fix(backend): harden principal child isolation
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
import { spawn } from "node:child_process";
|
||||
import { existsSync } from "node:fs";
|
||||
import { join } from "node:path";
|
||||
import { principalEnvironment, type PrincipalContext } from "../auth/principal.js";
|
||||
import { clearPrincipalEnvironment, principalEnvironment, type PrincipalContext } from "../auth/principal.js";
|
||||
|
||||
export interface ThtConfig {
|
||||
thtBin: string;
|
||||
@@ -68,6 +68,7 @@ export class ThtRunner {
|
||||
return new Promise((resolve) => {
|
||||
const env: NodeJS.ProcessEnv = { ...process.env };
|
||||
delete env.THT_DATA_ROOT;
|
||||
clearPrincipalEnvironment(env);
|
||||
if (this.cfg.dataRoot !== undefined) env.THT_DATA_ROOT = this.cfg.dataRoot;
|
||||
if (this.principal) Object.assign(env, principalEnvironment(this.principal));
|
||||
const ch = spawn(this.cfg.thtBin, this.buildArgv(args, workspace), {
|
||||
@@ -159,15 +160,15 @@ export class ThtRunner {
|
||||
closeSession(id: string, workspace?: string) { return this.ok(["session", "close", id], workspace); }
|
||||
failSession(id: string, workspace?: string) { return this.ok(["session", "fail", id], workspace); }
|
||||
reopenSession(id: string, workspace?: string) { return this.ok(["session", "reopen", id], workspace); }
|
||||
setName(id: string, name: string) { return this.ok(["session", "set-name", id, "--name", name]); }
|
||||
setGroup(id: string, group: string) { return this.ok(["session", "set-group", id, "--group", group]); }
|
||||
archive(id: string) { return this.ok(["session", "archive", id]); }
|
||||
unarchive(id: string) { return this.ok(["session", "unarchive", id]); }
|
||||
setName(id: string, name: string, workspace?: string) { return this.ok(["session", "set-name", id, "--name", name], workspace); }
|
||||
setGroup(id: string, group: string, workspace?: string) { return this.ok(["session", "set-group", id, "--group", group], workspace); }
|
||||
archive(id: string, workspace?: string) { return this.ok(["session", "archive", id], workspace); }
|
||||
unarchive(id: string, workspace?: string) { return this.ok(["session", "unarchive", id], workspace); }
|
||||
async deleteSession(id: string, workspace?: string) {
|
||||
const { code, stderr } = await this.run(["session", "delete", id], workspace);
|
||||
if (code !== 0) throw new Error(`tht session delete exit ${code}: ${stderr.trim()}`);
|
||||
}
|
||||
documents(id: string) { return this.json<SessionDocument[]>(["session", "documents", id, "--json"]); }
|
||||
documents(id: string, workspace?: string) { return this.json<SessionDocument[]>(["session", "documents", id, "--json"], workspace); }
|
||||
|
||||
preferencesGet(workspace?: string) { return this.json<Record<string, unknown>>(["session", "preferences", "get", "--json"], workspace); }
|
||||
async preferencesSet(preferences: Record<string, unknown>, workspace?: string): Promise<void> {
|
||||
|
||||
Reference in New Issue
Block a user