P0-A: 修复鉴权体系

- check_endpoint_auth 路径归一化(无前导斜杠),v1/v2 端点级鉴权真正生效
- ADMIN_API_ENDPOINTS 重建:修复 files 单复数、补 mirrors/alerts/prewarm/api-docs/user-password
- handler check_auth 方法感知:公开端点仅 GET/HEAD,写操作默认要求认证(fail-closed)
- 补全受保护端点(monitor/activity/login-logs/mirrors/alerts/prewarm/file 元数据)
- _check_basic_auth/_check_token_auth 改用 hmac.compare_digest
- do_POST/do_HEAD 解析路径时剥离查询串;do_HEAD 增加 is_safe_path 检查
- is_safe_path 改用 realpath 防符号链接绕过
This commit is contained in:
HYC Fixer
2026-08-30 12:16:14 +08:00
parent a8e773839b
commit ffae028664
5 changed files with 164 additions and 66 deletions
+6 -3
View File
@@ -84,10 +84,13 @@ def sanitize_filename(filename: str) -> str:
def is_safe_path(base_dir: str, path: str) -> bool:
"""检查路径是否安全(防止目录遍历)"""
"""检查路径是否安全(防止目录遍历)
使用 realpath 解析符号链接,避免 base_dir 内 symlink 指向外部目录的绕过。
"""
try:
abs_path = os.path.abspath(path)
abs_base = os.path.abspath(base_dir)
abs_path = os.path.realpath(path)
abs_base = os.path.realpath(base_dir)
common_path = os.path.commonpath([abs_path, abs_base])
return common_path == abs_base
except ValueError: