-
Notifications
You must be signed in to change notification settings - Fork 12
Expand file tree
/
Copy pathindex.html
More file actions
17 lines (17 loc) · 14.8 KB
/
Copy pathindex.html
File metadata and controls
17 lines (17 loc) · 14.8 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
<!doctype html><html lang="zh-CN"><head>
<meta charset="utf-8"><meta name="viewport" content="width=device-width, initial-scale=1, viewport-fit=cover"><meta name="theme-color" content="#ffffff">
<meta name="description" content="PythonIDE 安全说明:本地数据、钥匙串、传输保护、设备认证、购买验证、社区审核与安全问题报告。" data-zh="PythonIDE 安全说明:本地数据、钥匙串、传输保护、设备认证、购买验证、社区审核与安全问题报告。" data-en="PythonIDE security overview covering local data, Keychain, transport protection, device attestation, purchase verification, community review, and vulnerability reporting.">
<meta property="og:type" content="article"><meta property="og:site_name" content="PythonIDE"><meta property="og:title" content="PythonIDE 安全说明" data-zh="PythonIDE 安全说明" data-en="PythonIDE Security"><meta property="og:description" content="了解 PythonIDE 的保护边界与负责任披露渠道。" data-zh="了解 PythonIDE 的保护边界与负责任披露渠道。" data-en="Understand PythonIDE's protections and responsible disclosure channel."><meta property="og:url" content="https://pythonide.xin/security/"><meta property="og:image" content="https://pythonide.xin/assets/pythonide-social-card.png?v=3"><meta name="twitter:card" content="summary_large_image"><meta name="twitter:title" content="PythonIDE 安全说明" data-zh="PythonIDE 安全说明" data-en="PythonIDE Security"><meta name="twitter:description" content="了解 PythonIDE 的保护边界与负责任披露渠道。" data-zh="了解 PythonIDE 的保护边界与负责任披露渠道。" data-en="Understand PythonIDE's protections and responsible disclosure channel."><meta name="twitter:image" content="https://pythonide.xin/assets/pythonide-social-card.png?v=3">
<link rel="canonical" href="https://pythonide.xin/security/"><link rel="alternate" hreflang="zh-CN" href="https://pythonide.xin/security/"><link rel="alternate" hreflang="en" href="https://pythonide.xin/security/?lang=en"><link rel="alternate" hreflang="x-default" href="https://pythonide.xin/security/"><link rel="icon" href="/assets/brand-mark.svg" type="image/svg+xml"><script>(function(){try{var t=localStorage.getItem("pythonide_site_theme");if(t==="light"||t==="dark")document.documentElement.dataset.theme=t;}catch(_){}}());</script><link rel="stylesheet" href="/assets/site.css"><script defer src="/assets/site.js"></script><title data-zh="安全说明 — PythonIDE" data-en="Security — PythonIDE">安全说明 — PythonIDE</title>
</head><body><a class="skip-link" href="#content" data-en="Skip to content">跳到正文</a><div class="page">
<header class="site-header"><nav class="nav" aria-label="PythonIDE"><a class="brand" href="/"><img class="brand-mark" src="/assets/brand-mark.svg" alt=""><span>PythonIDE</span></a><div class="nav-links" data-nav-links data-open="false"><a class="nav-link" href="/" data-en="Overview">概览</a><a class="nav-link" href="/i/" data-en="Invite">邀请</a><a class="nav-link" href="/support/" aria-current="page" data-en="Support">支持</a><a class="nav-link" href="/about/" data-en="About">关于</a><a class="nav-link nav-external" href="https://github.com/Python-IDE/PythonIDE-iOS" target="_blank" rel="noreferrer" data-en="GitHub">GitHub</a><a class="button primary nav-download" href="https://apps.apple.com/app/id6753987304" data-download data-en="Download App">下载 App</a></div><div class="nav-actions"><button class="icon-button" type="button" data-theme-toggle aria-label="切换深色模式"><svg viewBox="0 0 24 24" fill="none" stroke="currentColor"><path d="M21 12.8A9 9 0 1 1 11.2 3 7 7 0 0 0 21 12.8Z"/></svg></button><div class="language-toggle"><button type="button" data-lang="zh" aria-pressed="true">中</button><button type="button" data-lang="en" aria-pressed="false">EN</button></div><button class="menu-button" type="button" data-menu-toggle aria-label="打开导航菜单" data-label-en="Open navigation menu" aria-expanded="false"><svg viewBox="0 0 24 24" fill="none" stroke="currentColor"><path d="M4 7h16M4 12h16M4 17h16"/></svg></button></div></nav></header>
