P0-A: 修复鉴权体系
- check_endpoint_auth 路径归一化(无前导斜杠),v1/v2 端点级鉴权真正生效 - ADMIN_API_ENDPOINTS 重建:修复 files 单复数、补 mirrors/alerts/prewarm/api-docs/user-password - handler check_auth 方法感知:公开端点仅 GET/HEAD,写操作默认要求认证(fail-closed) - 补全受保护端点(monitor/activity/login-logs/mirrors/alerts/prewarm/file 元数据) - _check_basic_auth/_check_token_auth 改用 hmac.compare_digest - do_POST/do_HEAD 解析路径时剥离查询串;do_HEAD 增加 is_safe_path 检查 - is_safe_path 改用 realpath 防符号链接绕过
This commit is contained in:
@@ -83,7 +83,6 @@ class APIv2(APIv1):
|
||||
public_endpoints = [
|
||||
'admin/auth/verify',
|
||||
'user/login',
|
||||
'user/password',
|
||||
'search/enhanced',
|
||||
'search/by-tag',
|
||||
'search/by-date',
|
||||
@@ -100,7 +99,8 @@ class APIv2(APIv1):
|
||||
|
||||
# 如果需要认证(不是公开端点且auth_type不是none)
|
||||
if auth_manager and not is_public and not skip_auth:
|
||||
auth_check = check_endpoint_auth(method, path, auth_manager)
|
||||
# 传入完整路径(api/v2/ 前缀),与 ADMIN_API_ENDPOINTS 规则匹配
|
||||
auth_check = check_endpoint_auth(method, f"api/v2/{path}", auth_manager)
|
||||
if auth_check['required']:
|
||||
auth_result = auth_manager.validate_request(handler, 'admin')
|
||||
if not auth_result.get('authenticated'):
|
||||
|
||||
Reference in New Issue
Block a user