Protect private API routes and scope agent data

This commit is contained in:
Hamza Ayed
2026-10-03 00:34:49 +03:00
parent 1c1f662850
commit b0cd825838
17 changed files with 313 additions and 95 deletions
+11 -2
View File
@@ -157,6 +157,8 @@ def create_change_preview(
relative_path: str,
operation: str,
content: str,
*,
user_id: str | None = None,
) -> dict[str, object]:
"""Build and retain a short-lived diff; this function never writes the file."""
raw_content = content.encode("utf-8")
@@ -202,6 +204,7 @@ def create_change_preview(
"content": proposed_bytes,
"expected_hash": hashlib.sha256(original).hexdigest(),
"expires_at": time.time() + PROPOSAL_TTL_SECONDS,
"user_id": user_id,
}
return {
"token": token,
@@ -212,11 +215,17 @@ def create_change_preview(
}
def apply_change_preview(token: str) -> dict[str, str]:
def apply_change_preview(
token: str, *, user_id: str | None = None
) -> dict[str, str]:
"""Apply a reviewed proposal once, only if its target is still unchanged."""
proposal = _pending_changes.pop(token, None)
proposal = _pending_changes.get(token)
if proposal is None or float(proposal["expires_at"]) <= time.time():
_pending_changes.pop(token, None)
raise ValueError("انتهت صلاحية معاينة التغيير أو استُخدمت مسبقًا؛ أنشئ معاينة جديدة.")
if proposal.get("user_id") != user_id:
raise ValueError("معاينة التعديل لا تخص جلسة المستخدم الحالية.")
_pending_changes.pop(token, None)
root = Path(str(proposal["root"])).resolve(strict=True)
relative_path = str(proposal["path"])