mirror of
https://github.com/langbot-app/LangBot.git
synced 2026-08-22 18:27:12 +00:00
feat(tenancy): add Workspace multi-tenant foundation (#2353)
* Document multi-tenant workspace architecture * Add OSS and commercial workspace boundaries * docs: redesign multi-tenant workspace architecture * feat(tenancy): implement workspace isolation * docs(tenancy): record verification evidence * docs(tenancy): revise single-instance SaaS topology * docs(tenancy): refine architecture options * docs: finalize cloud v2 multi-tenant decisions * feat(tenancy): establish cloud isolation foundations * feat(tenancy): harden shared cloud runtime boundaries * docs(tenancy): record final isolation verification * fix(tenancy): close isolation and permission gaps * docs(tenancy): record final isolation verification * feat(tenancy): connect cloud workspace control plane * fix(build): install git for pinned SDK * docs(cloud): update control plane verification * chore: update multi-tenant SDK pin * fix(cloud): skip legacy model sync during startup * test(cloud): preserve minimal model manager fixtures * fix(cloud): preserve authenticated account context * fix(cloud): reuse authenticated account for user info * feat(cloud): complete Workspace settings navigation * test(web): cover Workspace dropdown menu * feat(web): place workspace controls in sidebar * refactor(web): streamline workspace controls * style(web): format workspace layout test * fix(cloud): surface runtime and workspace plan status * fix(plugin): keep runtime identity stable across restarts * fix(ui): widen and center workspace switcher * fix(ui): hide roles from workspace switcher * fix(ui): align workspace switcher with sidebar entries * feat(workspace): add in-product collaboration and direct Cloud launch * style: format collaboration changes * fix(workspace): bind collaboration APIs to tenant UoW * fix(cloud): preserve Core-owned collaboration state * test(cloud): require Space identity for invite registration * feat(cloud): complete secure invitation experience * style(web): format invitation flows * fix(cloud): recover box runtime without unscoped skill reload * feat(oss): enforce invitation account and owner billing flows * style: format OSS account service * test(oss): cover invitation logout handoff * fix(oss): resolve workspace owner in scoped session * feat(cloud): harden multi-tenant runtime resources * fix(cloud): bound runtime restart storms * fix(cloud): eliminate periodic runtime CPU spikes * fix(cloud): enforce instance capacity ceilings * fix(cloud): scope public login capability discovery * fix(cloud): bound tenant maintenance and monitoring work * fix(runtime): bound tenant resource amplification * fix(deps): pin green multi-tenant plugin SDK * fix(cloud): handle unavailable skill capability * fix(security): require authentication for image file endpoint (H-2) - Changed /api/v1/files/image from AuthType.NONE to USER_TOKEN_OR_API_KEY - Added Permission.RESOURCE_VIEW requirement - Prevents unauthenticated cross-tenant file access via leaked keys - Fixes HIGH severity finding from multi-tenant security review docs: add comprehensive database migration guide - Complete migration steps for OSS → multi-tenant - Backup, execution, verification procedures - Rollback scenarios and recovery plans - Performance tuning recommendations * test: add comprehensive cross-tenant isolation tests Added 7 critical test scenarios for multi-tenant boundaries: - Cross-tenant bot access prevention - Viewer role read-only enforcement - Removed member immediate access revocation - Model provider credential isolation - WebSocket message isolation - Invitation token workspace scoping - Multi-workspace context validation These tests address P0-2 coverage gaps for: - workspaces.py (membership & invitation flows) - user.py (authentication & authorization) - websocket_chat.py (real-time isolation) - plugins.py (resource access control) docs: finalize database migration guide * fix(security): resolve M-1, M-2, M-3 security findings M-1: WebSocket authorization TOCTOU race (FIXED) - Changed _revalidate_websocket_authorization to return RequestContext - Ensures validated context is used immediately without race window - Prevents removed members from sending messages during revalidation gap M-2: Model Manager cache workspace isolation (VERIFIED) - Confirmed _CacheKey already uses 4-tuple: (instance, workspace, generation, resource) - Cache is properly scoped per workspace, no cross-tenant leakage possible - No code change needed, documented as working correctly M-3: Invitation lock workspace scoping (FIXED) - Changed lock key from token_digest to workspace_uuid:token_digest - Prevents DoS where attacker locks token in Workspace A to block Workspace B - Locks now isolated per workspace All MEDIUM severity findings from security review now resolved. * fix(cloud): unblock tenant CI and enforce knowledge quotas * fix(tenancy): scope rerank model sync --------- Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com>
