build(onlyoffice): 移除未授权字体注入入口
Client Quality Gates / Shared client and Web (push) Has been cancelled
Client Quality Gates / macOS Desktop (push) Has been cancelled

This commit is contained in:
Cheng Zhou
2026-09-04 09:50:08 +08:00
parent 49b32dc20f
commit 684b8b51bb
3 changed files with 7 additions and 42 deletions
+5 -21
View File
@@ -28,31 +28,15 @@ bash scripts/onlyoffice-dev-up.sh --rotate-secret
轮换会强制重建相关容器,已签发但尚未使用的短时预览配置会立即失效。生产环境不使用该自动生成流程,仍必须由部署密钥管理系统显式提供密钥。
可用 `ONLYOFFICE_IMAGE` 覆盖默认的 `onlyoffice/documentserver:9.4.0.1`。默认派生镜像增加 Noto Sans CJK/Noto Serif CJK;其他字体由上游镜像或部署方提供。
可用 `ONLYOFFICE_IMAGE` 覆盖默认的 `onlyoffice/documentserver:9.4.0.1`。默认派生镜像只额外增加 Noto Sans CJK/Noto Serif CJK;其他字体仅继承自获准使用的上游镜像。
## 导入宋体和 Times New Roman
## 字体许可边界
将获准使用的字体放到 `onlyoffice/fonts/`,文件名为 `simsun.ttc`、`times.ttf`、`timesbd.ttf`、`timesi.ttf`、`timesbi.ttf`。宋体集合包含 SimSun(宋体)和 NSimSun(新宋体),Times New Roman 的四个文件分别提供常规、粗体、斜体和粗斜体。该目录的字体文件被 Git 忽略,必须在每台构建主机上单独提供;构建得到的镜像会包含这些字体。
项目只在派生镜像中额外安装可再分发的 Noto CJK 字体,不打包、复制、下载或自动注入部署方提供的宋体、Times New Roman 等专有字体。文档指定了未安装字体时,ONLYOFFICE 会使用可用字体替代,版式可能产生差异。
从仓库根目录执行以下命令;如果运行的是独立开发栈,为每条 Compose 命令增加 `-f docker-compose.dev.yaml -p ctms_dev`:
部署方不得将来源不明或没有服务器部署及再分发许可的字体放入项目目录、Docker 构建上下文或 `onlyoffice_data` 卷。确需增加其他字体时,应先取得相应授权并独立完成合规评估;当前安装和更新脚本不提供专有字体注入入口。
```bash
docker compose build onlyoffice
docker compose exec -T onlyoffice documentserver-prepare4shutdown.sh
docker compose up -d --no-deps onlyoffice
```
维护前先完成文档保存。上述关闭准备会等待在线文档保存,随后替换 ONLYOFFICE 容器;启动脚本自动重建字体索引。构建脚本仅在四个 Times New Roman 文件齐全时移除上游同名字体,避免编辑器继续选用旧版本。未提供字体的环境沿用原有字体。
健康检查通过后,重新打开在线文档,在字体列表中查找 `SimSun`(宋体)和 `Times New Roman`。可用以下命令核对字体来源:
```bash
docker compose exec -T onlyoffice fc-match SimSun
docker compose exec -T onlyoffice fc-match 'Times New Roman'
docker compose exec -T onlyoffice curl -fsS http://127.0.0.1/healthcheck
```
补充说明:当前版本的生成器也会扫描 `onlyoffice_data` 卷中的 `/var/www/onlyoffice/Data/custom-fonts/`。放在该处的字体可跨容器重建保留,但同名字体仍可能被上游版本优先选中;替换 Times New Roman 时使用上述镜像构建流程。迁移部署时应单独携带字体来源文件。字体索引刷新方式参见 [ONLYOFFICE 官方字体安装说明](https://helpcenter.onlyoffice.com/docs/installation/docs-install-fonts-docker.aspx)。
`ONLYOFFICE_IMAGE` 上游基础镜像可能自带其他字体;其内容和许可不属于项目字体注入流程。分发派生镜像前仍应单独审查获准使用的上游镜像,不能以本项目已移除自定义字体作为上游字体合规结论。
## 配置边界
+2 -19
View File
@@ -3,8 +3,8 @@ FROM ${ONLYOFFICE_IMAGE}
USER root
# Use redistributable Noto CJK fonts for Chinese document preview. Proprietary
# Microsoft fonts must be supplied separately by an authorized deployment.
# Use redistributable Noto CJK fonts for Chinese document preview. Do not add
# deployment-supplied proprietary Microsoft or Zhongyi fonts to this build.
RUN apt-get update \
&& DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends fonts-noto-cjk \
&& rm -rf /var/lib/apt/lists/*
@@ -16,20 +16,3 @@ RUN locale_root=/var/www/onlyoffice/documentserver/web-apps/apps \
&& test -n "$matches" \
&& sed -i 's/另存副本为/另存为/g' $matches \
&& ! grep -RIl '另存副本为' "$locale_root"/*/main/locale/zh.json
# Deployment-supplied fonts are kept out of Git, but included in local builds.
COPY fonts/ /usr/local/share/fonts/ctms/
# The upstream image contains an older Times New Roman family. Remove those
# duplicates only when the deployment supplies all four replacement faces.
RUN if [ -s /usr/local/share/fonts/ctms/times.ttf ] \
&& [ -s /usr/local/share/fonts/ctms/timesbd.ttf ] \
&& [ -s /usr/local/share/fonts/ctms/timesi.ttf ] \
&& [ -s /usr/local/share/fonts/ctms/timesbi.ttf ]; then \
rm -f /usr/share/fonts/truetype/msttcorefonts/Times_New_Roman*.ttf \
/usr/share/fonts/truetype/msttcorefonts/times.ttf \
/usr/share/fonts/truetype/msttcorefonts/timesbd.ttf \
/usr/share/fonts/truetype/msttcorefonts/timesi.ttf \
/usr/share/fonts/truetype/msttcorefonts/timesbi.ttf; \
fi \
&& fc-cache -f
-2
View File
@@ -1,2 +0,0 @@
*
!.gitignore