mirror of
https://github.com/hansjone/oclaw.git
synced 2026-10-09 07:20:44 +08:00
重构仓库目录为统一的 runtime 分层并清理历史 openclaw 残留。
本次迁移将网关/通道/工具/技能/脚本与协议资源集中到新结构,统一路径常量与脚本转发机制,减少顶层噪音并保证运行与测试行为一致。 Made-with: Cursor
This commit is contained in:
parent
ba3836f00f
commit
4a23b715a2
498 changed files with 2760 additions and 2200 deletions
54
runtime/orchestration/security.py
Normal file
54
runtime/orchestration/security.py
Normal file
|
|
@ -0,0 +1,54 @@
|
|||
from __future__ import annotations
|
||||
|
||||
from dataclasses import dataclass
|
||||
|
||||
from oclaw.runtime.orchestration.protocol import AgentTask
|
||||
|
||||
_HIGH_RISK_ACTIONS = ("删除", "drop", "重启", "批量", "扫描", "写入", "变更")
|
||||
|
||||
|
||||
@dataclass(frozen=True)
|
||||
class GuardrailResult:
|
||||
allowed: bool
|
||||
needs_confirmation: bool
|
||||
reason: str
|
||||
|
||||
|
||||
def evaluate_risk(task: AgentTask) -> GuardrailResult:
|
||||
text = (task.user_text or "").lower()
|
||||
high_risk = task.risk_level == "high" or any(k in text for k in _HIGH_RISK_ACTIONS)
|
||||
if high_risk:
|
||||
return GuardrailResult(
|
||||
allowed=True,
|
||||
needs_confirmation=True,
|
||||
reason="High-risk action detected, require explicit confirmation token.",
|
||||
)
|
||||
return GuardrailResult(allowed=True, needs_confirmation=False, reason="Low-risk request")
|
||||
|
||||
|
||||
def has_explicit_confirmation(user_text: str) -> bool:
|
||||
return has_explicit_confirmation_token(user_text, token=None)
|
||||
|
||||
|
||||
def has_explicit_confirmation_token(user_text: str, token: str | None) -> bool:
|
||||
text = (user_text or "").strip()
|
||||
if not text:
|
||||
return False
|
||||
low = text.lower()
|
||||
if low.startswith("confirm "):
|
||||
if token:
|
||||
parts = low.split()
|
||||
return len(parts) >= 2 and parts[1].strip() == token.lower()
|
||||
return True
|
||||
if "[confirm]" in low or "确认执行" in low:
|
||||
return True
|
||||
if token:
|
||||
t = token.strip()
|
||||
if not t:
|
||||
return False
|
||||
if f"[confirm:{t}]".lower() in low or f"confirm:{t}".lower() in low:
|
||||
return True
|
||||
return False
|
||||
|
||||
|
||||
__all__ = ["GuardrailResult", "evaluate_risk", "has_explicit_confirmation", "has_explicit_confirmation_token"]
|
||||
Loading…
Add table
Add a link
Reference in a new issue