fix: check_auth 前缀匹配去尾斜杠避免双斜杠不命中(公开/受保护端点判定修正)
This commit is contained in:
@@ -343,17 +343,20 @@ class MirrorServerHandler(BaseHTTPRequestHandler):
|
||||
|
||||
# 任何方法都公开
|
||||
for endpoint in public_any:
|
||||
if check_path == endpoint or check_path.startswith(endpoint + '/'):
|
||||
ep = endpoint.rstrip('/')
|
||||
if check_path == ep or check_path.startswith(ep + '/'):
|
||||
return True
|
||||
|
||||
if method in ('GET', 'HEAD'):
|
||||
# 只读公开端点放行
|
||||
# 只读公开端点放行(去尾斜杠后按前缀匹配,避免双斜杠不命中)
|
||||
for endpoint in public_get:
|
||||
if check_path == endpoint or check_path.startswith(endpoint + '/'):
|
||||
ep = endpoint.rstrip('/')
|
||||
if check_path == ep or check_path.startswith(ep + '/'):
|
||||
return True
|
||||
# 其余 GET: 命中受保护前缀才需要认证
|
||||
for endpoint in protected_endpoints:
|
||||
if check_path.startswith(endpoint):
|
||||
ep = endpoint.rstrip('/')
|
||||
if check_path == ep or check_path.startswith(ep + '/'):
|
||||
return self._do_auth(auth_type)
|
||||
return True
|
||||
|
||||
|
||||
Reference in New Issue
Block a user