P0-A: 修复鉴权体系
- check_endpoint_auth 路径归一化(无前导斜杠),v1/v2 端点级鉴权真正生效 - ADMIN_API_ENDPOINTS 重建:修复 files 单复数、补 mirrors/alerts/prewarm/api-docs/user-password - handler check_auth 方法感知:公开端点仅 GET/HEAD,写操作默认要求认证(fail-closed) - 补全受保护端点(monitor/activity/login-logs/mirrors/alerts/prewarm/file 元数据) - _check_basic_auth/_check_token_auth 改用 hmac.compare_digest - do_POST/do_HEAD 解析路径时剥离查询串;do_HEAD 增加 is_safe_path 检查 - is_safe_path 改用 realpath 防符号链接绕过
This commit is contained in:
@@ -85,6 +85,17 @@ class APIv1:
|
||||
})
|
||||
return
|
||||
|
||||
if auth_check.get('permission'):
|
||||
if not auth_manager.check_permission(auth_result, auth_check['permission']):
|
||||
handler.send_json_response({
|
||||
"error": "权限不足",
|
||||
"code": "FORBIDDEN",
|
||||
"required_permission": auth_check['permission']
|
||||
}, 403)
|
||||
return
|
||||
|
||||
handler.auth_result = auth_result
|
||||
|
||||
# 文件管理API (GET /api/v1/files 不需要认证)
|
||||
if path == 'files':
|
||||
if method == 'GET':
|
||||
|
||||
Reference in New Issue
Block a user