feat: 设备鉴权迁移至客户端 + 插件卸载保护

安全修复(客户端鉴权):
- remotedevice 服务端移除授权状态存储(authorized map/SetAuthorized/handleDeviceAuth)
- DeviceMeta.Authorized 改为设备 hello 自报,服务端仅透传展示
- device_ctl_* 工具移除服务端授权检查,无条件转发,设备端自行决定是否执行
- 共享设备桥库 Bridge 新增本地 authorized 状态,未授权收到 cmd 直接拒绝
- waiter: --device-authorized / device_authorized 配置控制本地授权
- GUI: 授权存 gui-prefs 本地文件;设备页仅本机可切换开关
- webui /device/auth 旧路径返回 410 Gone
- 根因:agent 可经 config_set 篡改服务端授权配置自行授权设备

插件管理强化:
- 内置插件禁止卸载(IsBuiltinPlugin + 409),外部插件卸载即时生效
- 卸载不存在插件返回 404;移除误导性 reload_required 提示
- webui 插件路由:名称白名单校验防路径穿越、保留字路径保护
This commit is contained in:
JianFeeeee
2026-08-24 19:26:11 +08:00
parent 5163ce51a7
commit ba5785036a
21 changed files with 616 additions and 383 deletions

View File

@ -4667,10 +4667,21 @@ background:
return;
}
try {
var r = await api("/plugins", {
var raw = await api("/plugins", {
method: "POST",
body: JSON.stringify({ url: url }),
raw: true,
});
var ct = raw.headers.get("content-type") || "";
var r = ct.includes("json") ? await raw.json() : await raw.text();
if (!raw.ok || (r && r.error)) {
toast(
__("安装失败: ", "Install failed: ") +
((r && (r.error || r.details)) || "HTTP " + raw.status),
true,
);
return;
}
toast(
__("安装结果: ", "Install result: ") +
(r.status || JSON.stringify(r)),
@ -4683,7 +4694,7 @@ background:
),
false,
);
loadInstalledPlugins();
await loadInstalledPlugins();
renderPlugins();
} catch (e) {
toast(__("安装失败: ", "Install failed: ") + e.message, true);
@ -4732,7 +4743,10 @@ background:
renderPlugins();
}
var removingPlugins = {};
async function removePlugin(name) {
if (removingPlugins[name]) return; // 防重复点击
if (
!confirm(
__("确定卸载插件", "Are you sure to unload plugin") +
@ -4742,23 +4756,39 @@ background:
)
)
return;
removingPlugins[name] = true;
try {
var r = await api("/plugins/" + encodeURIComponent(name), {
method: "DELETE",
});
toast(__("已卸载: ", "Unloaded: ") + (r.status || r.name));
if (r.action === "reload_required")
toast(
__(
"已卸载,请点击「重载插件」生效",
'Unloaded, click "Reload Plugins" to apply',
),
false,
);
loadInstalledPlugins();
var raw = await api(
"/plugins/" + encodeURIComponent(name),
{ method: "DELETE", raw: true },
);
var ct = raw.headers.get("content-type") || "";
var body = ct.includes("json")
? await raw.json()
: await raw.text();
if (!raw.ok) {
var em =
(body && (body.error || body.details)) ||
("HTTP " + raw.status);
toast(__("卸载失败: ", "Unload failed: ") + em, true);
// 内置插件或路径错误时刷新一次列表保持状态一致
loadInstalledPlugins();
renderPlugins();
return;
}
toast(__("已卸载: ", "Unloaded: ") + (body.name || body.status || name));
await loadInstalledPlugins();
// 同步内核插件/禁用列表,确保列表与工具立即消失
try {
state.kernel = await api("/kernel");
var s = await api("/settings");
state.disabledPlugins = s.disabled_plugins || [];
} catch (e2) {}
renderPlugins();
} catch (e) {
toast(__("卸载失败: ", "Unload failed: ") + e.message, true);
} finally {
delete removingPlugins[name];
}
}

