、监控。

1. 服务器要求

项最低推荐
CPU1 核2 核+
内存1 GB2 GB+
硬盘20 GB40 GB+ SSD
带宽1 Mbps5 Mbps+
PHP7.48.0+
MySQL5.78.0+

2. Nginx 配置示例

server {
    listen 80;
    server_name license.example.com;
    return 301 https://$server_name$request_uri;
}

server {
    listen 443 ssl http2;
    server_name license.example.com;

    # SSL 证书(Let's Encrypt)
    ssl_certificate     /etc/nginx/ssl/license.example.com.crt;
    ssl_certificate_key /etc/nginx/ssl/license.example.com.key;
    ssl_protocols       TLSv1.2 TLSv1.3;
    ssl_ciphers         HIGH:!aNULL:!MD5;

    # 安全头
    add_header X-Frame-Options "SAMEORIGIN" always;
    add_header X-Content-Type-Options "nosniff" always;
    add_header X-XSS-Protection "1; mode=block" always;
    add_header Referrer-Policy "strict-origin-when-cross-origin" always;

    # 站点根目录
    root /www/wwwroot/license.example.com;
    index index.php;

    # 隐藏敏感文件
    location ~ /\.(?!well-known).* {
        deny all;
    }

    location ~* /(inc|docs|api)/.*\.(sql|bak|log|env|ini)$ {
        deny all;
    }

    # PHP 处理
    location ~ \.php$ {
        fastcgi_pass unix:/tmp/php-cgi-82.sock;
        fastcgi_index index.php;
        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
        include fastcgi_params;
        fastcgi_read_timeout 60;
    }

    # API 路由特殊处理(防缓存)
    location ~ ^/api/ {
        add_header Cache-Control "no-store, no-cache, must-revalidate" always;
        try_files $uri $uri/ /index.php?$query_string;
    }

    # 静态资源缓存
    location ~* \.(css|js|jpg|jpeg|png|gif|ico|svg|woff2?)$ {
        expires 30d;
        add_header Cache-Control "public, immutable";
        access_log off;
    }

    # 日志
    access_log /var/log/nginx/license.example.com.access.log;
    error_log  /var/log/nginx/license.example.com.error.log;
}

3. PHP-FPM 配置

编辑 /www/server/php/82/etc/php-fpm.conf 或 www.conf:

[www]
pm = dynamic
pm.max_children = 30
pm.start_servers = 5
pm.min_spare_servers = 5
pm.max_spare_servers = 20
pm.max_requests = 500

; PHP 脚本超时
request_terminate_timeout = 60s

; 上传限制
file_uploads = On
upload_max_filesize = 10M
post_max_size = 10M

4. MySQL 配置

编辑 /etc/my.cnf:

[mysqld]
character-set-server = utf8mb4
collation-server = utf8mb4_unicode_ci
default-storage-engine = InnoDB

# 性能
innodb_buffer_pool_size = 256M
innodb_log_file_size = 64M
max_connections = 100

# 慢查询日志
slow_query_log = 1
long_query_time = 2
slow_query_log_file = /var/log/mysql/slow.log

5. 数据库自动备份

创建 /www/wwwroot/backup.sh:

#!/bin/bash
# 每日凌晨 3 点备份

BACKUP_DIR=/www/backup/license-server
DATE=$(date +%Y%m%d_%H%M%S)
KEEP_DAYS=30

mkdir -p $BACKUP_DIR

# 备份数据库
mysqldump -u license_user -p'your-password' \
    --single-transaction --routines --triggers \
    license_server | gzip > $BACKUP_DIR/db_$DATE.sql.gz

# 清理 30 天前的备份
find $BACKUP_DIR -name "db_*.sql.gz" -mtime +$KEEP_DAYS -delete

# 上传到 OSS(可选)
# ossutil cp $BACKUP_DIR/db_$DATE.sql.gz oss://your-bucket/license-server/

设置 cron:

chmod +x /www/wwwroot/backup.sh
echo "0 3 * * * /www/wwwroot/backup.sh" >> /etc/crontab
systemctl reload crond

6. 监控与告警

健康检查接口

创建 health.php:

<?php
require_once __DIR__ . '/inc/functions.php';

header('Content-Type: application/json');

try {
    $db = get_db();
    $db->query("SELECT 1");

    // 检查关键表是否存在
    $tables = ['lic_users', 'lic_products', 'lic_licenses', 'lic_orders'];
    foreach ($tables as $t) {
        $db->query("SELECT 1 FROM " . table($t) . " LIMIT 1");
    }

    echo json_encode([
        'status'  => 'ok',
        'time'    => date('c'),
        'version' => '1.0.0',
    ]);
} catch (Exception $e) {
    http_response_code(500);
    echo json_encode([
        'status' => 'error',
        'message' => $e->getMessage(),
    ]);
}

使用外部监控(如 UptimeRobot)每 5 分钟 ping 一次:

https://license.example.com/health.php

日志清理

编辑 /etc/logrotate.d/license-server:

/var/log/nginx/license.example.com.*.log {
    daily
    rotate 30
    compress
    delaycompress
    missingok
    notifempty
    create 0640 www-data adm
    sharedscripts
    postrotate
        [ -f /var/run/nginx.pid ] && kill -USR1 $(cat /var/run/nginx.pid)
    endscript
}

7. 上线 Checklist

  • 数据库密码使用强密码(≥ 16 字符)
  • HMAC_SALT 和 API_SECRET 已改为随机字符串
  • 删除 install.php、patch_*.php、debug.php 等脚本
  • 关闭 WP_DEBUG(如使用 WordPress)
  • 关闭 PHP display_errors
  • 配置 HTTPS(Let's Encrypt)
  • 配置防火墙(仅开放 80/443/22)
  • 数据库自动备份已启用
  • 监控告警已配置
  • 易支付回调地址白名单已配置
  • 测试授权验证全流程
  • 测试支付回调
部署完成后,记得阅读 安全建议 加固系统。