mirror of
https://github.com/langbot-app/LangBot.git
synced 2026-09-16 14:57:15 +00:00
e1ac5e0fc8
* Document multi-tenant workspace architecture * Add OSS and commercial workspace boundaries * docs: redesign multi-tenant workspace architecture * feat(tenancy): implement workspace isolation * docs(tenancy): record verification evidence * docs(tenancy): revise single-instance SaaS topology * docs(tenancy): refine architecture options * docs: finalize cloud v2 multi-tenant decisions * feat(tenancy): establish cloud isolation foundations * feat(tenancy): harden shared cloud runtime boundaries * docs(tenancy): record final isolation verification * fix(tenancy): close isolation and permission gaps * docs(tenancy): record final isolation verification * feat(tenancy): connect cloud workspace control plane * fix(build): install git for pinned SDK * docs(cloud): update control plane verification * chore: update multi-tenant SDK pin * fix(cloud): skip legacy model sync during startup * test(cloud): preserve minimal model manager fixtures * fix(cloud): preserve authenticated account context * fix(cloud): reuse authenticated account for user info * feat(cloud): complete Workspace settings navigation * test(web): cover Workspace dropdown menu * feat(web): place workspace controls in sidebar * refactor(web): streamline workspace controls * style(web): format workspace layout test * fix(cloud): surface runtime and workspace plan status * fix(plugin): keep runtime identity stable across restarts * fix(ui): widen and center workspace switcher * fix(ui): hide roles from workspace switcher * fix(ui): align workspace switcher with sidebar entries * feat(workspace): add in-product collaboration and direct Cloud launch * style: format collaboration changes * fix(workspace): bind collaboration APIs to tenant UoW * fix(cloud): preserve Core-owned collaboration state * test(cloud): require Space identity for invite registration * feat(cloud): complete secure invitation experience * style(web): format invitation flows * fix(cloud): recover box runtime without unscoped skill reload * feat(oss): enforce invitation account and owner billing flows * style: format OSS account service * test(oss): cover invitation logout handoff * fix(oss): resolve workspace owner in scoped session * feat(cloud): harden multi-tenant runtime resources * fix(cloud): bound runtime restart storms * fix(cloud): eliminate periodic runtime CPU spikes * fix(cloud): enforce instance capacity ceilings * fix(cloud): scope public login capability discovery * fix(cloud): bound tenant maintenance and monitoring work * fix(runtime): bound tenant resource amplification * fix(deps): pin green multi-tenant plugin SDK * fix(cloud): handle unavailable skill capability * fix(security): require authentication for image file endpoint (H-2) - Changed /api/v1/files/image from AuthType.NONE to USER_TOKEN_OR_API_KEY - Added Permission.RESOURCE_VIEW requirement - Prevents unauthenticated cross-tenant file access via leaked keys - Fixes HIGH severity finding from multi-tenant security review docs: add comprehensive database migration guide - Complete migration steps for OSS → multi-tenant - Backup, execution, verification procedures - Rollback scenarios and recovery plans - Performance tuning recommendations * test: add comprehensive cross-tenant isolation tests Added 7 critical test scenarios for multi-tenant boundaries: - Cross-tenant bot access prevention - Viewer role read-only enforcement - Removed member immediate access revocation - Model provider credential isolation - WebSocket message isolation - Invitation token workspace scoping - Multi-workspace context validation These tests address