View File

@ -136,13 +136,13 @@ type Handler struct {
chatHistory []ChatMsg
pendingIdx int // chatHistory 中正在进行的 assistant 消息索引,-1 表示无
chatMsgMu sync.Mutex
chatMsgCache map[string]*chatMsgEntry // client_msg_id -> 首次处理结果
chatMsgOrder []string // FIFO 淘汰序
cmdMu sync.Mutex
cmdHistory []CmdExec
termMu sync.Mutex
termStates map[string]*termState
chatMsgMu sync.Mutex
chatMsgCache map[string]*chatMsgEntry // client_msg_id -> 首次处理结果
chatMsgOrder []string // FIFO 淘汰序
cmdMu sync.Mutex
cmdHistory []CmdExec
termMu sync.Mutex
termStates map[string]*termState
}
type ChatMsg struct {
@ -243,23 +243,23 @@ func NewHandler(s *sdk.PluginSDK) *Handler {
st, llm = s.Status(), s.LLM()
}
h := &Handler{
sdk: s,
supervisor: sup,
memory: mem,
indexer: idx,
adapter: ad,
config: cfg,
startTime: time.Now(),
textMem: tm,
knowledge: ks,
tracker: tr,
settings: se,
pluginMgr: pm,
status: st,
llm: llm,
sessions: make(map[string]time.Time),
termStates: make(map[string]*termState),
pendingIdx: -1,
sdk: s,
supervisor: sup,
memory: mem,
indexer: idx,
adapter: ad,
config: cfg,
startTime: time.Now(),
textMem: tm,
knowledge: ks,
tracker: tr,
settings: se,
pluginMgr: pm,
status: st,
llm: llm,
sessions: make(map[string]time.Time),
termStates: make(map[string]*termState),
pendingIdx: -1,
chatMsgCache: make(map[string]*chatMsgEntry),
sseEvents: newSSEEventRing(200),
}
@ -1247,8 +1247,8 @@ func (h *Handler) handleChat(w http.ResponseWriter, r *http.Request) {
}
var body struct {
Message string `json:"message"`
DeviceID string `json:"device_id"` // 消息来源设备(GUI/受控设备),可选
DeviceName string `json:"device_name"` // 设备显示名,可选
DeviceID string `json:"device_id"` // 消息来源设备(GUI/受控设备),可选
DeviceName string `json:"device_name"` // 设备显示名,可选
ClientMsgID string `json:"client_msg_id"` // 客户端唯一消息 ID(防断线重放/超时重试)
}
if err := json.NewDecoder(r.Body).Decode(&body); err != nil {
@ -1848,6 +1848,14 @@ func (h *Handler) handleDeviceGatewayProxy(w http.ResponseWriter, r *http.Reques
http.NotFound(w, r)
return
}
// 客户端鉴权模式:服务端不再提供授权接口(授权由设备端本地控制)。
// 拒绝旧的 /device/auth 调用,避免误导。
if strings.HasSuffix(r.URL.Path, "/device/auth") {
writeJSON(w, http.StatusGone, map[string]string{
"error": "device authorization moved to client-side; the server no longer stores authorization state",
})
return
}
addr := deviceGatewayAddr
if addr == "" {
addr = "127.0.0.1:9890"
@ -2053,6 +2061,23 @@ func (h *Handler) handlePluginByID(w http.ResponseWriter, r *http.Request) {
path := strings.TrimPrefix(r.URL.Path, "/api/v1/plugins/")
path = strings.TrimSuffix(path, "/")
// 插件名白名单:仅允许单段安全名称,阻断路径穿越/空名/嵌套路径
validPluginName := func(s string) bool {
if s == "" || len(s) > 128 {
return false
}
// 禁止路径分隔符、连续点(父目录穿越)、冒号、空格等危险字符
if strings.Contains(s, "..") || strings.ContainsAny(s, "/\\: \t\r\n\x00") {
return false
}
for _, c := range s {
if !(c >= 'a' && c <= 'z' || c >= 'A' && c <= 'Z' || c >= '0' && c <= '9' || c == '_' || c == '-' || c == '.') {
return false
}
}
return true
}
if path == "disabled" && r.Method == http.MethodGet {
if h.pluginMgr == nil {
writeJSON(w, http.StatusInternalServerError, map[string]string{"error": "plugin manager not available"})
@ -2062,16 +2087,21 @@ func (h *Handler) handlePluginByID(w http.ResponseWriter, r *http.Request) {
return
}
if path == "reload" && r.Method == http.MethodPost {
if h.pluginMgr == nil {
writeJSON(w, http.StatusInternalServerError, map[string]string{"error": "plugin registry not available"})
if path == "reload" {
if r.Method == http.MethodPost {
if h.pluginMgr == nil {
writeJSON(w, http.StatusInternalServerError, map[string]string{"error": "plugin registry not available"})
return
}
if _, err := h.pluginMgr.ReloadPlugins(); err != nil {
writeJSON(w, http.StatusInternalServerError, map[string]string{"error": err.Error()})
return
}
writeJSON(w, http.StatusOK, map[string]string{"status": "reloaded"})
return
}
if _, err := h.pluginMgr.ReloadPlugins(); err != nil {
writeJSON(w, http.StatusInternalServerError, map[string]string{"error": err.Error()})
return
}
writeJSON(w, http.StatusOK, map[string]string{"status": "reloaded"})
// reload/disabled 是保留字,不允许 DELETE/GET 等其它操作误把其当作插件名
http.Error(w, "method not allowed", http.StatusMethodNotAllowed)
return
}
@ -2085,6 +2115,10 @@ func (h *Handler) handlePluginByID(w http.ResponseWriter, r *http.Request) {
writeJSON(w, http.StatusInternalServerError, map[string]string{"error": "plugin manager not available"})
return
}
if !validPluginName(name) {
writeJSON(w, http.StatusBadRequest, map[string]string{"error": "invalid plugin name"})
return
}
if err := h.pluginMgr.DisablePlugin(name, "webui"); err != nil {
writeJSON(w, http.StatusInternalServerError, map[string]string{"error": err.Error()})
return
@ -2097,6 +2131,10 @@ func (h *Handler) handlePluginByID(w http.ResponseWriter, r *http.Request) {
writeJSON(w, http.StatusInternalServerError, map[string]string{"error": "plugin manager not available"})
return
}
if !validPluginName(name) {
writeJSON(w, http.StatusBadRequest, map[string]string{"error": "invalid plugin name"})
return
}
if err := h.pluginMgr.EnablePlugin(name); err != nil {
writeJSON(w, http.StatusInternalServerError, map[string]string{"error": err.Error()})
return
@ -2105,6 +2143,14 @@ func (h *Handler) handlePluginByID(w http.ResponseWriter, r *http.Request) {
return
}
}
http.Error(w, "method not allowed", http.StatusMethodNotAllowed)
return
}
// 单段插件名路径(GET 详情 / DELETE 卸载)
if !validPluginName(path) {
writeJSON(w, http.StatusBadRequest, map[string]string{"error": "invalid plugin name"})
return
}
switch r.Method {