This commit is contained in:
@@ -0,0 +1,98 @@
|
||||
from __future__ import annotations
|
||||
|
||||
import io
|
||||
import zipfile
|
||||
|
||||
import yaml
|
||||
|
||||
|
||||
_PLUGIN_ARCHIVE_MAX_ENTRIES = 512
|
||||
_PLUGIN_ARCHIVE_MAX_ENTRY_BYTES = 16 * 1024 * 1024
|
||||
_PLUGIN_ARCHIVE_MAX_TOTAL_BYTES = 64 * 1024 * 1024
|
||||
_PLUGIN_ARCHIVE_MAX_COMPRESSION_RATIO = 100
|
||||
_PLUGIN_METADATA_MAX_BYTES = 1024 * 1024
|
||||
_PLUGIN_REQUIREMENTS_MAX_ENTRIES = 1000
|
||||
|
||||
|
||||
def _read_plugin_archive_member(
|
||||
archive: zipfile.ZipFile,
|
||||
member: zipfile.ZipInfo,
|
||||
*,
|
||||
max_bytes: int = _PLUGIN_METADATA_MAX_BYTES,
|
||||
) -> bytes:
|
||||
if member.file_size > max_bytes:
|
||||
raise ValueError(f'Plugin metadata file exceeds the {max_bytes}-byte limit: {member.filename}')
|
||||
with archive.open(member, 'r') as source:
|
||||
content = source.read(max_bytes + 1)
|
||||
if len(content) > max_bytes or len(content) != member.file_size:
|
||||
raise ValueError(f'Plugin metadata file has an invalid size: {member.filename}')
|
||||
return content
|
||||
|
||||
|
||||
def inspect_plugin_archive_metadata(
|
||||
file_bytes: bytes,
|
||||
*,
|
||||
require_manifest: bool = True,
|
||||
) -> tuple[dict, list[str], list[str]]:
|
||||
"""Validate archive size metadata and read only bounded preview fields."""
|
||||
|
||||
with zipfile.ZipFile(io.BytesIO(file_bytes)) as archive:
|
||||
members = archive.infolist()
|
||||
if len(members) > _PLUGIN_ARCHIVE_MAX_ENTRIES:
|
||||
raise ValueError('Plugin archive contains too many entries')
|
||||
|
||||
total_uncompressed = 0
|
||||
files: dict[str, zipfile.ZipInfo] = {}
|
||||
names: list[str] = []
|
||||
for member in members:
|
||||
if member.is_dir():
|
||||
continue
|
||||
if member.flag_bits & 0x1:
|
||||
raise ValueError('Encrypted plugin archives are not supported')
|
||||
if member.file_size > _PLUGIN_ARCHIVE_MAX_ENTRY_BYTES:
|
||||
raise ValueError(f'Plugin archive entry exceeds the size limit: {member.filename}')
|
||||
if (
|
||||
member.file_size
|
||||
and member.file_size > max(member.compress_size, 1) * _PLUGIN_ARCHIVE_MAX_COMPRESSION_RATIO
|
||||
):
|
||||
raise ValueError(f'Plugin archive entry exceeds the compression-ratio limit: {member.filename}')
|
||||
total_uncompressed += member.file_size
|
||||
if total_uncompressed > _PLUGIN_ARCHIVE_MAX_TOTAL_BYTES:
|
||||
raise ValueError('Plugin archive exceeds the uncompressed size limit')
|
||||
normalized = member.filename.replace('\\', '/').strip('/')
|
||||
names.append(member.filename)
|
||||
files.setdefault(normalized.lower(), member)
|
||||
|
||||
manifest_member = files.get('manifest.yaml') or files.get('manifest.yml')
|
||||
if manifest_member is None:
|
||||
if require_manifest:
|
||||
raise ValueError('manifest.yaml is required')
|
||||
manifest = {}
|
||||
else:
|
||||
manifest = yaml.safe_load(_read_plugin_archive_member(archive, manifest_member).decode('utf-8')) or {}
|
||||
if not isinstance(manifest, dict):
|
||||
raise ValueError('Plugin manifest must be an object')
|
||||
|
||||
requirements: list[str] = []
|
||||
requirements_member = next(
|
||||
(
|
||||
member
|
||||
for normalized, member in files.items()
|
||||
if normalized == 'requirements.txt' or normalized.endswith('/requirements.txt')
|
||||
),
|
||||
None,
|
||||
)
|
||||
if requirements_member is not None:
|
||||
content = _read_plugin_archive_member(
|
||||
archive,
|
||||
requirements_member,
|
||||
).decode(
|
||||
'utf-8',
|
||||
errors='ignore',
|
||||
)
|
||||
requirements = [
|
||||
line.strip()[:1000]
|
||||
for line in content.splitlines()
|
||||
if line.strip() and not line.strip().startswith('#')
|
||||
][:_PLUGIN_REQUIREMENTS_MAX_ENTRIES]
|
||||
return manifest, requirements, names
|
||||
+1599
-354
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,97 @@
|
||||
from __future__ import annotations
|
||||
|
||||
import re
|
||||
from typing import Any
|
||||
from urllib.parse import unquote, urlparse
|
||||
|
||||
|
||||
_GITHUB_OWNER_PATTERN = re.compile(r'^[A-Za-z0-9](?:[A-Za-z0-9-]{0,38})$')
|
||||
_GITHUB_REPO_PATTERN = re.compile(r'^[A-Za-z0-9._-]{1,100}$')
|
||||
|
||||
|
||||
def _positive_github_id(value: object, field_name: str) -> int:
|
||||
if isinstance(value, bool):
|
||||
raise ValueError(f'{field_name} must be a positive GitHub identifier')
|
||||
try:
|
||||
identifier = int(value)
|
||||
except (TypeError, ValueError) as exc:
|
||||
raise ValueError(f'{field_name} must be a positive GitHub identifier') from exc
|
||||
if identifier <= 0 or str(value).strip() != str(identifier):
|
||||
raise ValueError(f'{field_name} must be a positive GitHub identifier')
|
||||
return identifier
|
||||
|
||||
|
||||
def validate_github_release_asset_url(
|
||||
asset_url: object,
|
||||
*,
|
||||
owner: str,
|
||||
repo: str,
|
||||
release_tag: str,
|
||||
) -> str:
|
||||
"""Accept only a GitHub browser release URL tied to the requested release."""
