feat(tenancy): add Workspace multi-tenant foundation (#2353)

* Document multi-tenant workspace architecture

* Add OSS and commercial workspace boundaries

* docs: redesign multi-tenant workspace architecture

* feat(tenancy): implement workspace isolation

* docs(tenancy): record verification evidence

* docs(tenancy): revise single-instance SaaS topology

* docs(tenancy): refine architecture options

* docs: finalize cloud v2 multi-tenant decisions

* feat(tenancy): establish cloud isolation foundations

* feat(tenancy): harden shared cloud runtime boundaries

* docs(tenancy): record final isolation verification

* fix(tenancy): close isolation and permission gaps

* docs(tenancy): record final isolation verification

* feat(tenancy): connect cloud workspace control plane

* fix(build): install git for pinned SDK

* docs(cloud): update control plane verification

* chore: update multi-tenant SDK pin

* fix(cloud): skip legacy model sync during startup

* test(cloud): preserve minimal model manager fixtures

* fix(cloud): preserve authenticated account context

* fix(cloud): reuse authenticated account for user info

* feat(cloud): complete Workspace settings navigation

* test(web): cover Workspace dropdown menu

* feat(web): place workspace controls in sidebar

* refactor(web): streamline workspace controls

* style(web): format workspace layout test

* fix(cloud): surface runtime and workspace plan status

* fix(plugin): keep runtime identity stable across restarts

* fix(ui): widen and center workspace switcher

* fix(ui): hide roles from workspace switcher

* fix(ui): align workspace switcher with sidebar entries

* feat(workspace): add in-product collaboration and direct Cloud launch

* style: format collaboration changes

* fix(workspace): bind collaboration APIs to tenant UoW

* fix(cloud): preserve Core-owned collaboration state

* test(cloud): require Space identity for invite registration

* feat(cloud): complete secure invitation experience

* style(web): format invitation flows

* fix(cloud): recover box runtime without unscoped skill reload

* feat(oss): enforce invitation account and owner billing flows

* style: format OSS account service

* test(oss): cover invitation logout handoff

* fix(oss): resolve workspace owner in scoped session

* feat(cloud): harden multi-tenant runtime resources

* fix(cloud): bound runtime restart storms

* fix(cloud): eliminate periodic runtime CPU spikes

* fix(cloud): enforce instance capacity ceilings

* fix(cloud): scope public login capability discovery

* fix(cloud): bound tenant maintenance and monitoring work

* fix(runtime): bound tenant resource amplification

* fix(deps): pin green multi-tenant plugin SDK

* fix(cloud): handle unavailable skill capability

* fix(security): require authentication for image file endpoint (H-2)

- Changed /api/v1/files/image from AuthType.NONE to USER_TOKEN_OR_API_KEY
- Added Permission.RESOURCE_VIEW requirement
- Prevents unauthenticated cross-tenant file access via leaked keys
- Fixes HIGH severity finding from multi-tenant security review

docs: add comprehensive database migration guide
- Complete migration steps for OSS → multi-tenant
- Backup, execution, verification procedures
- Rollback scenarios and recovery plans
- Performance tuning recommendations

* test: add comprehensive cross-tenant isolation tests

Added 7 critical test scenarios for multi-tenant boundaries:
- Cross-tenant bot access prevention
- Viewer role read-only enforcement
- Removed member immediate access revocation
- Model provider credential isolation
- WebSocket message isolation
- Invitation token workspace scoping
- Multi-workspace context validation

These tests address P0-2 coverage gaps for:
- workspaces.py (membership & invitation flows)
- user.py (authentication & authorization)
- websocket_chat.py (real-time isolation)
- plugins.py (resource access control)

docs: finalize database migration guide

* fix(security): resolve M-1, M-2, M-3 security findings

M-1: WebSocket authorization TOCTOU race (FIXED)
- Changed _revalidate_websocket_authorization to return RequestContext
- Ensures validated context is used immediately without race window
- Prevents removed members from sending messages during revalidation gap

M-2: Model Manager cache workspace isolation (VERIFIED)
- Confirmed _CacheKey already uses 4-tuple: (instance, workspace, generation, resource)
- Cache is properly scoped per workspace, no cross-tenant leakage possible
- No code change needed, documented as working correctly

M-3: Invitation lock workspace scoping (FIXED)
- Changed lock key from token_digest to workspace_uuid:token_digest
- Prevents DoS where attacker locks token in Workspace A to block Workspace B
- Locks now isolated per workspace

All MEDIUM severity findings from security review now resolved.

