Tighten WebCRT command audit: reject device errors and stdout replay.

Only audit interactive commands from frontend audit_line with a CLI prompt prefix; skip prompt-sync Enter and device error echoes; join wrapped xterm rows for long commands.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-09-02 14:47:12 +08:00
parent 52424dce37
commit 302ebfac23
5 changed files with 163 additions and 27 deletions

View file

@ -539,14 +539,49 @@ def _is_prompt_command_line(line: str) -> bool:
)
def _has_cli_prompt_prefix(line: str) -> bool:
s = normalize_audit_line(line)
return bool(
re.match(
r"^(?:"
r"[\w.-]+(?:\([^)]+\))*[#>]"
r"|>[\w.-]+"
r"|<[^>]+>"
r"|\[[^\]]+\]"
r")",
s,
flags=re.I,
)
)
def _is_device_output_line(line: str) -> bool:
"""Device error/warning echo — never an operator-typed command."""
s = normalize_audit_line(line).strip()
if not s:
return False
low = s.lower()
if low.startswith("%error") or low.startswith("%warning"):
return True
if "invalid input detected" in low:
return True
if re.match(r"^\^+\s*$", s):
return True
if re.match(r"^enter configuration commands", low):
return True
return False
def is_auditable_command_line(line: str) -> bool:
"""False for empty Enter (prompt only, no command text)."""
"""False for empty Enter, device output, or lines without a CLI prompt prefix."""
s = normalize_audit_line(line)
if not s.strip():
return False
if _is_prompt_only_line(s):
return False
return True
if _is_device_output_line(s):
return False
return _has_cli_prompt_prefix(s)
def _is_prompt_only_line(line: str) -> bool: