fix(auth): validate stopped workspace restore

This commit is contained in:
2026-08-18 00:06:28 +02:00
parent e8b9995ed0
commit 0651f3316f
6 changed files with 300 additions and 11 deletions
+26 -4
View File
@@ -5,6 +5,7 @@ import (
"crypto/rand"
"crypto/sha256"
"encoding/hex"
"encoding/json"
"errors"
"fmt"
"io"
@@ -407,14 +408,35 @@ func verifyRestoreWorkspace(ctx context.Context, installation config.Installatio
if err != nil {
return err
}
command := []string{"exec", "-T", "core", "node", "-e"}
command := []string{"exec", "-T", "core", "node", "/app/backend/dist/operator-command.js", "workspace-integrity"}
if !running {
command = []string{"run", "--rm", "--no-deps", "--no-TTY", "core", "node", "-e"}
command = []string{"run", "--rm", "--no-deps", "--no-TTY", "core", "node", "/app/backend/dist/operator-command.js", "workspace-integrity"}
}
command = append(command, `const fs=require("node:fs");const p="/data/workspace-registry/state/active.json";const s=JSON.parse(fs.readFileSync(p,"utf8"));const h=/^[0-9a-f]{40}$/;if(!h.test(s.head)||!Array.isArray(s.revisions)||s.revisions.some(r=>!r||typeof r.id!=="string"||!r.id||!h.test(r.commit)||!h.test(r.blob)))process.exit(1);for(const r of s.revisions)fs.accessSync("/data/workspace-registry/snapshots/"+r.commit+"/"+r.id+".yaml",fs.constants.R_OK)`)
result, err := runner.Run(ctx, installation.ComposeArgs(command...), nil)
if err != nil {
if err != nil || result.ExitCode != 0 {
return dockerError("validate restored workspace registry", result, err)
}
if len(result.Stdout) == 0 || len(result.Stdout) > 4096 {
return errors.New("restored workspace registry returned an invalid result")
}
var payload struct {
Ready bool `json:"ready"`
State string `json:"state"`
Workspaces int `json:"workspaces"`
}
decoder := json.NewDecoder(strings.NewReader(result.Stdout))
decoder.DisallowUnknownFields()
if decodeErr := decoder.Decode(&payload); decodeErr != nil {
return errors.New("restored workspace registry returned an invalid result")
}
var trailing any
if decodeErr := decoder.Decode(&trailing); !errors.Is(decodeErr, io.EOF) {
return errors.New("restored workspace registry returned an invalid result")
}
if !payload.Ready || payload.Workspaces < 0 ||
(payload.State != "active" && payload.State != "uninitialized") ||
(payload.State == "uninitialized" && payload.Workspaces != 0) {
return errors.New("restored workspace registry did not pass integrity validation")
}
return nil
}