Protect private API routes and scope agent data
This commit is contained in:
@@ -157,6 +157,8 @@ def create_change_preview(
|
||||
relative_path: str,
|
||||
operation: str,
|
||||
content: str,
|
||||
*,
|
||||
user_id: str | None = None,
|
||||
) -> dict[str, object]:
|
||||
"""Build and retain a short-lived diff; this function never writes the file."""
|
||||
raw_content = content.encode("utf-8")
|
||||
@@ -202,6 +204,7 @@ def create_change_preview(
|
||||
"content": proposed_bytes,
|
||||
"expected_hash": hashlib.sha256(original).hexdigest(),
|
||||
"expires_at": time.time() + PROPOSAL_TTL_SECONDS,
|
||||
"user_id": user_id,
|
||||
}
|
||||
return {
|
||||
"token": token,
|
||||
@@ -212,11 +215,17 @@ def create_change_preview(
|
||||
}
|
||||
|
||||
|
||||
def apply_change_preview(token: str) -> dict[str, str]:
|
||||
def apply_change_preview(
|
||||
token: str, *, user_id: str | None = None
|
||||
) -> dict[str, str]:
|
||||
"""Apply a reviewed proposal once, only if its target is still unchanged."""
|
||||
proposal = _pending_changes.pop(token, None)
|
||||
proposal = _pending_changes.get(token)
|
||||
if proposal is None or float(proposal["expires_at"]) <= time.time():
|
||||
_pending_changes.pop(token, None)
|
||||
raise ValueError("انتهت صلاحية معاينة التغيير أو استُخدمت مسبقًا؛ أنشئ معاينة جديدة.")
|
||||
if proposal.get("user_id") != user_id:
|
||||
raise ValueError("معاينة التعديل لا تخص جلسة المستخدم الحالية.")
|
||||
_pending_changes.pop(token, None)
|
||||
|
||||
root = Path(str(proposal["root"])).resolve(strict=True)
|
||||
relative_path = str(proposal["path"])
|
||||
|
||||
Reference in New Issue
Block a user