P0-A: 修复鉴权体系

- check_endpoint_auth 路径归一化(无前导斜杠),v1/v2 端点级鉴权真正生效
- ADMIN_API_ENDPOINTS 重建:修复 files 单复数、补 mirrors/alerts/prewarm/api-docs/user-password
- handler check_auth 方法感知:公开端点仅 GET/HEAD,写操作默认要求认证(fail-closed)
- 补全受保护端点(monitor/activity/login-logs/mirrors/alerts/prewarm/file 元数据)
- _check_basic_auth/_check_token_auth 改用 hmac.compare_digest
- do_POST/do_HEAD 解析路径时剥离查询串;do_HEAD 增加 is_safe_path 检查
- is_safe_path 改用 realpath 防符号链接绕过
This commit is contained in:
HYC Fixer
2026-08-30 12:16:14 +08:00
parent a8e773839b
commit ffae028664
5 changed files with 164 additions and 66 deletions
+2 -2
View File
@@ -83,7 +83,6 @@ class APIv2(APIv1):
public_endpoints = [
'admin/auth/verify',
'user/login',
'user/password',
'search/enhanced',
'search/by-tag',
'search/by-date',
@@ -100,7 +99,8 @@ class APIv2(APIv1):
# 如果需要认证(不是公开端点且auth_type不是none)
if auth_manager and not is_public and not skip_auth:
auth_check = check_endpoint_auth(method, path, auth_manager)
# 传入完整路径(api/v2/ 前缀),与 ADMIN_API_ENDPOINTS 规则匹配
auth_check = check_endpoint_auth(method, f"api/v2/{path}", auth_manager)
if auth_check['required']:
auth_result = auth_manager.validate_request(handler, 'admin')
if not auth_result.get('authenticated'):