pipeline-sdlc/wwwroot/api/workspace_file.dspy
ymq 0c66bdee81 fix(workspace): 工作控件产线隔离——弹窗与9个子端点全部按产线过滤
- workspace_popup 把 pipeline_id 透传给树/文件/查看/编辑/删除子端点
- 9个子端点 get_project_dir→get_project_dir_pl(跨产线项目视为无项目)
- 开发驾驶舱工作空间按钮补传 pipeline_id=sdlc_general
- 修复:会话绑投标项目时开发驾驶舱工作空间直接打开投标项目目录(已实测复现)
2026-08-31 16:54:08 +08:00

45 lines
1.6 KiB
Plaintext

# workspace_file.dspy - 提供工作空间文件(媒体流 / 下载)
import os
from urllib.parse import quote
from aiohttp.web_fileresponse import FileResponse
file_id = (params_kw or {}).get('id', '').strip()
download = (params_kw or {}).get('download', '').strip()
uid = await get_user()
if not uid:
uid = 'user-01'
session_id = (params_kw or {}).get('session_id', '') or ''
pipeline_id = (params_kw or {}).get('pipeline_id', '') or ''
dbname = get_module_dbname('pipeline-sdlc')
async with DBPools().sqlorContext(dbname) as sor:
# 产线隔离:跨产线项目视为无项目(与弹窗入口一致,防绕过)
project_dir, _ = await get_project_dir_pl(sor, uid, session_id, pipeline_id)
space_dir, _ = await get_space_dir(sor, uid, session_id)
if not file_id or file_id == '__root__':
return {"widgettype": "Message", "options": {"title": "错误", "message": "未指定文件"}}
full_path = resolve_workspace_path(project_dir, space_dir, file_id)
# 路径穿越校验
real_ws = os.path.realpath(space_dir)
real_full = os.path.realpath(full_path)
if not real_full.startswith(real_ws + os.sep):
return {"widgettype": "Message", "options": {"title": "错误", "message": "非法路径"}}
if not os.path.isfile(full_path):
return {"widgettype": "Message", "options": {"title": "错误", "message": "文件不存在: " + file_id}}
headers = {}
if download:
filename = os.path.basename(full_path)
safe_name = quote(filename)
headers['Content-Disposition'] = 'attachment; filename="%s"; filename*=UTF-8\'\'%s' % (filename, safe_name)
return FileResponse(full_path, headers=headers)