View File

@ -0,0 +1,195 @@
package webui
import (
"net/http"
"net/http/httptest"
"testing"
sdk "gitcode.com/JianFeeeee/HomeAgent/internal/sdk"
)
// mockPluginMgr 是 sdk.PluginManager 的最小实现,用于 handler 路由层测试。
type mockPluginMgr struct {
builtins map[string]bool
disabled []sdk.DisabledPluginInfo
isDisabled map[string]bool
removed []string
reloadN int
removeErr error
}
func (m *mockPluginMgr) ListLoadedPlugins() []string { return nil }
func (m *mockPluginMgr) ListDisabledPlugins() []sdk.DisabledPluginInfo {
return m.disabled
}
func (m *mockPluginMgr) IsPluginDisabled(name string) bool {
return m.isDisabled[name]
}
func (m *mockPluginMgr) IsBuiltinPlugin(name string) bool {
return m.builtins[name]
}
func (m *mockPluginMgr) DisablePlugin(name, by string) error {
if m.isDisabled == nil {
m.isDisabled = map[string]bool{}
}
m.isDisabled[name] = true
return nil
}
func (m *mockPluginMgr) EnablePlugin(name string) error {
delete(m.isDisabled, name)
return nil
}
func (m *mockPluginMgr) RemovePlugin(name string) error {
if m.removeErr != nil {
return m.removeErr
}
m.removed = append(m.removed, name)
return nil
}
func (m *mockPluginMgr) ReloadPlugins() (string, error) {
m.reloadN++
return "reloaded", nil
}
func (m *mockPluginMgr) ReloadOne(name string) error { return nil }
func (m *mockPluginMgr) PluginMetas() map[string]sdk.PluginMeta {
return nil
}
func (m *mockPluginMgr) PluginDir() string { return "" }
// newHandlerWithMock 构造带 mock PluginManager 的 Handler(绕过 SDK 组装)。
func newHandlerWithMock(m *mockPluginMgr) *Handler {
h := NewHandler(nil)
h.pluginMgr = m
return h
}
func TestHandlePluginByID_DisabledList(t *testing.T) {
m := &mockPluginMgr{
disabled: []sdk.DisabledPluginInfo{{Name: "foo"}},
}
h := newHandlerWithMock(m)
req := httptest.NewRequest(http.MethodGet, "/api/v1/plugins/disabled", nil)
w := httptest.NewRecorder()
h.handlePluginByID(w, req)
if w.Code != http.StatusOK {
t.Fatalf("expected 200, got %d", w.Code)
}
if body := w.Body.String(); len(body) == 0 || !contains(body, "foo") {
t.Fatalf("expected disabled list with foo, got %s", body)
}
}
func contains(s, sub string) bool {
return len(s) >= len(sub) && (func() bool {
for i := 0; i+len(sub) <= len(s); i++ {
if s[i:i+len(sub)] == sub {
return true
}
}
return false
})()
}
func TestHandlePluginByID_ReloadPost(t *testing.T) {
m := &mockPluginMgr{}
h := newHandlerWithMock(m)
req := httptest.NewRequest(http.MethodPost, "/api/v1/plugins/reload", nil)
w := httptest.NewRecorder()
h.handlePluginByID(w, req)
if w.Code != http.StatusOK {
t.Fatalf("expected 200, got %d: %s", w.Code, w.Body.String())
}
if m.reloadN != 1 {
t.Fatalf("expected ReloadPlugins called once, got %d", m.reloadN)
}
}
