fix(isolation): 第7层泄漏——通用会话历史回放不过滤产线,跨产线对话进上下文

实测:工具/文件系统隔离生效后,通用助手仍复述出产线项目ID。
根因:_load_history 无 session_id 分支按 created_by 全量回放该用户
所有产线的最近对话(项目名称/ID 随历史泄漏)。

修复:通用会话只回放 pipeline_id='' 的历史(存库时 store_pl='' 与
此过滤对称);有 session_id 的分支同样加通用会话空产线过滤。
This commit is contained in:
ymq 2026-09-05 15:27:00 +08:00
parent 5c28fed040
commit b93617feaf

View File

@ -1531,11 +1531,16 @@ class AgentExecutor:
# 产线隔离(2026-08-31 修复跨产线串扰):各产线页面默认 tab 共用
# session_id='default',历史若不按产线过滤,投标页会加载开发页的
# 对话(如"元景项目/新建demo项目"),LLM 跟着最后上下文答错产线。
# 2026-09-05 第7层泄漏修复:通用会话(存库时 pipeline_id='')只回放
# 自己的历史,否则会加载该用户各产线的最近对话——项目名称/ID
# 等产线信息随历史泄漏进通用助手。
sql = ("SELECT role, content FROM pipeline_conversations "
"WHERE session_id=${sid}$ AND created_by=${uid}$ ")
params = {"sid": self.session_id, "uid": self.user_id or "",
"lim": self.config.history_limit}
if self.pipeline_id and not self.generic:
if self.generic:
sql += "AND (pipeline_id='' OR pipeline_id IS NULL) "
elif self.pipeline_id:
sql += "AND pipeline_id=${pl}$ "
params["pl"] = self.pipeline_id
sql += "ORDER BY created_at DESC LIMIT ${lim}$"
@ -1550,6 +1555,16 @@ class AgentExecutor:
"ORDER BY created_at DESC LIMIT ${lim}$",
{"pid": pid, "uid": self.user_id or "", "lim": self.config.history_limit},
)
elif self.generic:
# 2026-09-05 第7层泄漏修复:通用会话只回放自己的历史
# (存库时 generic 会话 pipeline_id=''),禁止按 user_id 全量
# 回放——否则用户各产线最近对话(含项目名称/ID)全部泄漏。
recs = await sor.sqlExe(
"SELECT role, content FROM pipeline_conversations "
"WHERE created_by=${uid}$ AND (pipeline_id='' OR pipeline_id IS NULL) "
"ORDER BY created_at DESC LIMIT ${lim}$",
{"uid": self.user_id or "", "lim": self.config.history_limit},
)
else:
recs = await sor.sqlExe(
"SELECT role, content FROM pipeline_conversations "