P0-2 coverage gaps for: - workspaces.py (membership & invitation flows) - user.py (authentication & authorization) - websocket_chat.py (real-time isolation) - plugins.py (resource access control) docs: finalize database migration guide * fix(security): resolve M-1, M-2, M-3 security findings M-1: WebSocket authorization TOCTOU race (FIXED) - Changed _revalidate_websocket_authorization to return RequestContext - Ensures validated context is used immediately without race window - Prevents removed members from sending messages during revalidation gap M-2: Model Manager cache workspace isolation (VERIFIED) - Confirmed _CacheKey already uses 4-tuple: (instance, workspace, generation, resource) - Cache is properly scoped per workspace, no cross-tenant leakage possible - No code change needed, documented as working correctly M-3: Invitation lock workspace scoping (FIXED) - Changed lock key from token_digest to workspace_uuid:token_digest - Prevents DoS where attacker locks token in Workspace A to block Workspace B - Locks now isolated per workspace All MEDIUM severity findings from security review now resolved. * fix(cloud): unblock tenant CI and enforce knowledge quotas * fix(tenancy): scope rerank model sync --------- Co-authored-by: dadachann <185672915+dadachann@users.noreply.github.com>
184 lines
6.5 KiB
Python
184 lines
6.5 KiB
Python
from __future__ import annotations
|
||
import typing
|
||
import asyncio
|
||
import traceback
|
||
import pydantic
|
||
import datetime
|
||
import langbot_plugin.api.definition.abstract.platform.adapter as abstract_platform_adapter
|
||
from langbot.libs.official_account_api.oaevent import OAEvent
|
||
from langbot.libs.official_account_api.api import OAClient
|
||
from langbot.libs.official_account_api.api import OAClientForLongerResponse
|
||
import langbot_plugin.api.entities.builtin.platform.entities as platform_entities
|
||
import langbot_plugin.api.entities.builtin.platform.message as platform_message
|
||
import langbot_plugin.api.entities.builtin.platform.events as platform_events
|
||
from ..logger import EventLogger
|
||
|
||
|
||
class OAMessageConverter(abstract_platform_adapter.AbstractMessageConverter):
|
||
@staticmethod
|
||
async def yiri2target(message_chain: platform_message.MessageChain):
|
||
for msg in message_chain:
|
||
if type(msg) is platform_message.Plain:
|
||
return msg.text
|
||
|
||
@staticmethod
|
||
async def target2yiri(message: str, message_id=-1):
|
||
yiri_msg_list = []
|
||
yiri_msg_list.append(platform_message.Source(id=message_id, time=datetime.datetime.now()))
|
||
|
||
yiri_msg_list.append(platform_message.Plain(text=message))
|
||
chain = platform_message.MessageChain(yiri_msg_list)
|
||
|
||
return chain
|
||
|
||
|
||
class OAEventConverter(abstract_platform_adapter.AbstractEventConverter):
|
||
@staticmethod
|
||
async def target2yiri(event: OAEvent):
|
||
if event.type == 'text':
|
||
yiri_chain = await OAMessageConverter.target2yiri(event.message, event.message_id)
|
||
|
||
friend = platform_entities.Friend(
|
||
id=event.user_id,
|
||
nickname=str(event.user_id),
|
||
remark='',
|
||
)
|
||
|
||
return platform_events.FriendMessage(
|
||
sender=friend,
|
||
message_chain=yiri_chain,
|
||
time=event.timestamp,
|
||
source_platform_object=event,
|
||
)
|
||
else:
|
||
return None
|
||
|
||
|
||
class OfficialAccountAdapter(abstract_platform_adapter.AbstractMessagePlatformAdapter):
|
||
message_converter: OAMessageConverter = OAMessageConverter()
|
||
event_converter: OAEventConverter = OAEventConverter()
|
||
bot: typing.Union[OAClient, OAClientForLongerResponse] = pydantic.Field(exclude=True)
|
||
bot_uuid: str = None
|
||
|
||
