fix: check_auth 前缀匹配去尾斜杠避免双斜杠不命中(公开/受保护端点判定修正)

This commit is contained in:
HYC Fixer
2026-08-30 12:26:30 +08:00
parent dfae749612
commit 08a8062a01
+7 -4
View File
@@ -343,17 +343,20 @@ class MirrorServerHandler(BaseHTTPRequestHandler):
# 任何方法都公开
for endpoint in public_any:
if check_path == endpoint or check_path.startswith(endpoint + '/'):
ep = endpoint.rstrip('/')
if check_path == ep or check_path.startswith(ep + '/'):
return True
if method in ('GET', 'HEAD'):
# 只读公开端点放行
# 只读公开端点放行(去尾斜杠后按前缀匹配,避免双斜杠不命中)
for endpoint in public_get:
if check_path == endpoint or check_path.startswith(endpoint + '/'):
ep = endpoint.rstrip('/')
if check_path == ep or check_path.startswith(ep + '/'):
return True
# 其余 GET: 命中受保护前缀才需要认证
for endpoint in protected_endpoints:
if check_path.startswith(endpoint):
ep = endpoint.rstrip('/')
if check_path == ep or check_path.startswith(ep + '/'):
return self._do_auth(auth_type)
return True