mirror of
https://github.com/larksuite/cli.git
synced 2026-09-14 18:42:53 +08:00
d12b39cf46
* feat(vfs): allow absolute paths under a built-in path allowlist Path flags only accepted paths relative to the working directory, so an agent passing a full path (typically under /tmp) failed on its first call and had to retry with a relative one. Absolute paths are now accepted when they resolve inside a built-in allowlist: the working directory, /tmp, and ~/files. A built-in denylist covers system and credential locations and wins over the allowlist, including over the working directory. Both lists are compiled in and read no environment variable, flag, or config file, so the effective policy is fixed by the binary; upgrading is all it takes for the new behavior to apply. Containment is decided by file identity (device and inode) alongside the resolved name, because a single directory has many spellings: APFS folds U+017F onto "s", so ".sshh" spelled with it opens ~/.ssh, and NTFS and APFS both compare case-insensitively. Reads are hardened where the policy applies: O_NOFOLLOW pins the final component, O_NONBLOCK keeps a FIFO from blocking before it can be refused, and the opened descriptor is matched against the inspected object, rejected when it is not a regular file, and rejected when it carries extra hard links. The relaxed local-input tier used by apps upload keeps its own contract (symlinks are legitimate arguments there) and gains the denylist check instead. Two behaviors are deliberate rather than incidental. Working inside a denylisted directory now refuses even relative paths, since the denylist is unconditional. Running as root leaves only the working directory and /tmp, because the home directory is then /root, itself a deny root. Existing tests asserted the old "every absolute path is refused" baseline; they now assert the allowlist. Traversal fixtures escape to the filesystem root, which stays outside every allowed root on Linux, where the temp directory that hosts t.TempDir() is /tmp itself. * fix(vfs): close two paths around the built-in denylist A "~/..." argument had two readings: validation expanded it to the home directory, while a caller that keeps the original string — SafeLocalFlagPath returns it verbatim — opens whatever "~" names in the working directory. A symlink there carried reads past the denylist, confirmed by reading /etc/passwd through it. Every interpretation of an argument is now checked, so the shorthand still reaches ~/files while the literal entry cannot escape. With no LARKSUITE_CLI_CONFIG_DIR and no reachable home directory, core.GetBaseConfigDir keeps credentials in a bare ".lark-cli" resolved against the working directory, which is an allow root. That fallback is now mirrored as a deny root, so containers whose home lookup fails do not expose their stored tokens. * fix(vfs): enforce hard-link checks across readers * fix(vfs): stop an output hard link from rewriting a file outside the allowlist A hard link has no target for name resolution to follow, so a link inside an allowed root looked like an allowed destination while sharing its inode with a file outside every root. A caller that truncated the approved name in place rewrote that outside file: `auth qrcode --output <link>` reported success and replaced a 43-byte JSON file outside the allowlist with its PNG. Output validation now refuses an existing target that carries more than one name, which covers callers that write directly, and auth qrcode commits through a temp file and a rename, which replaces the directory entry and leaves the other names alone. Writers already going through FileIO.Save were never affected, since that path has always committed by rename. * fix(vfs): give the hard-link refusal a workable recovery hint The message told the caller to copy the file into an allowed directory, which answers a question they did not ask: the file that triggers this is normally already inside one, with every one of its names there too. It now states what the check actually cannot do — enumerate the other names a file is reachable by — and offers the step that works, which is to copy the file and use the copy. * test(vfs): pick the denylist fixture for the platform under test Two tests reached for "/etc/passwd" as a denylisted absolute path. That path is not absolute on Windows, so one test met the foreign-path rejection instead of the denylist it was asserting, and the other saw the path joined to the working directory and no rejection at all. Both now ask for a deny root that exists on the platform running them — the credential directories under the account home qualify everywhere — which keeps the denylist covered on Windows rather than skipping it there. Verified on Windows 10.0.19045 by running the package's test binary from this branch and from main: main passed, this branch failed these two, and both pass after the change. The other packages this branch touches were compared the same way and their Windows results are identical on both sides. * fix(vfs): state the hard-link check as the condition it tests The check read as "bail out unless the target can be inspected", which nilerr reads as an error swallowed on the way out. It now names the case it acts on — an existing regular file with more than one name — and the comment carries what the early return used to imply: a target that cannot be inspected has no link count to judge, and the write layer reports the real failure with proper typing. * docs(vfs): scope the policy's environment claim to what holds The header promised that neither list accepts runtime input and that no caller controlling the environment can widen them. Two inputs contradict that: LARKSUITE_CLI_CONFIG_DIR contributes a deny root, and where the account database cannot name the running uid, $HOME decides where ~/files points — reproduced in a container running as an unregistered uid, which wrote into a directory the environment chose. The comments now state the preference and its boundary rather than a guarantee, and record what the boundary costs: a directory named "files" under the named path, with the home directory itself still outside the allowlist and every candidate home still carrying the credential deny roots. The trustedHome note also said the pure-Go lookup falls back