mirror of
https://github.com/hansjone/oclaw.git
synced 2026-10-11 04:10:44 +08:00
将高风险 public 工具开关改为按用户生效。
在 Admin 工作区路径页新增并保存用户级 public_tools_allow_high,扩展用户路径策略存储字段并让 catalog 风险门控优先读取该用户策略(环境变量仍可覆盖)。 Made-with: Cursor
This commit is contained in:
parent
e06184cc2f
commit
5ef9abb069
4 changed files with 81 additions and 11 deletions
|
|
@ -1401,8 +1401,18 @@ def build_admin_router() -> APIRouter:
|
|||
raise HTTPException(status_code=403, detail="workspace_paths_self_only")
|
||||
row = store.get_user_workspace_path_allowlist(tenant_id=tid, user_id=uid)
|
||||
if not row:
|
||||
return {"ok": True, "from_db": False, "policy": {"extra_roots": "", "allow_any_path": False}}
|
||||
return {"ok": True, "from_db": True, "policy": row}
|
||||
return {
|
||||
"ok": True,
|
||||
"from_db": False,
|
||||
"policy": {"extra_roots": "", "allow_any_path": False},
|
||||
"public_tools_allow_high": False,
|
||||
}
|
||||
return {
|
||||
"ok": True,
|
||||
"from_db": True,
|
||||
"policy": row,
|
||||
"public_tools_allow_high": bool(row.get("allow_high_risk_public_tools")),
|
||||
}
|
||||
|
||||
@router.post("/admin/api/users/workspace-path-policy")
|
||||
def api_users_workspace_path_policy_save(
|
||||
|
|
@ -1429,11 +1439,13 @@ def build_admin_router() -> APIRouter:
|
|||
if err:
|
||||
return {"ok": False, "error": err}
|
||||
allow_any = bool(payload.get("allow_any_path", False))
|
||||
allow_high = bool(payload.get("public_tools_allow_high", False))
|
||||
store.upsert_user_workspace_path_allowlist(
|
||||
tenant_id=tid,
|
||||
user_id=uid,
|
||||
extra_roots=norm,
|
||||
allow_any_path=allow_any,
|
||||
allow_high_risk_public_tools=allow_high,
|
||||
)
|
||||
store.add_admin_audit_log(
|
||||
actor_tenant_id=ctx["tenant_id"],
|
||||
|
|
@ -1442,10 +1454,15 @@ def build_admin_router() -> APIRouter:
|
|||
target_type="user",
|
||||
target_id=uid,
|
||||
status="ok",
|
||||
detail={"tenant_id": tid, "allow_any_path": allow_any, "extra_roots_preview": norm[:500]},
|
||||
detail={
|
||||
"tenant_id": tid,
|
||||
"allow_any_path": allow_any,
|
||||
"public_tools_allow_high": bool(allow_high),
|
||||
"extra_roots_preview": norm[:500],
|
||||
},
|
||||
)
|
||||
row = store.get_user_workspace_path_allowlist(tenant_id=tid, user_id=uid)
|
||||
return {"ok": True, "policy": row or {}}
|
||||
return {"ok": True, "policy": row or {}, "public_tools_allow_high": bool((row or {}).get("allow_high_risk_public_tools"))}
|
||||
|
||||
@router.post("/admin/api/users/delete-unbound")
|
||||
def api_users_delete_unbound(
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue