feat(runtime): bind process and job resources to authority

This commit is contained in:
Alexandre Teixeira
2026-10-02 18:54:09 +01:00
parent 7b8ac6f631
commit db41d7e822
36 changed files with 2251 additions and 174 deletions
+14 -1
View File
@@ -405,7 +405,20 @@ def _append_local_ollama_download_command_lines(
def setup_cookbook_routes() -> APIRouter:
router = APIRouter(tags=["cookbook"])
async def protect_native_control(request: Request):
if request.method in {"GET", "HEAD"}:
return
# Cookbook's UI records and session strings are not an application
# process registry. No loopback caller can use them as local authority.
path = request.url.path
from routes.shell_routes import _require_admin
if path in {"/api/cookbook/kill-pid", "/api/cookbook/state", "/api/cookbook/ssh-key"}:
_require_admin(request)
if path in {"/api/model/download", "/api/model/serve"}:
payload = await request.json()
if not payload.get("remote_host"):
_require_admin(request)
router = APIRouter(tags=["cookbook"], dependencies=[Depends(protect_native_control)])
_cookbook_state_path = Path(COOKBOOK_STATE_FILE)
_state_get_cache = {"ts": 0.0, "mtime": 0.0, "value": None}
_tasks_status_cache = {"ts": 0.0, "value": None}
+7 -11
View File
@@ -59,21 +59,17 @@ from core.platform_compat import (
def _require_admin(request: Request):
"""Reject non-admin callers. Shell exec is admin-only — never expose to
regular users; that's RCE-after-signup."""
# In the explicitly single-user, auth-disabled deployment the middleware
# does not attach a current user. AuthManager is still instantiated by the
# app, so checking only for its presence incorrectly returns 403 here.
# Anonymous loopback is also reachable from an admitted native workload.
# It cannot be treated as a human admin or as process creation authority.
from src.agent_runtime.authority import is_internal_tool_request
if is_internal_tool_request(request):
raise HTTPException(403, "Internal shell execution requires a dedicated resource-bound producer")
if _auth_disabled():
return
raise HTTPException(403, "Anonymous native process control has no resource authority")
auth_manager = getattr(request.app.state, "auth_manager", None)
if not auth_manager:
# No auth at all — only safe in fully-trusted localhost dev mode
return
raise HTTPException(403, "Native process control requires authenticated administration")
user = getattr(request.state, "current_user", None)
# In-process tool loopback. The AuthMiddleware already validated the
# internal token + loopback client before setting this marker, so
# honour it here as admin-equivalent.
if user == INTERNAL_TOOL_USER:
return
if not user or user == "api":
raise HTTPException(403, "Admin only")
if not auth_manager.is_admin(user):