feat(backend): enforce user-owned sessions
This commit is contained in:
@@ -1,6 +1,7 @@
|
||||
import { spawn } from "node:child_process";
|
||||
import { existsSync } from "node:fs";
|
||||
import { join } from "node:path";
|
||||
import { principalEnvironment, type PrincipalContext } from "../auth/principal.js";
|
||||
|
||||
export interface ThtConfig {
|
||||
thtBin: string;
|
||||
@@ -37,7 +38,10 @@ export interface OllamaEnsureResult {
|
||||
}
|
||||
|
||||
export class ThtRunner {
|
||||
constructor(private cfg: ThtConfig) {}
|
||||
constructor(private cfg: ThtConfig, private principal?: PrincipalContext) {}
|
||||
|
||||
/** Bind one trusted request principal to every child spawned by this runner. */
|
||||
withPrincipal(principal: PrincipalContext): ThtRunner { return new ThtRunner(this.cfg, principal); }
|
||||
|
||||
/**
|
||||
* Resolve the `-c <config>` args. If `workspace` is given AND a matching
|
||||
@@ -65,15 +69,23 @@ export class ThtRunner {
|
||||
const env: NodeJS.ProcessEnv = { ...process.env };
|
||||
delete env.THT_DATA_ROOT;
|
||||
if (this.cfg.dataRoot !== undefined) env.THT_DATA_ROOT = this.cfg.dataRoot;
|
||||
if (this.principal) Object.assign(env, principalEnvironment(this.principal));
|
||||
const ch = spawn(this.cfg.thtBin, this.buildArgv(args, workspace), {
|
||||
cwd: this.cfg.harnessDir,
|
||||
env,
|
||||
});
|
||||
let stdout = "";
|
||||
let stderr = "";
|
||||
let settled = false;
|
||||
const finish = (result: { code: number; stdout: string; stderr: string }) => {
|
||||
if (settled) return;
|
||||
settled = true;
|
||||
resolve(result);
|
||||
};
|
||||
ch.stdout.on("data", (d: Buffer) => (stdout += d));
|
||||
ch.stderr.on("data", (d: Buffer) => (stderr += d));
|
||||
ch.on("close", (code) => resolve({ code: code ?? 0, stdout, stderr }));
|
||||
ch.on("error", (error) => finish({ code: 1, stdout, stderr: stderr || error.message }));
|
||||
ch.on("close", (code) => finish({ code: code ?? 0, stdout, stderr }));
|
||||
});
|
||||
}
|
||||
|
||||
@@ -124,7 +136,7 @@ export class ThtRunner {
|
||||
return this.json<unknown>(["session", "show", id, "--json"], workspace);
|
||||
}
|
||||
|
||||
sqlPreview(id: string, p: { limit?: number; offset?: number }) {
|
||||
sqlPreview(id: string, p: { limit?: number; offset?: number }, workspace?: string) {
|
||||
// No positional FILE: the harness resolves sql_final.sql from the session
|
||||
// via _session_sql_file(cfg, session_id), which respects the workspace path.
|
||||
const a = ["sql", "preview", "--session", id, "--json"];
|
||||
@@ -135,11 +147,11 @@ export class ThtRunner {
|
||||
rows: unknown[][];
|
||||
execution_ms: number;
|
||||
truncated: boolean;
|
||||
}>(a);
|
||||
}>(a, workspace);
|
||||
}
|
||||
|
||||
async sqlExport(id: string) {
|
||||
const { code, stdout, stderr } = await this.run(["sql", "export", "--session", id]);
|
||||
async sqlExport(id: string, workspace?: string) {
|
||||
const { code, stdout, stderr } = await this.run(["sql", "export", "--session", id], workspace);
|
||||
if (code !== 0) throw new Error(`tht sql export exit ${code}: ${stderr.trim()}`);
|
||||
return { path: stdout.trim() };
|
||||
}
|
||||
@@ -157,6 +169,11 @@ export class ThtRunner {
|
||||
}
|
||||
documents(id: string) { return this.json<SessionDocument[]>(["session", "documents", id, "--json"]); }
|
||||
|
||||
preferencesGet(workspace?: string) { return this.json<Record<string, unknown>>(["session", "preferences", "get", "--json"], workspace); }
|
||||
async preferencesSet(preferences: Record<string, unknown>, workspace?: string): Promise<void> {
|
||||
await this.ok(["session", "preferences", "set", "--json", JSON.stringify(preferences)], workspace);
|
||||
}
|
||||
|
||||
async ollamaEnsure(workspace: string, timeoutSec: number): Promise<OllamaEnsureResult> {
|
||||
const { code, stdout, stderr } = await this.run(
|
||||
["ollama", "ensure", "--json", "--timeout", String(timeoutSec)],
|
||||
|
||||
Reference in New Issue
Block a user