<main class="main" id="content"><section class="hero compact document-hero"><div class="shell hero-center"><div class="hero-copy"><p class="kicker" data-en="Security">安全</p><h1 class="display medium" data-en="Strong boundaries. Honest limits.">边界要牢固,限制也要诚实。</h1><p class="lede" data-en="PythonIDE combines Apple platform security, local-first storage, signed service requests, and review controls. Security still depends on the code, providers, and permissions you choose.">PythonIDE 结合 Apple 平台安全、本地优先存储、签名服务请求与审核控制;实际安全仍取决于你选择的代码、服务商与权限。</p><p class="hero-meta" data-en="Last updated: July 16, 2026">最近更新:2026 年 7 月 16 日</p></div></div></section>
<div class="shell document-layout"><aside class="toc"><p class="toc-title" data-en="On this page">本页目录</p><a href="#protections" data-en="Protections">保护措施</a><a href="#boundaries" data-en="Boundaries">安全边界</a><a href="#practices" data-en="Your practices">你的做法</a><a href="#report" data-en="Report a vulnerability">报告漏洞</a></aside><article class="article">
<section class="article-section" id="protections"><h2 data-en="Security measures in the product">产品中的安全措施</h2><div class="info-list"><div class="info-row"><strong data-en="Local-first storage">本地优先存储</strong><span data-en="Projects, settings, and AI history primarily stay on the device or in the file provider you select, reducing unnecessary central collection.">项目、设置与 AI 历史主要留在设备或你选择的文件提供商中,减少不必要的集中收集。</span></div><div class="info-row"><strong data-en="Keychain protection">钥匙串保护</strong><span data-en="Account session tokens, AI API keys, OAuth secrets and tokens, custom authentication headers, and device-attestation identifiers use the Apple Keychain where supported.">账户会话令牌、AI API 密钥、OAuth 密钥与令牌、自定义认证请求头及设备认证标识在受支持时使用 Apple 钥匙串。</span></div><div class="info-row"><strong data-en="Encrypted and pinned platform transport">加密与固定平台传输</strong><span data-en="Online services use HTTPS. The built-in platform AI connection validates server trust and matches approved public-key pins for its configured host.">在线服务使用 HTTPS;内置平台 AI 连接还会验证服务器信任,并对配置主机匹配批准的公钥固定值。</span></div><div class="info-row"><strong data-en="Device attestation">设备认证</strong><span data-en="Supported platform AI authentication uses Apple App Attest keys and assertions to reduce automated abuse and bind short-lived service tokens to a genuine app instance.">受支持的平台 AI 鉴权使用 Apple App Attest 密钥与断言,降低自动化滥用,并把短期服务令牌与真实 App 实例关联。</span></div><div class="info-row"><strong data-en="Signed purchase verification">签名购买验证</strong><span data-en="StoreKit signed transactions and current entitlements are verified and synchronized to maintain access, restoration, refunds, and anti-fraud state.">StoreKit 签名交易与当前权益会被验证和同步,用于维护访问、恢复、退款与反欺诈状态。</span></div><div class="info-row"><strong data-en="Account and community controls">账户与社区控制</strong><span data-en="Sign in with Apple, refresh-token revocation, manual submission review, moderation records, soft removal, and permanent account deletion provide operational control and auditability.">通过 Apple 登录、刷新令牌撤销、投稿人工审核、处理记录、软下架与永久账户删除提供运行控制与可审计性。</span></div></div></section>
<section class="article-section" id="boundaries"><h2 data-en="Security boundaries to understand">需要理解的安全边界</h2><ul><li data-en="Python code can be powerful. A script may access files, network services, sensors, personal data, external apps, or system integrations only within available platform and permission boundaries, but those actions can still be harmful if you approve them without review.">Python 代码具有强大能力。脚本可能在平台与权限边界内访问文件、网络、传感器、个人数据、外部 App 或系统集成;未经检查就授权仍可能造成危害。</li><li data-en="Community review reduces obvious risk but is not a guarantee or security certification. Imported, shared, downloaded, and AI-generated code must still be reviewed before execution.">社区审核会降低明显风险,但不是保证或安全认证。导入、分享、下载与 AI 生成代码在执行前仍需检查。</li><li data-en="A custom AI endpoint, package repository, Git service, website, file provider, or other third party is outside PythonIDE's direct security control. Its terms, authentication, logging, and incident response apply.">自定义 AI 接口、包仓库、Git 服务、网站、文件提供商或其他第三方不在 PythonIDE 的直接安全控制中,其条款、鉴权、日志与事件响应同时适用。</li><li data-en="No software or network service can guarantee absolute security, availability, or recovery. Keep backups and use provider-side controls for important credentials and data.">任何软件或网络服务都无法保证绝对安全、可用性或恢复能力。请保留备份,并使用提供方的控制保护重要凭证与数据。</li></ul></section>
