mirror of
https://github.com/hansjone/dsh-ops-cron.git
synced 2026-10-09 01:53:19 +08:00
Fix cron cwd for super_admin and harden IM channel job isolation.
Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
parent
b35bfde557
commit
b1bb0067a0
16 changed files with 714 additions and 49 deletions
|
|
@ -4,6 +4,7 @@
|
|||
*/
|
||||
|
||||
import { DEFAULT_LOCALE, t } from './i18n.js'
|
||||
import { canViewAllJobs, isMultiUserIdentity } from './ownership.js'
|
||||
|
||||
export function normalizeDelivery(input = {}) {
|
||||
const src = input && typeof input === 'object' ? input : {}
|
||||
|
|
@ -28,6 +29,25 @@ export function normalizeDelivery(input = {}) {
|
|||
return { kind: 'dsh' }
|
||||
}
|
||||
|
||||
/**
|
||||
* Web/sidebar callers who are not super_admin must not aim IM delivery at
|
||||
* arbitrary bot/target ids (confused deputy). Channel jobs bind delivery via peer.
|
||||
* @param {object|null|undefined} delivery
|
||||
* @param {object|null|undefined} identity
|
||||
*/
|
||||
export function assertDeliveryAllowedForIdentity(delivery, identity) {
|
||||
if (!delivery || delivery.kind !== 'im') return delivery
|
||||
if (!identity?.empNo) return delivery
|
||||
// Standalone local identity may still configure IM for single-user hosts.
|
||||
if (!isMultiUserIdentity(identity)) return delivery
|
||||
if (canViewAllJobs(identity)) return delivery
|
||||
const error = new Error(
|
||||
'only super_admin can set WhatsApp/IM delivery from the web sidebar; create channel jobs from the IM chat',
|
||||
)
|
||||
error.code = 'IM_DELIVERY_FORBIDDEN'
|
||||
throw error
|
||||
}
|
||||
|
||||
/**
|
||||
* Keep creator @mention when the UI re-saves the same IM target without mention fields.
|
||||
* @param {object|null|undefined} previous
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue