Restrict workspace paths to configured roots
This commit is contained in:
@@ -29,12 +29,30 @@ MAX_PENDING_PROPOSALS = 32
|
||||
_pending_changes: dict[str, dict[str, object]] = {}
|
||||
|
||||
|
||||
def configured_roots() -> tuple[Path, ...]:
|
||||
"""Return the server administrator's allow-listed workspace roots."""
|
||||
configured = os.getenv("SOVEREIGNAI_ALLOWED_WORKSPACES")
|
||||
if configured:
|
||||
values = configured.split(os.pathsep)
|
||||
else:
|
||||
primary = os.getenv("SOVEREIGNAI_WORKSPACE")
|
||||
values = [primary] if primary else []
|
||||
roots: list[Path] = []
|
||||
for value in values:
|
||||
if not value or not value.strip():
|
||||
continue
|
||||
try:
|
||||
root = Path(value.strip()).expanduser().resolve(strict=True)
|
||||
except (OSError, RuntimeError):
|
||||
continue
|
||||
if root.is_dir() and root not in roots:
|
||||
roots.append(root)
|
||||
return tuple(roots)
|
||||
|
||||
|
||||
def configured_root() -> Path | None:
|
||||
value = os.getenv("SOVEREIGNAI_WORKSPACE")
|
||||
if not value:
|
||||
return None
|
||||
root = Path(value).expanduser().resolve()
|
||||
return root if root.is_dir() else None
|
||||
roots = configured_roots()
|
||||
return roots[0] if roots else None
|
||||
|
||||
|
||||
def selected_root(value: str | None) -> Path | None:
|
||||
@@ -51,6 +69,11 @@ def selected_root(value: str | None) -> Path | None:
|
||||
raise ValueError("اختر مجلد مشروع محددًا، وليس جذر القرص.")
|
||||
if root.name.startswith(".") or root.name in IGNORED_PARTS:
|
||||
raise ValueError("لا يمكن استخدام مجلد مخفي أو مستثنى كمساحة عمل.")
|
||||
allowed_roots = configured_roots()
|
||||
if allowed_roots and not any(
|
||||
root == allowed or allowed in root.parents for allowed in allowed_roots
|
||||
):
|
||||
raise ValueError("المساحة المحددة خارج مجلدات المشاريع المصرح بها على الخادم.")
|
||||
return root
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user