|
||||
|
||||
normalized_url = str(asset_url or '').strip()
|
||||
parsed = urlparse(normalized_url)
|
||||
try:
|
||||
port = parsed.port
|
||||
except ValueError as exc:
|
||||
raise ValueError('asset_url has an invalid port') from exc
|
||||
if (
|
||||
parsed.scheme != 'https'
|
||||
or (parsed.hostname or '').lower() != 'github.com'
|
||||
or parsed.username is not None
|
||||
or parsed.password is not None
|
||||
or port not in {None, 443}
|
||||
or parsed.fragment
|
||||
):
|
||||
raise ValueError('asset_url must be an HTTPS GitHub release asset URL')
|
||||
decoded_path = unquote(parsed.path)
|
||||
expected_prefix = f'/{owner}/{repo}/releases/download/{release_tag}/'
|
||||
if not decoded_path.casefold().startswith(
|
||||
f'/{owner}/{repo}/releases/download/'.casefold()
|
||||
) or not decoded_path.startswith(expected_prefix):
|
||||
raise ValueError('asset_url does not match the requested GitHub release')
|
||||
if decoded_path == expected_prefix or decoded_path.endswith('/'):
|
||||
raise ValueError('asset_url must identify a GitHub release asset')
|
||||
return normalized_url
|
||||
|
||||
|
||||
def validate_github_plugin_install_info(install_info: dict[str, Any]) -> dict[str, Any]:
|
||||
"""Normalize a GitHub install request without trusting a tenant-provided URL."""
|
||||
|
||||
owner = str(install_info.get('owner') or '').strip()
|
||||
repo = str(install_info.get('repo') or '').strip()
|
||||
release_tag = str(install_info.get('release_tag') or '').strip()
|
||||
if _GITHUB_OWNER_PATTERN.fullmatch(owner) is None:
|
||||
raise ValueError('owner must be a valid GitHub repository owner')
|
||||
if _GITHUB_REPO_PATTERN.fullmatch(repo) is None:
|
||||
raise ValueError('repo must be a valid GitHub repository name')
|
||||
if not release_tag or '\x00' in release_tag or len(release_tag) > 255:
|
||||
raise ValueError('release_tag must identify a GitHub release')
|
||||
|
||||
release_id_value = install_info.get('release_id')
|
||||
asset_id_value = install_info.get('asset_id')
|
||||
normalized = dict(install_info)
|
||||
normalized.update(
|
||||
{
|
||||
'owner': owner,
|
||||
'repo': repo,
|
||||
'release_tag': release_tag,
|
||||
'github_url': f'https://github.com/{owner}/{repo}',
|
||||
}
|
||||
)
|
||||
if release_id_value is not None or asset_id_value is not None:
|
||||
if release_id_value is None or asset_id_value is None:
|
||||
raise ValueError('release_id and asset_id must be provided together')
|
||||
normalized['release_id'] = _positive_github_id(release_id_value, 'release_id')
|
||||
normalized['asset_id'] = _positive_github_id(asset_id_value, 'asset_id')
|
||||
normalized.pop('asset_url', None)
|
||||
return normalized
|
||||
|
||||
normalized['asset_url'] = validate_github_release_asset_url(
|
||||
install_info.get('asset_url'),
|
||||
owner=owner,
|
||||
repo=repo,
|
||||
release_tag=release_tag,
|
||||
)
|
||||
return normalized
|
||||
+941
-144
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user