生产检查清单
必查项
TLS 配置
- [ ]
InsecureSkipVerify设为false(默认值) - [ ]
MinTLSVersion至少为tls.VersionTLS12 - [ ] 不使用
TestingConfig()
SSRF 防护
- [ ]
AllowPrivateIPs为false(默认值) - [ ] 如需访问内部服务,使用
SSRFExemptCIDRs精确指定 - [ ] 处理用户提供的 URL 时使用
SecureConfig()
超时配置
- [ ] 所有超时值已设置且合理
- [ ]
TimeoutConfig.Request不为 0(防止无限等待) - [ ] 考虑使用
WithContext为每个请求设置超时
响应限制
- [ ]
MaxResponseBodySize设置合理上限 - [ ]
MaxDecompressedBodySize设置合理上限 - [ ] 处理大响应时使用流式下载
重试配置
- [ ]
MaxRetries不超过 5 - [ ] 非幂等请求(POST/PUT/PATCH)谨慎使用重试
- [ ] 启用
EnableJitter防止惊群
资源管理
- [ ] 客户端使用后调用
Close() - [ ] 使用
defer确保资源释放
推荐项
中间件
- [ ] 使用
RecoveryMiddleware()防止 panic 崩溃 - [ ] 使用
LoggingMiddleware()记录请求日志 - [ ] 使用
MetricsMiddleware()收集指标 - [ ] 安全敏感场景使用
AuditMiddleware()
请求头
- [ ] 设置有意义的
User-Agent - [ ] 不在默认请求头中存储敏感信息
- [ ] 使用
WithBearerToken而非手动设置 Authorization
Cookie
- [ ] 安全敏感场景启用
CookieSecurity验证 - [ ] 使用
StrictCookieSecurityConfig()强制安全属性
重定向
- [ ] 用户输入 URL 场景禁用重定向
- [ ] 使用
RedirectWhitelist限制重定向目标
代码示例
生产级客户端创建
go
func createProductionClient() (httpc.Client, error) {
cfg := httpc.DefaultConfig()
// 超时
cfg.Timeouts.Request = 30 * time.Second
cfg.Timeouts.Dial = 10 * time.Second
cfg.Timeouts.TLSHandshake = 10 * time.Second
cfg.Timeouts.ResponseHeader = 30 * time.Second // transport 级硬上限:作用于该 client 所有请求,无法按请求用 WithTimeout 覆盖;AI API/长响应场景应设为 0 依赖 Request 超时
// 连接池
cfg.Connection.MaxIdleConns = 50
cfg.Connection.MaxConnsPerHost = 10
// 安全
cfg.Security.AllowPrivateIPs = false
cfg.Security.MaxResponseBodySize = 10 * 1024 * 1024
// 重试
cfg.Retry.MaxRetries = 3
cfg.Retry.Delay = 1 * time.Second
cfg.Retry.EnableJitter = true
// 中间件
cfg.Middleware.UserAgent = "my-service/1.0"
cfg.Middleware.Middlewares = []httpc.MiddlewareFunc{
httpc.RecoveryMiddleware(),
httpc.LoggingMiddleware(log.Printf),
httpc.RequestIDMiddleware("X-Request-ID", nil),
}
return httpc.New(cfg)
}安全级客户端
go
func createSecureClient() (httpc.Client, error) {
cfg := httpc.SecureConfig()
cfg.Security.CookieSecurity = httpc.StrictCookieSecurityConfig()
cfg.Security.RedirectWhitelist = []string{"api.example.com"}
return httpc.New(cfg)
}检查命令
bash
# 检查是否误用 TestingConfig
grep -r "TestingConfig" --include="*.go" | grep -v "_test.go"
# 检查 InsecureSkipVerify
grep -r "InsecureSkipVerify.*true" --include="*.go" | grep -v "_test.go"
# 检查 AllowPrivateIPs
grep -r "AllowPrivateIPs.*true" --include="*.go" | grep -v "_test.go"