mirror of
https://github.com/pewdiepie-archdaemon/odysseus.git
synced 2026-10-09 16:32:21 +02:00
feat(runtime): bind process and job resources to authority
This commit is contained in:
@@ -405,7 +405,20 @@ def _append_local_ollama_download_command_lines(
|
||||
|
||||
|
||||
def setup_cookbook_routes() -> APIRouter:
|
||||
router = APIRouter(tags=["cookbook"])
|
||||
async def protect_native_control(request: Request):
|
||||
if request.method in {"GET", "HEAD"}:
|
||||
return
|
||||
# Cookbook's UI records and session strings are not an application
|
||||
# process registry. No loopback caller can use them as local authority.
|
||||
path = request.url.path
|
||||
from routes.shell_routes import _require_admin
|
||||
if path in {"/api/cookbook/kill-pid", "/api/cookbook/state", "/api/cookbook/ssh-key"}:
|
||||
_require_admin(request)
|
||||
if path in {"/api/model/download", "/api/model/serve"}:
|
||||
payload = await request.json()
|
||||
if not payload.get("remote_host"):
|
||||
_require_admin(request)
|
||||
router = APIRouter(tags=["cookbook"], dependencies=[Depends(protect_native_control)])
|
||||
_cookbook_state_path = Path(COOKBOOK_STATE_FILE)
|
||||
_state_get_cache = {"ts": 0.0, "mtime": 0.0, "value": None}
|
||||
_tasks_status_cache = {"ts": 0.0, "value": None}
|
||||
|
||||
+7
-11
@@ -59,21 +59,17 @@ from core.platform_compat import (
|
||||
def _require_admin(request: Request):
|
||||
"""Reject non-admin callers. Shell exec is admin-only — never expose to
|
||||
regular users; that's RCE-after-signup."""
|
||||
# In the explicitly single-user, auth-disabled deployment the middleware
|
||||
# does not attach a current user. AuthManager is still instantiated by the
|
||||
# app, so checking only for its presence incorrectly returns 403 here.
|
||||
# Anonymous loopback is also reachable from an admitted native workload.
|
||||
# It cannot be treated as a human admin or as process creation authority.
|
||||
from src.agent_runtime.authority import is_internal_tool_request
|
||||
if is_internal_tool_request(request):
|
||||
raise HTTPException(403, "Internal shell execution requires a dedicated resource-bound producer")
|
||||
if _auth_disabled():
|
||||
return
|
||||
raise HTTPException(403, "Anonymous native process control has no resource authority")
|
||||
auth_manager = getattr(request.app.state, "auth_manager", None)
|
||||
if not auth_manager:
|
||||
# No auth at all — only safe in fully-trusted localhost dev mode
|
||||
return
|
||||
raise HTTPException(403, "Native process control requires authenticated administration")
|
||||
user = getattr(request.state, "current_user", None)
|
||||
# In-process tool loopback. The AuthMiddleware already validated the
|
||||
# internal token + loopback client before setting this marker, so
|
||||
# honour it here as admin-equivalent.
|
||||
if user == INTERNAL_TOOL_USER:
|
||||
return
|
||||
if not user or user == "api":
|
||||
raise HTTPException(403, "Admin only")
|
||||
if not auth_manager.is_admin(user):
|
||||
|
||||
Reference in New Issue
Block a user