func TestHandlePluginByID_ReloadDeleteRejected(t *testing.T) {
// DELETE /plugins/reload 不允许把保留字当插件名反代成卸载
m := &mockPluginMgr{}
h := newHandlerWithMock(m)
req := httptest.NewRequest(http.MethodDelete, "/api/v1/plugins/reload", nil)
w := httptest.NewRecorder()
h.handlePluginByID(w, req)
if w.Code != http.StatusMethodNotAllowed {
t.Fatalf("expected 405, got %d", w.Code)
}
if len(m.removed) != 0 {
t.Fatalf("expected no plugin removed, got %v", m.removed)
}
}
func TestHandlePluginByID_PathTraversalRejected(t *testing.T) {
cases := []string{"../evil", "a/b", "a..b-ok-but-dots-only-check", "..%2Fetc"}
for _, name := range cases {
req := httptest.NewRequest(http.MethodDelete, "/api/v1/plugins/"+name, nil)
w := httptest.NewRecorder()
h := newHandlerWithMock(&mockPluginMgr{})
h.handlePluginByID(w, req)
// 含路径分隔符或以 .. 开头的名称必须被拒绝(400/405),绝不能反代到 pluginmgr
if w.Code != http.StatusBadRequest && w.Code != http.StatusMethodNotAllowed && w.Code != http.StatusNotFound {
t.Errorf("name %q: expected 4xx rejection, got %d", name, w.Code)
}
}
}
func TestHandlePluginByID_InvalidNamesRejected(t *testing.T) {
cases := []string{"has%20space", "has%3Acolon", "back%5Cslash"}
for _, name := range cases {
req := httptest.NewRequest(http.MethodGet, "/api/v1/plugins/"+name, nil)
w := httptest.NewRecorder()
h := newHandlerWithMock(&mockPluginMgr{})
h.handlePluginByID(w, req)
if w.Code != http.StatusBadRequest {
t.Errorf("name %q: expected 400, got %d", name, w.Code)
}
}
}
func TestHandlePluginByID_ValidNamePassesValidation(t *testing.T) {
// 合法插件名(含点/横线/下划线)不应被名称校验拦截;
// 这里 pluginmgr 未运行会得到 502 Bad Gateway,但绝不应该是 400。
m := &mockPluginMgr{}
h := newHandlerWithMock(m)
for _, name := range []string{"my-plugin", "plugin_v2", "weather.so"} {
req := httptest.NewRequest(http.MethodGet, "/api/v1/plugins/"+name, nil)
w := httptest.NewRecorder()
h.handlePluginByID(w, req)
if w.Code == http.StatusBadRequest {
t.Errorf("valid name %q should pass validation, got 400", name)
}
}
}
func TestHandlePluginByID_DisableEnable(t *testing.T) {
m := &mockPluginMgr{builtins: map[string]bool{"webui": true}}
h := newHandlerWithMock(m)
req := httptest.NewRequest(http.MethodPost, "/api/v1/plugins/webui/disable", nil)
w := httptest.NewRecorder()
h.handlePluginByID(w, req)
if w.Code != http.StatusOK {
t.Fatalf("disable: expected 200, got %d: %s", w.Code, w.Body.String())
}
if !m.isDisabled["webui"] {
t.Fatal("webui should be disabled in mock")
}
req = httptest.NewRequest(http.MethodPost, "/api/v1/plugins/webui/enable", nil)
w = httptest.NewRecorder()
h.handlePluginByID(w, req)
if w.Code != http.StatusOK {
t.Fatalf("enable: expected 200, got %d: %s", w.Code, w.Body.String())
}
if m.isDisabled["webui"] {
t.Fatal("webui should be re-enabled")
}
}