mirror of
https://github.com/langbot-app/LangBot.git
synced 2026-08-26 20:27:13 +00:00
e1ac5e0fc8
* Document multi-tenant workspace architecture * Add OSS and commercial workspace boundaries * docs: redesign multi-tenant workspace architecture * feat(tenancy): implement workspace isolation * docs(tenancy): record verification evidence * docs(tenancy): revise single-instance SaaS topology * docs(tenancy): refine architecture options * docs: finalize cloud v2 multi-tenant decisions * feat(tenancy): establish cloud isolation foundations * feat(tenancy): harden shared cloud runtime boundaries * docs(tenancy): record final isolation verification * fix(tenancy): close isolation and permission gaps * docs(tenancy): record final isolation verification * feat(tenancy): connect cloud workspace control plane * fix(build): install git for pinned SDK * docs(cloud): update control plane verification * chore: update multi-tenant SDK pin * fix(cloud): skip legacy model sync during startup * test(cloud): preserve minimal model manager fixtures * fix(cloud): preserve authenticated account context * fix(cloud): reuse authenticated account for user info * feat(cloud): complete Workspace settings navigation * test(web): cover Workspace dropdown menu * feat(web): place workspace controls in sidebar * refactor(web): streamline workspace controls * style(web): format workspace layout test * fix(cloud): surface runtime and workspace plan status * fix(plugin): keep runtime identity stable across restarts * fix(ui): widen and center workspace switcher * fix(ui): hide roles from workspace switcher * fix(ui): align workspace switcher with sidebar entries * feat(workspace): add in-product collaboration and direct Cloud launch * style: format collaboration changes * fix(workspace): bind collaboration APIs to tenant UoW * fix(cloud): preserve Core-owned collaboration state * test(cloud): require Space identity for invite registration * feat(cloud): complete secure invitation experience * style(web): format invitation flows * fix(cloud): recover box runtime without unscoped skill reload * feat(oss): enforce invitation account and owner billing flows * style: format OSS account service * test(oss): cover invitation logout handoff * fix(oss): resolve workspace owner in scoped session * feat(cloud): harden multi-tenant runtime resources * fix(cloud): bound runtime restart storms * fix(cloud): eliminate periodic runtime CPU spikes * fix(cloud): enforce instance capacity ceilings * fix(cloud): scope public login capability discovery * fix(cloud): bound tenant maintenance and monitoring work * fix(runtime): bound tenant resource amplification * fix(deps): pin green multi-tenant plugin SDK * fix(cloud): handle unavailable skill capability * fix(security): require authentication for image file endpoint (H-2) - Changed /api/v1/files/image from AuthType.NONE to USER_TOKEN_OR_API_KEY - Added Permission.RESOURCE_VIEW requirement - Prevents unauthenticated cross-tenant file access via leaked keys - Fixes HIGH severity finding from multi-tenant security review docs: add comprehensive database migration guide - Complete migration steps for OSS → multi-tenant - Backup, execution, verification procedures - Rollback scenarios and recovery plans - Performance tuning recommendations * test: add comprehensive cross-tenant isolation tests Added 7 critical test scenarios for multi-tenant boundaries: - Cross-tenant bot access prevention - Viewer role read-only enforcement - Removed member immediate access revocation - Model provider credential isolation - WebSocket message isolation - Invitation token workspace scoping - Multi-workspace context validation These tests address P0-2 coverage