* fix(cloud): unblock tenant CI and enforce knowledge quotas

* fix(tenancy): scope rerank model sync

---------

Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com>
This commit is contained in:
RockChinQ
2026-07-30 21:43:35 +08:00
committed by GitHub
parent 463b120923
commit e1ac5e0fc8
468 changed files with 78320 additions and 13137 deletions
+98
View File
@@ -0,0 +1,98 @@
from __future__ import annotations
import io
import zipfile
import yaml
_PLUGIN_ARCHIVE_MAX_ENTRIES = 512
_PLUGIN_ARCHIVE_MAX_ENTRY_BYTES = 16 * 1024 * 1024
_PLUGIN_ARCHIVE_MAX_TOTAL_BYTES = 64 * 1024 * 1024
_PLUGIN_ARCHIVE_MAX_COMPRESSION_RATIO = 100
_PLUGIN_METADATA_MAX_BYTES = 1024 * 1024
_PLUGIN_REQUIREMENTS_MAX_ENTRIES = 1000
def _read_plugin_archive_member(
archive: zipfile.ZipFile,
member: zipfile.ZipInfo,
*,
max_bytes: int = _PLUGIN_METADATA_MAX_BYTES,
) -> bytes:
if member.file_size > max_bytes:
raise ValueError(f'Plugin metadata file exceeds the {max_bytes}-byte limit: {member.filename}')
with archive.open(member, 'r') as source:
content = source.read(max_bytes + 1)
if len(content) > max_bytes or len(content) != member.file_size:
raise ValueError(f'Plugin metadata file has an invalid size: {member.filename}')
return content
def inspect_plugin_archive_metadata(
file_bytes: bytes,
*,
require_manifest: bool = True,
) -> tuple[dict, list[str], list[str]]:
"""Validate archive size metadata and read only bounded preview fields."""
with zipfile.ZipFile(io.BytesIO(file_bytes)) as archive:
members = archive.infolist()
if len(members) > _PLUGIN_ARCHIVE_MAX_ENTRIES:
raise ValueError('Plugin archive contains too many entries')
total_uncompressed = 0
files: dict[str, zipfile.ZipInfo] = {}
names: list[str] = []
for member in members:
if member.is_dir():
continue
if member.flag_bits & 0x1:
raise ValueError('Encrypted plugin archives are not supported')
if member.file_size > _PLUGIN_ARCHIVE_MAX_ENTRY_BYTES:
raise ValueError(f'Plugin archive entry exceeds the size limit: {member.filename}')
if (
member.file_size
and member.file_size > max(member.compress_size, 1) * _PLUGIN_ARCHIVE_MAX_COMPRESSION_RATIO
):
raise ValueError(f'Plugin archive entry exceeds the compression-ratio limit: {member.filename}')
total_uncompressed += member.file_size
if total_uncompressed > _PLUGIN_ARCHIVE_MAX_TOTAL_BYTES:
raise ValueError('Plugin archive exceeds the uncompressed size limit')
normalized = member.filename.replace('\\', '/').strip('/')
names.append(member.filename)
files.setdefault(normalized.lower(), member)
manifest_member = files.get('manifest.yaml') or files.get('manifest.yml')
if manifest_member is None:
if require_manifest:
raise ValueError('manifest.yaml is required')
manifest = {}
else:
manifest = yaml.safe_load(_read_plugin_archive_member(archive, manifest_member).decode('utf-8')) or {}
if not isinstance(manifest, dict):
raise ValueError('Plugin manifest must be an object')
requirements: list[str] = []
requirements_member = next(
(
member
for normalized, member in files.items()
if normalized == 'requirements.txt' or normalized.endswith('/requirements.txt')
),
None,
)
if requirements_member is not None:
content = _read_plugin_archive_member(
archive,
requirements_member,
).decode(
'utf-8',
errors='ignore',
)
requirements = [
line.strip()[:1000]
for line in content.splitlines()
if line.strip() and not line.strip().startswith('#')
][:_PLUGIN_REQUIREMENTS_MAX_ENTRIES]
return manifest, requirements, names
File diff suppressed because it is too large Load Diff
