feat(ne): add managed NE read-only exec API

Add a guarded managed-ne exec endpoint for oclaw ops tools to login managed devices and run read-only CLI safely.
Include request schema and unit tests for command guardrails and execution flow.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-05-28 22:12:50 +08:00
parent dc17f9d15a
commit 981347b5b1
4 changed files with 208 additions and 1 deletions

View file

@ -8,7 +8,8 @@ from .db import get_db
from .device_types import SUPPORTED_DEVICE_TYPES, SUPPORTED_VENDORS
from .ne_connect import schedule_connect_tests
from .ne_crypto import credentials_configured
from .ne_schemas import BatchHopApplyRequest, ConnectTestRequest, ManagedNeCreate, ManagedNeUpdate
from .ne_exec import execute_managed_ne_commands
from .ne_schemas import BatchHopApplyRequest, ConnectTestRequest, ManagedNeCreate, ManagedNeExecRequest, ManagedNeUpdate
from .ne_service import (
batch_apply_hop_proxy,
build_managed_ne_import_template,
@ -102,6 +103,17 @@ def api_batch_delete_managed_ne(body: ConnectTestRequest, db: Session = Depends(
return batch_delete_managed_ne(db, body.ids)
@router.post("/exec")
def api_exec_managed_ne(body: ManagedNeExecRequest, db: Session = Depends(get_db)):
"""Login to a managed NE and run read-only CLI (show/display/ping). For oclaw ops tools."""
return execute_managed_ne_commands(
db,
body.ne_id,
body.commands,
read_timeout_sec=body.read_timeout_sec,
)
@router.post("/connect-test")
def api_connect_test(body: ConnectTestRequest, db: Session = Depends(get_db)):
ids = [str(x).strip() for x in body.ids if str(x).strip()]