feat: update encrypt

This commit is contained in:
chaoszhu
2026-08-15 14:46:08 +08:00
parent 6827366dee
commit 08cf10dd60
4 changed files with 26 additions and 2 deletions
+2 -1
View File
@@ -85,7 +85,8 @@ const ALWAYS_READ_ONLY_CMDS = new Set([
'ls', 'stat', 'du', 'df', 'grep', 'egrep', 'fgrep', 'wc',
'readlink', 'realpath', 'pwd', 'which', 'whereis', 'echo', 'printf', 'test',
'cd',
'ps', 'free', 'uptime', 'uname', 'whoami', 'id', 'printenv',
'ps', 'free', 'uptime', 'uname', 'whoami', 'last', 'lastb',
'id', 'printenv',
'md5sum', 'sha256sum', 'cut', 'tr', 'jq'
])
File diff suppressed because one or more lines are too long
+21
View File
@@ -30,6 +30,7 @@ const { getToolSpec, PlusPolicy, requiresPlus } = await import(`${ originalCwd }
const { requestTerminalDispatch } = await import(`${ originalCwd }/app/ai/terminal-dispatch.js`)
const { buildTools, describeAvailableTools } = await import(`${ originalCwd }/app/ai/tools/index.js`)
const { hostList, checkRestrictedToolAccess } = await import(`${ originalCwd }/app/ai/tools/executors.js`)
const { RuntimeState } = await import(`${ originalCwd }/app/utils/runtime-state.js`)
const hostListDB = new HostListDB().getInstance()
@@ -241,6 +242,26 @@ console.log('\n========== Plus 工具权限 ==========')
&& event.effect === Effect.WRITE
&& event.toolCallId === 'tool-write'
)))
const runtimeState = new RuntimeState().getInstance()
runtimeState.setPlusKicked(true)
events.length = 0
const invalidAccess = await checkRestrictedToolAccess(
ctx,
'exec_command',
Effect.WRITE,
'tool-invalid-plus'
)
expect('已失效的 Plus 授权不误报成未激活', invalidAccess.code, 'PLUS_AUTH_INVALID')
assert('授权失效时返回可恢复的工具拒绝', events.some((event) => (
event.type === 'tool_denied'
&& event.toolCallId === 'tool-invalid-plus'
&& event.permanent === false
)))
assert('授权失效时不弹出重复激活提示', !events.some((event) => (
event.type === 'tool_requires_plus'
)))
runtimeState.setPlusKicked(false)
}
console.log('\n========== 会话保留策略 ==========')
+2
View File
@@ -136,6 +136,8 @@ const normalCases = [
['date +%F', Effect.READ],
['find /tmp -type f', Effect.READ],
['journalctl --no-pager -n 50', Effect.READ],
['last -n 15', Effect.READ],
['lastb -n 15', Effect.READ],
['dmesg --level err', Effect.READ],
['ss -lntp', Effect.READ],
['crontab -l', Effect.READ],