P0-A: 修复鉴权体系

- check_endpoint_auth 路径归一化(无前导斜杠),v1/v2 端点级鉴权真正生效
- ADMIN_API_ENDPOINTS 重建:修复 files 单复数、补 mirrors/alerts/prewarm/api-docs/user-password
- handler check_auth 方法感知:公开端点仅 GET/HEAD,写操作默认要求认证(fail-closed)
- 补全受保护端点(monitor/activity/login-logs/mirrors/alerts/prewarm/file 元数据)
- _check_basic_auth/_check_token_auth 改用 hmac.compare_digest
- do_POST/do_HEAD 解析路径时剥离查询串;do_HEAD 增加 is_safe_path 检查
- is_safe_path 改用 realpath 防符号链接绕过
This commit is contained in:
HYC Fixer
2026-08-30 12:16:14 +08:00
parent a8e773839b
commit ffae028664
5 changed files with 164 additions and 66 deletions
+11
View File
@@ -85,6 +85,17 @@ class APIv1:
})
return
if auth_check.get('permission'):
if not auth_manager.check_permission(auth_result, auth_check['permission']):
handler.send_json_response({
"error": "权限不足",
"code": "FORBIDDEN",
"required_permission": auth_check['permission']
}, 403)
return
handler.auth_result = auth_result
# 文件管理API (GET /api/v1/files 不需要认证)
if path == 'files':
if method == 'GET':