to $HOME silently; it does so only when $USER is set as well, and returns an error otherwise, which drops the ~/files root instead of moving it. No behavior change. * fix(auth): keep the mode of a QR output file that already exists Committing the QR write by rename fixed a hard link from rewriting a file outside the allowlist, but it also changed what happens to the target's mode. A rename installs the temp file's inode, mode included, where the previous in-place write left the existing file's mode untouched. Overwriting a target the caller had restricted to 0600 therefore published it as 0644. The mode now comes from the file already at the path; only a path with nothing at it takes the default. Verified against main, which preserved 0600 here, and covered by a test that fails when the fixed mode is restored. * test(sheets): move the csv file-alias tests onto the new path baseline Merging main brought #2559's tests for the --file → --csv alias, written against the policy this branch replaces. Two of them fail on it, both because the verdict they describe moved rather than disappeared. The out-of-tree case used /tmp, which the allowlist now accepts, so the value came back as a missing file instead of an out-of-tree one; it now names a path no allow root can contain. The directory case is refused when the descriptor is inspected, before a read is attempted, so the message reads "not a regular file". What the caller sees of both — the flag named, the cause kept, stdin offered — is unchanged. That message listed the kinds it refuses and omitted directories, which is how it reached a directory test reading as a mismatch. It now names them. * fix(im): let the path policy judge a download target `+messages-resources-download` refused an absolute --output before the shared policy saw it, so the flag stayed relative-only after the policy learned to accept full paths. It is the command behind 99% of a reported 1,189 download path errors in one week, where 97.2% of first calls passed an absolute path and every later success had switched to a relative one. The shape checks are gone. Both call sites already hand the result to ResolveSavePath, which applies the allowlist, the denylist and symlink resolution, so refusing a shape here decided nothing the policy would not decide better — an absolute path is now answered by where it points rather than by how it is written. The file-key checks stay, and they are what the batch caller relies on: it embeds the key in the path, and a key carrying a separator is refused as a malformed key, so a traversal cannot be built from one. Verified against a real tenant: /tmp and ~/files now save, while ~/.ssh, /etc and a path outside every root are still refused. * test(im): pin the download output contract the policy now decides The dry-run suite listed an absolute path among the values --output must refuse. That held while the command rejected the shape itself; now that the built-in policy decides, /tmp is an allowed root and the path is accepted, so the case asserted a rule that no longer exists. It is replaced by the two halves of the real contract: an absolute path inside an allowed root reaches the request, and a path that resolves outside every root — a parent escape from this working directory, or a denylisted directory — is still turned down as a validation error naming --output. * fix(vfs): hold a relative path to the working directory Accepting /tmp as an allow root gave a relative path somewhere new to go. A process whose working directory sits under /tmp — CI runners, containers and agent sandboxes commonly arrange that — could climb out with "../" and still satisfy the allowlist, because the sibling it landed in was also under /tmp. /tmp is world-writable, so that sibling can belong to another user or another session, and the write side commits by rename, which replaces an existing target unconditionally. The previous policy refused this: it required every resolved path to stay under the working directory. Naming a full path and climbing out of the working directory are different acts and no longer share one verdict. An absolute path is judged by the allowlist, which is what this branch set out to allow; a relative one has to resolve inside the working directory, whatever wider root contains it. The home denylist grows at the same time and for the same reason: the working directory is an allow root and running from the home directory is ordinary, so a credential store there is reachable by a relative name unless the list covers it. It now names the common ones — netrc, git and shell credentials, kube, docker, azure, gh, gcloud, the language package registries — and the shell histories, which carry pasted keys as reliably as a credential file. ---------
485 lines
17 KiB
Go
485 lines
17 KiB
Go
// Copyright (c) 2026 Lark Technologies Pte. Ltd.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package event
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"fmt"
|
|
"io"
|
|
"os"
|
|
"os/signal"
|
|
"strings"
|
|
"syscall"
|
|
"time"
|
|
|
|
"github.com/spf13/cobra"
|
|
|
|
"github.com/larksuite/cli/cmd/event/render"
|
|
"github.com/larksuite/cli/errs"
|
|
"github.com/larksuite/cli/internal/appmeta"
|
|
"github.com/larksuite/cli/internal/auth"
|
|
"github.com/larksuite/cli/internal/cmdutil"
|
|
"github.com/larksuite/cli/internal/core"
|
|
"github.com/larksuite/cli/internal/credential"
|
|
eventlib "github.com/larksuite/cli/internal/event"
|
|
"github.com/larksuite/cli/internal/event/adapter/localbus/transport"
|
|
appconsume "github.com/larksuite/cli/internal/event/application/consume"
|
|
"github.com/larksuite/cli/internal/event/catalog"
|
|
"github.com/larksuite/cli/internal/event/consume"
|
|
"github.com/larksuite/cli/internal/output"
|
|
"github.com/larksuite/cli/internal/validate"
|
|
)
|
|
|
|
type consumeCmdOpts struct {
|
|
params []string
|
|
jqExpr string
|
|
quiet bool
|
|
outputDir string
|
|
|
|
maxEvents int
|
|
timeout time.Duration
|
|
dryRun bool
|
|
}
|
|
|
|
func NewCmdConsume(f *cmdutil.Factory, snap *catalog.Snapshot) *cobra.Command {
|
|
var o consumeCmdOpts
|
|
|
|
cmd := &cobra.Command{
|
|
Use: "consume <EventKey>",
|
|
Short: "Start consuming events for an EventKey",
|
|
Long: `Start consuming real-time events for the given EventKey.
