P0-A: 修复鉴权体系
- check_endpoint_auth 路径归一化(无前导斜杠),v1/v2 端点级鉴权真正生效 - ADMIN_API_ENDPOINTS 重建:修复 files 单复数、补 mirrors/alerts/prewarm/api-docs/user-password - handler check_auth 方法感知:公开端点仅 GET/HEAD,写操作默认要求认证(fail-closed) - 补全受保护端点(monitor/activity/login-logs/mirrors/alerts/prewarm/file 元数据) - _check_basic_auth/_check_token_auth 改用 hmac.compare_digest - do_POST/do_HEAD 解析路径时剥离查询串;do_HEAD 增加 is_safe_path 检查 - is_safe_path 改用 realpath 防符号链接绕过
This commit is contained in:
+6
-3
@@ -84,10 +84,13 @@ def sanitize_filename(filename: str) -> str:
|
||||
|
||||
|
||||
def is_safe_path(base_dir: str, path: str) -> bool:
|
||||
"""检查路径是否安全(防止目录遍历)"""
|
||||
"""检查路径是否安全(防止目录遍历)
|
||||
|
||||
使用 realpath 解析符号链接,避免 base_dir 内 symlink 指向外部目录的绕过。
|
||||
"""
|
||||
try:
|
||||
abs_path = os.path.abspath(path)
|
||||
abs_base = os.path.abspath(base_dir)
|
||||
abs_path = os.path.realpath(path)
|
||||
abs_base = os.path.realpath(base_dir)
|
||||
common_path = os.path.commonpath([abs_path, abs_base])
|
||||
return common_path == abs_base
|
||||
except ValueError:
|
||||
|
||||
Reference in New Issue
Block a user