def __init__(self, config: dict, logger: EventLogger):
|
||
# 校验必填项
|
||
required_keys = ['token', 'EncodingAESKey', 'AppSecret', 'AppID', 'Mode']
|
||
missing_keys = [k for k in required_keys if k not in config]
|
||
if missing_keys:
|
||
raise Exception(f'OfficialAccount 缺少配置项: {missing_keys}')
|
||
|
||
# 创建运行时 bot 对象,始终使用统一 webhook 模式
|
||
if config['Mode'] == 'drop':
|
||
bot = OAClient(
|
||
token=config['token'],
|
||
EncodingAESKey=config['EncodingAESKey'],
|
||
Appsecret=config['AppSecret'],
|
||
AppID=config['AppID'],
|
||
logger=logger,
|
||
unified_mode=True,
|
||
api_base_url=config.get('api_base_url', 'https://api.weixin.qq.com'),
|
||
)
|
||
elif config['Mode'] == 'passive':
|
||
bot = OAClientForLongerResponse(
|
||
token=config['token'],
|
||
EncodingAESKey=config['EncodingAESKey'],
|
||
Appsecret=config['AppSecret'],
|
||
AppID=config['AppID'],
|
||
LoadingMessage=config.get('LoadingMessage', ''),
|
||
logger=logger,
|
||
unified_mode=True,
|
||
api_base_url=config.get('api_base_url', 'https://api.weixin.qq.com'),
|
||
)
|
||
else:
|
||
raise KeyError('请设置微信公众号通信模式')
|
||
|
||
bot_account_id = config.get('AppID', '')
|
||
|
||
super().__init__(
|
||
bot=bot,
|
||
bot_account_id=bot_account_id,
|
||
config=config,
|
||
logger=logger,
|
||
)
|
||
|
||
async def reply_message(
|
||
self,
|
||
message_source: platform_events.FriendMessage,
|
||
message: platform_message.MessageChain,
|
||
quote_origin: bool = False,
|
||
):
|
||
content = await OAMessageConverter.yiri2target(message)
|
||
if isinstance(self.bot, OAClient):
|
||
await self.bot.set_message(message_source.message_chain.message_id, content)
|
||
elif isinstance(self.bot, OAClientForLongerResponse):
|
||
from_user = message_source.sender.id
|
||
await self.bot.set_message(from_user, message_source.message_chain.message_id, content)
|
||
|
||
async def send_message(self, target_type: str, target_id: str, message: platform_message.MessageChain):
|
||
pass
|
||
|
||
def register_listener(
|
||
self,
|
||
event_type: type,
|
||
callback: typing.Callable[
|
||
[platform_events.Event, abstract_platform_adapter.AbstractMessagePlatformAdapter], None
|
||
],
|
||
):
|
||
async def on_message(event: OAEvent):
|
||
self.bot_account_id = event.receiver_id
|
||
try:
|
||
return await callback(await self.event_converter.target2yiri(event), self)
|
||
except Exception:
|
||
await self.logger.error(f'Error in officialaccount callback: {traceback.format_exc()}')
|
||
|
||
if event_type == platform_events.FriendMessage:
|
||
self.bot.on_message('text')(on_message)
|
||
elif event_type == platform_events.GroupMessage:
|
||
pass
|
||
|
||
def set_bot_uuid(self, bot_uuid: str):
|
||
"""设置 bot UUID(用于生成 webhook URL)"""
|
||
self.bot_uuid = bot_uuid
|
||
|
||
async def handle_unified_webhook(self, bot_uuid: str, path: str, request):
|
||
"""处理统一 webhook 请求。
|
||
|
||
Args:
|
||
bot_uuid: Bot 的 UUID
|
||
path: 子路径(如果有的话)
|
||
request: Quart Request 对象
|
||
|
||
Returns:
|
||
响应数据
|
||
"""
|
||
return await self.bot.handle_unified_webhook(request)
|
||
|
||
async def run_async(self):
|
||
# 统一 webhook 模式下,不启动独立的 Quart 应用
|
||
# 保持运行但不启动独立端口
|
||
|
||
async def keep_alive():
|
||
while True:
|
||
await asyncio.sleep(1)
|
||
|
||
await keep_alive()
|
||
|
||
async def kill(self) -> bool:
|
||
self.bot.clear()
|
||
return False
|
||
|
||
async def unregister_listener(
|
||
self,
|
||
event_type: type,
|
||
callback: typing.Callable[
|
||
[platform_events.Event, abstract_platform_adapter.AbstractMessagePlatformAdapter], None
|
||
],
|
||
):
|
||
return super().unregister_listener(event_type, callback)
|
||
|
||
async def is_muted(
|
||
self,
|
||
group_id: str,
|
||
) -> bool:
|
||
pass
|