+97
View File
@@ -0,0 +1,97 @@
from __future__ import annotations
import re
from typing import Any
from urllib.parse import unquote, urlparse
_GITHUB_OWNER_PATTERN = re.compile(r'^[A-Za-z0-9](?:[A-Za-z0-9-]{0,38})$')
_GITHUB_REPO_PATTERN = re.compile(r'^[A-Za-z0-9._-]{1,100}$')
def _positive_github_id(value: object, field_name: str) -> int:
if isinstance(value, bool):
raise ValueError(f'{field_name} must be a positive GitHub identifier')
try:
identifier = int(value)
except (TypeError, ValueError) as exc:
raise ValueError(f'{field_name} must be a positive GitHub identifier') from exc
if identifier <= 0 or str(value).strip() != str(identifier):
raise ValueError(f'{field_name} must be a positive GitHub identifier')
return identifier
def validate_github_release_asset_url(
asset_url: object,
*,
owner: str,
repo: str,
release_tag: str,
) -> str:
"""Accept only a GitHub browser release URL tied to the requested release."""
normalized_url = str(asset_url or '').strip()
parsed = urlparse(normalized_url)
try:
port = parsed.port
except ValueError as exc:
raise ValueError('asset_url has an invalid port') from exc
if (
parsed.scheme != 'https'
or (parsed.hostname or '').lower() != 'github.com'
or parsed.username is not None
or parsed.password is not None
or port not in {None, 443}
or parsed.fragment
):
raise ValueError('asset_url must be an HTTPS GitHub release asset URL')
decoded_path = unquote(parsed.path)
expected_prefix = f'/{owner}/{repo}/releases/download/{release_tag}/'
if not decoded_path.casefold().startswith(
f'/{owner}/{repo}/releases/download/'.casefold()
) or not decoded_path.startswith(expected_prefix):
raise ValueError('asset_url does not match the requested GitHub release')
if decoded_path == expected_prefix or decoded_path.endswith('/'):
raise ValueError('asset_url must identify a GitHub release asset')
return normalized_url
def validate_github_plugin_install_info(install_info: dict[str, Any]) -> dict[str, Any]:
"""Normalize a GitHub install request without trusting a tenant-provided URL."""
owner = str(install_info.get('owner') or '').strip()
repo = str(install_info.get('repo') or '').strip()
release_tag = str(install_info.get('release_tag') or '').strip()
if _GITHUB_OWNER_PATTERN.fullmatch(owner) is None:
raise ValueError('owner must be a valid GitHub repository owner')
if _GITHUB_REPO_PATTERN.fullmatch(repo) is None:
raise ValueError('repo must be a valid GitHub repository name')
if not release_tag or '\x00' in release_tag or len(release_tag) > 255:
raise ValueError('release_tag must identify a GitHub release')
release_id_value = install_info.get('release_id')
asset_id_value = install_info.get('asset_id')
normalized = dict(install_info)
normalized.update(
{
'owner': owner,
'repo': repo,
'release_tag': release_tag,
'github_url': f'https://github.com/{owner}/{repo}',
}
)
if release_id_value is not None or asset_id_value is not None:
if release_id_value is None or asset_id_value is None:
raise ValueError('release_id and asset_id must be provided together')
normalized['release_id'] = _positive_github_id(release_id_value, 'release_id')
normalized['asset_id'] = _positive_github_id(asset_id_value, 'asset_id')
normalized.pop('asset_url', None)
return normalized
normalized['asset_url'] = validate_github_release_asset_url(
install_info.get('asset_url'),
owner=owner,
repo=repo,
release_tag=release_tag,
)
return normalized
File diff suppressed because it is too large Load Diff