mirror of
https://github.com/hansjone/oclaw.git
synced 2026-10-10 09:10:46 +08:00
将高风险 public 工具开关改为按用户生效。
在 Admin 工作区路径页新增并保存用户级 public_tools_allow_high,扩展用户路径策略存储字段并让 catalog 风险门控优先读取该用户策略(环境变量仍可覆盖)。 Made-with: Cursor
This commit is contained in:
parent
e06184cc2f
commit
5ef9abb069
4 changed files with 81 additions and 11 deletions
|
|
@ -273,7 +273,21 @@ def materialize_tool_specs(
|
|||
# Optional safety gate for public tools.
|
||||
# Default: only allow low risk public tools to be visible to all roles.
|
||||
# Override via env: AIA_PUBLIC_TOOLS_ALLOW_HIGH=1 to allow high risk public tools.
|
||||
allow_high = _is_truthy(os.getenv("AIA_PUBLIC_TOOLS_ALLOW_HIGH", "0"))
|
||||
# If env is unset, fallback to per-user workspace path policy switch.
|
||||
raw_env = str(os.getenv("AIA_PUBLIC_TOOLS_ALLOW_HIGH") or "").strip()
|
||||
if raw_env:
|
||||
allow_high = _is_truthy(raw_env)
|
||||
else:
|
||||
allow_high = False
|
||||
try:
|
||||
if store is not None and path_policy_tenant_id and path_policy_user_id:
|
||||
row = store.get_user_workspace_path_allowlist(
|
||||
tenant_id=str(path_policy_tenant_id),
|
||||
user_id=str(path_policy_user_id),
|
||||
)
|
||||
allow_high = bool((row or {}).get("allow_high_risk_public_tools"))
|
||||
except Exception:
|
||||
allow_high = False
|
||||
if allow_high:
|
||||
return True
|
||||
return str(getattr(spec, "risk_level", "") or "low").strip().lower() != "high"
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue