pipeline-sdlc/wwwroot/workspace_edit.xterm
ymq 524abb23e6 feat(workspace): 工作空间端点按会话解析项目(session_id)
- workspace_popup/tree/files/view/open/delete/upload/file + office_read/save 读 session_id 传 get_workspace_dir
- 内部 URL 链路(查看/编辑/删除/上传/文件/vi编辑/univer-office)透传 session_id
- workspace_edit.xterm 手写项目解析收敛到 get_workspace_dir(session_id)
2026-08-24 16:40:49 +08:00

72 lines
1.9 KiB
Plaintext
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

import os
import shlex
import shutil
file_id = (params_kw or {}).get('id', '').strip()
uid = await get_user()
if not uid:
uid = 'user-01'
session_id = (params_kw or {}).get('session_id', '') or ''
dbname = get_module_dbname('pipeline-sdlc')
async with DBPools().sqlorContext(dbname) as sor:
ws_dir, _ = await get_workspace_dir(sor, uid, session_id)
if not file_id or not ws_dir:
r = DictObject()
r.host = 'localhost'
r.username = 'pipeline'
r.cmdargs = ['echo 未指定文件']
return r
full_path = ws_dir + '/' + file_id
# 路径穿越校验
real_ws = os.path.realpath(ws_dir)
real_full = os.path.realpath(full_path)
if not real_full.startswith(real_ws + os.sep):
r = DictObject()
r.host = 'localhost'
r.username = 'pipeline'
r.cmdargs = ['echo 非法路径']
return r
# bwrap 沙箱路径(不存在则拒绝终端,安全优先,不给完整 shell)
bwrap = shutil.which('bwrap')
if not bwrap and os.path.exists('/d/pipeline/pipeline-app/bin/bwrap'):
bwrap = '/d/pipeline/pipeline-app/bin/bwrap'
r = DictObject()
r.host = 'localhost'
r.username = 'pipeline'
if not bwrap:
r.cmdargs = ['echo 沙箱不可用,已拒绝终端访问']
return r
# bwrap 沙箱:只暴露 workspace(挂载到 /home 可写)+ 只读系统目录,
# 隔离 user/pid/ipc/uts/net,防 rm -rf /、sudo 提权、越界访问、网络攻击
cmd = (
bwrap +
' --unshare-user --unshare-pid --unshare-ipc --unshare-uts --unshare-net'
' --die-with-parent'
' --ro-bind /usr /usr'
' --ro-bind /bin /bin'
' --ro-bind /sbin /sbin'
' --ro-bind /lib /lib'
' --ro-bind /lib64 /lib64'
' --ro-bind /etc /etc'
' --proc /proc'
' --dev /dev'
' --tmpfs /tmp'
' --bind ' + shlex.quote(real_ws) + ' /home'
' --chdir /home'
' --setenv HOME /home'
' -- vi ' + shlex.quote(file_id)
)
r.cmdargs = [cmd]
return r