mirror of
https://github.com/hansjone/oclaw.git
synced 2026-10-11 23:03:53 +08:00
同时收敛启动与运维脚本默认行为(含 wiki worker)、更新 Admin 可观测性与相关测试,降低首轮时延并提高运行稳定性。 Made-with: Cursor
40 lines
1.2 KiB
TypeScript
40 lines
1.2 KiB
TypeScript
import { fetchWithSsrFGuard } from "../../../../src/infra/net/fetch-guard.js";
|
|
import type { SsrFPolicy } from "../../../../src/infra/net/ssrf.js";
|
|
|
|
export function buildRemoteBaseUrlPolicy(baseUrl: string): SsrFPolicy | undefined {
|
|
const trimmed = baseUrl.trim();
|
|
if (!trimmed) {
|
|
return undefined;
|
|
}
|
|
try {
|
|
const parsed = new URL(trimmed);
|
|
if (parsed.protocol !== "http:" && parsed.protocol !== "https:") {
|
|
return undefined;
|
|
}
|
|
// Keep policy tied to the configured host so private operator endpoints
|
|
// continue to work, while cross-host redirects stay blocked.
|
|
return { allowedHostnames: [parsed.hostname] };
|
|
} catch {
|
|
return undefined;
|
|
}
|
|
}
|
|
|
|
export async function withRemoteHttpResponse<T>(params: {
|
|
url: string;
|
|
init?: RequestInit;
|
|
ssrfPolicy?: SsrFPolicy;
|
|
auditContext?: string;
|
|
onResponse: (response: Response) => Promise<T>;
|
|
}): Promise<T> {
|
|
const { response, release } = await fetchWithSsrFGuard({
|
|
url: params.url,
|
|
init: params.init,
|
|
policy: params.ssrfPolicy,
|
|
auditContext: params.auditContext ?? "memory-remote",
|
|
});
|
|
try {
|
|
return await params.onResponse(response);
|
|
} finally {
|
|
await release();
|
|
}
|
|
}
|