gaps for: - workspaces.py (membership & invitation flows) - user.py (authentication & authorization) - websocket_chat.py (real-time isolation) - plugins.py (resource access control) docs: finalize database migration guide * fix(security): resolve M-1, M-2, M-3 security findings M-1: WebSocket authorization TOCTOU race (FIXED) - Changed _revalidate_websocket_authorization to return RequestContext - Ensures validated context is used immediately without race window - Prevents removed members from sending messages during revalidation gap M-2: Model Manager cache workspace isolation (VERIFIED) - Confirmed _CacheKey already uses 4-tuple: (instance, workspace, generation, resource) - Cache is properly scoped per workspace, no cross-tenant leakage possible - No code change needed, documented as working correctly M-3: Invitation lock workspace scoping (FIXED) - Changed lock key from token_digest to workspace_uuid:token_digest - Prevents DoS where attacker locks token in Workspace A to block Workspace B - Locks now isolated per workspace All MEDIUM severity findings from security review now resolved. * fix(cloud): unblock tenant CI and enforce knowledge quotas * fix(tenancy): scope rerank model sync --------- Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com>
286 lines
11 KiB
Python
286 lines
11 KiB
Python
import typing
|
||
import quart
|
||
|
||
|
||
import traceback
|
||
import asyncio
|
||
import base64
|
||
import datetime
|
||
|
||
|
||
import langbot_plugin.api.definition.abstract.platform.adapter as abstract_platform_adapter
|
||
import langbot_plugin.api.entities.builtin.platform.message as platform_message
|
||
import langbot_plugin.api.entities.builtin.platform.events as platform_events
|
||
import langbot_plugin.api.entities.builtin.platform.entities as platform_entities
|
||
from ..logger import EventLogger
|
||
from ...utils import bounded_executor
|
||
|
||
|
||
from linebot.v3 import WebhookHandler
|
||
from linebot.v3.exceptions import InvalidSignatureError
|
||
from linebot.v3.messaging import Configuration, ApiClient, MessagingApi, ReplyMessageRequest, TextMessage, ImageMessage
|
||
from linebot.v3.webhooks import (
|
||
MessageEvent,
|
||
TextMessageContent,
|
||
ImageMessageContent,
|
||
VideoMessageContent,
|
||
AudioMessageContent,
|
||
)
|
||
|
||
# from linebot import WebhookParser
|
||
from linebot.v3.webhook import WebhookParser
|
||
from linebot.v3.messaging import MessagingApiBlob
|
||
|
||
MAX_LINE_MEDIA_BYTES = 10 * 1024 * 1024
|
||
|
||
|
||
def _validate_line_media_content(content: bytes) -> bytes:
|
||
if len(content) > MAX_LINE_MEDIA_BYTES:
|
||
raise ValueError(f'LINE media exceeds the {MAX_LINE_MEDIA_BYTES}-byte limit')
|
||
return content
|
||
|
||
|
||
class LINEMessageConverter(abstract_platform_adapter.AbstractMessageConverter):
|
||
@staticmethod
|
||
async def yiri2target(message_chain: platform_message.MessageChain, api_client: ApiClient) -> typing.Tuple[list]:
|
||
content_list = []
|
||
for component in message_chain:
|
||
if isinstance(component, platform_message.At):
|
||
content_list.append({'type': 'at', 'target': component.target})
|
||
elif isinstance(component, platform_message.Plain):
|
||
content_list.append({'type': 'text', 'content': component.text})
|
||
elif isinstance(component, platform_message.Image):
|
||
# Only add image if it has a valid URL
|
||
if component.url:
|
||
content_list.append({'type': 'image', 'image': component.url})
|
||
elif isinstance(component, platform_message.Voice):
|
||
content_list.append({'type': 'voice', 'url': component.url, 'length': component.length})
|
||
|
||
return content_list
|
||
|
||
@staticmethod
|
||
async def target2yiri(message, bot_client) -> platform_message.MessageChain:
|
||
lb_msg_list = []
|
||
msg_create_time = datetime.datetime.fromtimestamp(int(message.timestamp) / 1000)
|
||
|
||
lb_msg_list.append(platform_message.Source(id=message.webhook_event_id, time=msg_create_time))
|
||
|
||
if isinstance(message.message, TextMessageContent):
|
||
lb_msg_list.append(platform_message.Plain(text=message.message.text))
|
||
elif isinstance(message.message, AudioMessageContent):
|
||
pass
|
||
elif isinstance(message.message, VideoMessageContent):
|
||
pass
|
||
elif isinstance(message.message, ImageMessageContent):
|
||
message_content = await asyncio.to_thread(
|
||
MessagingApiBlob(bot_client).get_message_content,
|
||
message.message.id,
|
||
)
|
||
_validate_line_media_content(message_content)
|
||
|
||
base64_string = await asyncio.to_thread(lambda: base64.b64encode(message_content).decode('utf-8'))
|
||
|
||
# 如果需要Data URI格式(用于直接嵌入HTML等)
|
||
# 首先需要知道图片类型,LINE图片通常是JPEG
|
||
data_uri = f'data:image/jpeg;base64,{base64_string}'
|
||
lb_msg_list.append(platform_message.Image(base64=data_uri))
|
||
return platform_message.MessageChain(lb_msg_list)
|
||
|
||
|
||
class LINEEventConverter(abstract_platform_adapter.AbstractEventConverter):
|
||
@staticmethod
|
||
async def yiri2target(
|
||
event: platform_events.MessageEvent,
|
||
) -> MessageEvent:
|
||
pass
|
||
|
||
@staticmethod
|
||
async def target2yiri(event, bot_client) -> platform_events.Event:
|
||
message_chain = await LINEMessageConverter.target2yiri(event, bot_client)
|
||
|
||
if event.source.type == 'user':
|
||
return platform_events.FriendMessage(
|
||
sender=platform_entities.Friend(
|
||
id=event.message.id,
|
||
nickname=event.source.user_id,
|
||
remark='',
|
||
),
|
||
message_chain=message_chain,
|
||
time=event.timestamp,
|
||
source_platform_object=event,
|
||
)
|
||
else:
|
||
return platform_events.GroupMessage(
|
||
sender=platform_entities.GroupMember(
|
||
id=event.event.sender.sender_id.open_id,
|
||
member_name=event.event.sender.sender_id.union_id,
|
||
permission=platform_entities.Permission.Member,
|
||
group=platform_entities.Group(
|
||
id=event.message.id,
|
||
name='',
|
||
permission=platform_entities.Permission.Member,
|
||
),
|
||
special_title='',
|
||
),
|
||
message_chain=message_chain,
|
||
time=event.timestamp,
|
||
source_platform_object=event,
|
||
)
|
||
|
||
|
||
class LINEAdapter(abstract_platform_adapter.AbstractMessagePlatformAdapter):
|
||
bot: MessagingApi
|
||
api_client: ApiClient
|
||
parser: WebhookParser
|
||
|
||
bot_account_id: str # 用于在流水线中识别at是否是本bot,直接以bot_name作为标识
|
||
message_converter: LINEMessageConverter
|
||
event_converter: LINEEventConverter
|
||
|
||
listeners: typing.Dict[
|
||
typing.Type[platform_events.Event],
|
||
typing.Callable[[platform_events.Event, abstract_platform_adapter.AbstractMessagePlatformAdapter], None],
|
||
]
|
||
|
||
config: dict
|
||
bot_uuid: str = None
|
||
|
||
card_id_dict: dict[str, str] # 消息id到卡片id的映射,便于创建卡片后的发送消息到指定卡片
|
||
|
||
seq: int # 用于在发送卡片消息中识别消息顺序,直接以seq作为标识
|
||
|
||
def __init__(self, config: dict, logger: EventLogger):
|
||
configuration = Configuration(access_token=config['channel_access_token'])
|
||
line_webhook = WebhookHandler(config['channel_secret'])
|
||
parser = WebhookParser(config['channel_secret'])
|
||
api_client = ApiClient(configuration)
|
||
|
||
bot_account_id = config.get('bot_account_id', 'langbot')
|
||
|
||
super().__init__(
|
||
config=config,
|
||
logger=logger,
|
||
listeners={},
|
||
card_id_dict={},
|
||
seq=1,
|
||
event_converter=LINEEventConverter(),
|
||
message_converter=LINEMessageConverter(),
|
||
line_webhook=line_webhook,
|
||
parser=parser,
|
||
configuration=configuration,
