mirror of
https://github.com/langbot-app/LangBot.git
synced 2026-06-02 12:05:54 +00:00
Compare commits
1 Commits
fix/rag-ru
...
fix/plugin
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
779cf9899f |
@@ -35,6 +35,10 @@ from ..core import taskmgr
|
||||
from ..entity.persistence import plugin as persistence_plugin
|
||||
|
||||
|
||||
class PluginRuntimeNotConnectedError(RuntimeError):
|
||||
"""Raised when plugin runtime operations are requested before connection."""
|
||||
|
||||
|
||||
class PluginRuntimeConnector:
|
||||
"""Plugin runtime connector"""
|
||||
|
||||
@@ -192,7 +196,7 @@ class PluginRuntimeConnector:
|
||||
|
||||
async def ping_plugin_runtime(self):
|
||||
if not hasattr(self, 'handler'):
|
||||
raise Exception('Plugin runtime is not connected')
|
||||
raise PluginRuntimeNotConnectedError('Plugin runtime is not connected')
|
||||
|
||||
return await self.handler.ping()
|
||||
|
||||
|
||||
@@ -1,12 +1,8 @@
|
||||
from __future__ import annotations
|
||||
|
||||
import posixpath
|
||||
import re
|
||||
from typing import TYPE_CHECKING, Any
|
||||
from urllib.parse import unquote
|
||||
|
||||
if TYPE_CHECKING:
|
||||
from langbot.pkg.core import app
|
||||
from typing import Any
|
||||
from langbot.pkg.core import app
|
||||
|
||||
|
||||
class RAGRuntimeService:
|
||||
@@ -113,17 +109,8 @@ class RAGRuntimeService:
|
||||
regardless of the underlying storage provider.
|
||||
"""
|
||||
# Validate storage_path to prevent path traversal
|
||||
decoded_path = unquote(storage_path).replace('\\', '/')
|
||||
decoded_segments = decoded_path.split('/')
|
||||
normalized = posixpath.normpath(decoded_path)
|
||||
if (
|
||||
not storage_path
|
||||
or '\x00' in decoded_path
|
||||
or normalized.startswith('/')
|
||||
or '..' in decoded_segments
|
||||
or '..' in normalized.split('/')
|
||||
or re.match(r'^[A-Za-z]:/', normalized)
|
||||
):
|
||||
normalized = posixpath.normpath(storage_path)
|
||||
if normalized.startswith('/') or '..' in normalized.split('/'):
|
||||
raise ValueError('Invalid storage path')
|
||||
content_bytes = await self.ap.storage_mgr.storage_provider.load(normalized)
|
||||
return content_bytes if content_bytes else b''
|
||||
|
||||
32
tests/unit_tests/plugin/test_connector_ping.py
Normal file
32
tests/unit_tests/plugin/test_connector_ping.py
Normal file
@@ -0,0 +1,32 @@
|
||||
from __future__ import annotations
|
||||
|
||||
from types import SimpleNamespace
|
||||
from unittest.mock import AsyncMock
|
||||
|
||||
import pytest
|
||||
|
||||
from langbot.pkg.plugin.connector import PluginRuntimeConnector, PluginRuntimeNotConnectedError
|
||||
|
||||
|
||||
def make_connector() -> PluginRuntimeConnector:
|
||||
app = SimpleNamespace(instance_config=SimpleNamespace(data={'plugin': {'enable': True}}))
|
||||
return PluginRuntimeConnector(app, AsyncMock())
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_ping_plugin_runtime_raises_specific_error_when_not_connected():
|
||||
connector = make_connector()
|
||||
|
||||
with pytest.raises(PluginRuntimeNotConnectedError, match='Plugin runtime is not connected'):
|
||||
await connector.ping_plugin_runtime()
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_ping_plugin_runtime_delegates_to_connected_handler():
|
||||
connector = make_connector()
|
||||
connector.handler = SimpleNamespace(ping=AsyncMock(return_value='pong'))
|
||||
|
||||
result = await connector.ping_plugin_runtime()
|
||||
|
||||
assert result == 'pong'
|
||||
connector.handler.ping.assert_awaited_once()
|
||||
@@ -1,68 +0,0 @@
|
||||
from __future__ import annotations
|
||||
|
||||
from types import SimpleNamespace
|
||||
|
||||
import pytest
|
||||
|
||||
from langbot.pkg.rag.service.runtime import RAGRuntimeService
|
||||
|
||||
|
||||
class DummyStorageProvider:
|
||||
def __init__(self, content: bytes | None = b'data'):
|
||||
self.content = content
|
||||
self.loaded_paths: list[str] = []
|
||||
|
||||
async def load(self, path: str):
|
||||
self.loaded_paths.append(path)
|
||||
return self.content
|
||||
|
||||
|
||||
def make_service(storage_provider: DummyStorageProvider) -> RAGRuntimeService:
|
||||
return RAGRuntimeService(SimpleNamespace(storage_mgr=SimpleNamespace(storage_provider=storage_provider)))
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_get_file_stream_normalizes_safe_path():
|
||||
storage_provider = DummyStorageProvider()
|
||||
service = make_service(storage_provider)
|
||||
|
||||
content = await service.get_file_stream('safe/./nested/file.pdf')
|
||||
|
||||
assert content == b'data'
|
||||
assert storage_provider.loaded_paths == ['safe/nested/file.pdf']
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
@pytest.mark.parametrize(
|
||||
'storage_path',
|
||||
[
|
||||
'',
|
||||
'../secret.txt',
|
||||
'/absolute/path.txt',
|
||||
'..\\secret.txt',
|
||||
'nested\\..\\secret.txt',
|
||||
'%2e%2e/secret.txt',
|
||||
'nested/%2e%2e/secret.txt',
|
||||
'C:\\secret.txt',
|
||||
'safe/\x00file.txt',
|
||||
],
|
||||
)
|
||||
async def test_get_file_stream_rejects_unsafe_paths(storage_path: str):
|
||||
storage_provider = DummyStorageProvider()
|
||||
service = make_service(storage_provider)
|
||||
|
||||
with pytest.raises(ValueError, match='Invalid storage path'):
|
||||
await service.get_file_stream(storage_path)
|
||||
|
||||
assert storage_provider.loaded_paths == []
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_get_file_stream_returns_empty_bytes_for_missing_content():
|
||||
storage_provider = DummyStorageProvider(content=None)
|
||||
service = make_service(storage_provider)
|
||||
|
||||
content = await service.get_file_stream('safe/file.pdf')
|
||||
|
||||
assert content == b''
|
||||
assert storage_provider.loaded_paths == ['safe/file.pdf']
|
||||
Reference in New Issue
Block a user