fix: check_auth 前缀匹配去尾斜杠避免双斜杠不命中(公开/受保护端点判定修正)
This commit is contained in:
@@ -343,17 +343,20 @@ class MirrorServerHandler(BaseHTTPRequestHandler):
|
|||||||
|
|
||||||
# 任何方法都公开
|
# 任何方法都公开
|
||||||
for endpoint in public_any:
|
for endpoint in public_any:
|
||||||
if check_path == endpoint or check_path.startswith(endpoint + '/'):
|
ep = endpoint.rstrip('/')
|
||||||
|
if check_path == ep or check_path.startswith(ep + '/'):
|
||||||
return True
|
return True
|
||||||
|
|
||||||
if method in ('GET', 'HEAD'):
|
if method in ('GET', 'HEAD'):
|
||||||
# 只读公开端点放行
|
# 只读公开端点放行(去尾斜杠后按前缀匹配,避免双斜杠不命中)
|
||||||
for endpoint in public_get:
|
for endpoint in public_get:
|
||||||
if check_path == endpoint or check_path.startswith(endpoint + '/'):
|
ep = endpoint.rstrip('/')
|
||||||
|
if check_path == ep or check_path.startswith(ep + '/'):
|
||||||
return True
|
return True
|
||||||
# 其余 GET: 命中受保护前缀才需要认证
|
# 其余 GET: 命中受保护前缀才需要认证
|
||||||
for endpoint in protected_endpoints:
|
for endpoint in protected_endpoints:
|
||||||
if check_path.startswith(endpoint):
|
ep = endpoint.rstrip('/')
|
||||||
|
if check_path == ep or check_path.startswith(ep + '/'):
|
||||||
return self._do_auth(auth_type)
|
return self._do_auth(auth_type)
|
||||||
return True
|
return True
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user