|
||
api_client=api_client,
|
||
bot=MessagingApi(api_client),
|
||
bot_account_id=bot_account_id,
|
||
)
|
||
|
||
async def send_message(self, target_type: str, target_id: str, message: platform_message.MessageChain):
|
||
pass
|
||
|
||
async def reply_message(
|
||
self,
|
||
message_source: platform_events.MessageEvent,
|
||
message: platform_message.MessageChain,
|
||
quote_origin: bool = False,
|
||
):
|
||
content_list = await self.message_converter.yiri2target(message, self.api_client)
|
||
|
||
for content in content_list:
|
||
if content['type'] == 'text':
|
||
await asyncio.to_thread(
|
||
self.bot.reply_message_with_http_info,
|
||
ReplyMessageRequest(
|
||
reply_token=message_source.source_platform_object.reply_token,
|
||
messages=[TextMessage(text=content['content'])],
|
||
),
|
||
)
|
||
elif content['type'] == 'image':
|
||
# LINE ImageMessage requires original_content_url and preview_image_url
|
||
image_url = content['image']
|
||
await asyncio.to_thread(
|
||
self.bot.reply_message_with_http_info,
|
||
ReplyMessageRequest(
|
||
reply_token=message_source.source_platform_object.reply_token,
|
||
messages=[ImageMessage(original_content_url=image_url, preview_image_url=image_url)],
|
||
),
|
||
)
|
||
|
||
async def is_muted(self, group_id: int) -> bool:
|
||
return False
|
||
|
||
def register_listener(
|
||
self,
|
||
event_type: typing.Type[platform_events.Event],
|
||
callback: typing.Callable[
|
||
[platform_events.Event, abstract_platform_adapter.AbstractMessagePlatformAdapter], None
|
||
],
|
||
):
|
||
self.listeners[event_type] = callback
|
||
|
||
def unregister_listener(
|
||
self,
|
||
event_type: typing.Type[platform_events.Event],
|
||
callback: typing.Callable[
|
||
[platform_events.Event, abstract_platform_adapter.AbstractMessagePlatformAdapter], None
|
||
],
|
||
):
|
||
self.listeners.pop(event_type)
|
||
|
||
def set_bot_uuid(self, bot_uuid: str):
|
||
"""设置 bot UUID(用于生成 webhook URL)"""
|
||
self.bot_uuid = bot_uuid
|
||
|
||
async def handle_unified_webhook(self, bot_uuid: str, path: str, request):
|
||
"""处理统一 webhook 请求。
|
||
|
||
Args:
|
||
bot_uuid: Bot 的 UUID
|
||
path: 子路径(如果有的话)
|
||
request: Quart Request 对象
|
||
|
||
Returns:
|
||
响应数据
|
||
"""
|
||
try:
|
||
signature = request.headers.get('X-Line-Signature')
|
||
body = await request.get_data(as_text=True)
|
||
|
||
# Check if signature header exists
|
||
if not signature:
|
||
await self.logger.warning('Missing X-Line-Signature header')
|
||
return quart.Response('Missing X-Line-Signature header', status=400)
|
||
|
||
try:
|
||
events = self.parser.parse(body, signature) # 解密解析消息
|
||
except InvalidSignatureError:
|
||
await self.logger.info(
|
||
f'Invalid signature. Please check your channel access token/channel secret.{traceback.format_exc()}'
|
||
)
|
||
return quart.Response('Invalid signature', status=400)
|
||
|
||
# 处理事件
|
||
if events and len(events) > 0:
|
||
lb_event = await self.event_converter.target2yiri(events[0], self.api_client)
|
||
if lb_event.__class__ in self.listeners:
|
||
await self.listeners[lb_event.__class__](lb_event, self)
|
||
|
||
return {'code': 200, 'message': 'ok'}
|
||
except Exception:
|
||
await self.logger.error(f'Error in LINE callback: {traceback.format_exc()}')
|
||
print(traceback.format_exc())
|
||
return {'code': 500, 'message': 'error'}
|
||
|
||
async def run_async(self):
|
||
# 统一 webhook 模式下,不启动独立的 Quart 应用
|
||
# 保持运行但不启动独立端口
|
||
|
||
# 打印 webhook 回调地址
|
||
async def keep_alive():
|
||
while True:
|
||
await asyncio.sleep(1)
|
||
|
||
await keep_alive()
|
||
|
||
async def kill(self) -> bool:
|
||
await bounded_executor.run_blocking_cleanup(self.api_client.close)
|
||
return True
|