<section class="article-section" id="practices"><h2 data-en="Recommended practices">建议的安全做法</h2><div class="step-list"><div class="step"><div class="step-number">1</div><div><strong data-en="Update PythonIDE and the operating system">更新 App 与系统</strong><span data-en="Install current App Store and Apple system updates so you receive security and compatibility fixes.">及时安装 App Store 与 Apple 系统更新,获取安全与兼容性修复。</span></div></div><div class="step"><div class="step-number">2</div><div><strong data-en="Inspect before running">运行前检查</strong><span data-en="Read unfamiliar code, dependencies, network hosts, file operations, tool actions, and requested permissions. Test in a limited scope.">检查陌生源码、依赖、网络主机、文件操作、工具动作与请求权限,并在有限范围测试。</span></div></div><div class="step"><div class="step-number">3</div><div><strong data-en="Keep secrets out of content">不要把秘密写入内容</strong><span data-en="Use Keychain-backed settings. Do not commit or publish credentials, and do not paste them into AI prompts or support messages.">使用钥匙串支持的设置。不要提交或发布凭证,也不要粘贴到 AI 提示词或支持邮件。</span></div></div><div class="step"><div class="step-number">4</div><div><strong data-en="Use least privilege">最小权限</strong><span data-en="Grant only the permissions needed for the current task and revoke access in system settings when it is no longer needed.">只授予当前任务所需权限,不再需要时在系统设置中撤销。</span></div></div><div class="step"><div class="step-number">5</div><div><strong data-en="Back up important work">备份重要作品</strong><span data-en="Keep versioned copies in a location you control. Local deletion, device loss, provider sync, or a destructive script may not be reversible.">在你控制的位置保留版本化副本。本地删除、设备丢失、提供商同步或破坏性脚本可能无法撤销。</span></div></div></div></section>
<section class="article-section" id="report"><h2 data-en="Responsible vulnerability disclosure">负责任地报告安全问题</h2><p data-en="If you believe you found a vulnerability in the PythonIDE app or an official PythonIDE service, report it privately before public disclosure. Include the affected version or URL, impact, exact reproduction steps, proof that minimizes access to real data, and a safe way to contact you.">如你认为发现了 PythonIDE App 或官方服务的漏洞,请在公开披露前私下报告。请包含受影响版本或 URL、影响、完整复现步骤、尽量减少访问真实数据的证明,以及安全联系方式。</p><div class="notice danger"><strong data-en="Do not cause additional harm">不要扩大损害</strong><p data-en="Do not access other users' data, disrupt service, persist access, plant malware, conduct social engineering, publish credentials, or demand payment through a threat. Stop testing once you have enough evidence to explain the issue.">不得访问其他用户数据、破坏服务、维持访问、植入恶意软件、实施社会工程、公开凭证或以威胁方式索取报酬。获得足以说明问题的证据后应停止测试。</p></div><div class="button-row" style="justify-content:flex-start"><a class="button primary" href="mailto:jinwandalaohu940@gmail.com?subject=PythonIDE%20Security%20Report" data-en="Report a security issue">报告安全问题</a></div><p data-en="We will acknowledge credible reports, investigate based on severity and available information, and coordinate a reasonable disclosure timeline when appropriate. This page is not a promise of a bounty or safe-harbor program beyond rights provided by applicable law.">我们会确认可信报告,依据严重程度与现有信息调查,并在适当时协调合理披露时间。本页不构成漏洞奖金承诺,也不在适用法律已有权利之外额外承诺安全港计划。</p></section>
</article></div>
</main>
<footer class="site-footer"><div class="shell"><div class="footer-grid"><div class="footer-brand"><a class="brand" href="/"><img class="brand-mark" src="/assets/brand-mark.svg" alt=""><span>PythonIDE</span></a><p data-en="Security is a product boundary and a shared practice.">安全既是产品边界,也是共同实践。</p></div><div class="footer-col"><strong data-en="Security">安全</strong><a href="/security/" data-en="Security overview">安全说明</a><a href="/privacy/" data-en="Privacy">隐私政策</a><a href="/ai-policy/" data-en="AI data use">AI 数据使用</a></div><div class="footer-col"><strong data-en="Help">帮助</strong><a href="/support/" data-en="Support Center">支持中心</a><a href="/community-guidelines/" data-en="Community reports">社区举报</a><a href="/account-deletion/" data-en="Delete account">删除账户</a></div><div class="footer-col"><strong data-en="Product">产品</strong><a href="/docs/" data-en="Documentation">开发者文档</a><a href="/terms/" data-en="Terms">用户协议</a><a href="/about/" data-en="About">关于</a></div></div><div class="footer-bottom"><span>© 2026 PythonIDE</span><span data-en="Last updated July 16, 2026">最近更新:2026 年 7 月 16 日</span></div></div></footer>
</div></body></html>