|
|
|
|
The consume command connects to the event bus daemon (starting it if needed),
|
|
subscribes to the specified EventKey, and streams processed events to stdout.
|
|
|
|
Output is one JSON object per line (NDJSON). Pipe through 'jq .' if you need
|
|
pretty-printed formatting.
|
|
|
|
Use 'event list' to see all available EventKeys.
|
|
Use 'event schema <EventKey>' for parameter details.`,
|
|
Args: cobra.ExactArgs(1),
|
|
RunE: func(cmd *cobra.Command, args []string) error {
|
|
return runConsume(cmd, f, snap, args[0], o)
|
|
},
|
|
}
|
|
|
|
cmd.Flags().StringArrayVarP(&o.params, "param", "p", nil, "Key=value parameter (repeatable)")
|
|
cmd.Flags().StringVar(&o.jqExpr, "jq", "", "JQ expression to filter output")
|
|
cmd.Flags().BoolVar(&o.quiet, "quiet", false, "Suppress routine and per-event stderr output, including ready/exit markers and drop diagnostics. This can hide event loss; omit --quiet when integrity matters")
|
|
cmd.Flags().StringVar(&o.outputDir, "output-dir", "", "Write each event as a file in this directory (within the allowed roots: cwd, /tmp, ~/files; denylisted system/credential paths are rejected)")
|
|
cmd.Flags().IntVar(&o.maxEvents, "max-events", 0, "Exit after N successful emits (0 = unlimited). Multi-worker EventKeys may emit up to workers-1 past N before all workers stop. Bounded runs ignore stdin EOF.")
|
|
cmd.Flags().BoolVar(&o.dryRun, "dry-run", false, "Decide and preview the consume (identity, preconditions, side effects) without performing any of them, then exit")
|
|
cmd.Flags().DurationVar(&o.timeout, "timeout", 0, "Exit after DURATION (e.g. 30s, 2m). 0 = no timeout. Timeout is a normal exit (code 0; stderr 'reason: timeout'). Bounded runs ignore stdin EOF.")
|
|
cmd.Flags().String("as", "auto", "identity type: user | bot | auto (must match EventKey's declared AuthTypes)")
|
|
_ = cmd.RegisterFlagCompletionFunc("as", func(cmd *cobra.Command, args []string, toComplete string) ([]string, cobra.ShellCompDirective) {
|
|
return []string{"user", "bot", "auto"}, cobra.ShellCompDirectiveNoFileComp
|
|
})
|
|
cmdutil.SetRisk(cmd, "read")
|
|
|
|
return cmd
|
|
}
|
|
|
|
func runConsume(cmd *cobra.Command, f *cmdutil.Factory, snap *catalog.Snapshot, eventKey string, o consumeCmdOpts) error {
|
|
// Pipe-close (e.g. `... | head -n 1`) must reach the EPIPE error path in the loop, not SIGPIPE-kill.
|
|
ignoreBrokenPipe()
|
|
|
|
cfg, err := f.Config()
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
paramMap, err := parseParams(o.params)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
entry, ok := snap.Resolve(eventKey)
|
|
if !ok {
|
|
return unknownEventKeyErr(snap, eventKey)
|
|
}
|
|
keyDef := entry.Definition()
|
|
|
|
identity, err := resolveIdentity(cmd, f, keyDef)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
if o.jqExpr != "" {
|
|
if err := output.ValidateJqExpression(o.jqExpr); err != nil {
|
|
return errs.NewValidationError(errs.SubtypeInvalidArgument, "%s", err).
|
|
WithParam("--jq").
|
|
WithCause(err).
|
|
WithHint("see `lark-cli event consume --help` EXAMPLES for common patterns, or `lark-cli event schema %s` for valid field paths", eventKey)
|
|
}
|
|
}
|
|
|
|
outputDir := o.outputDir
|
|
if outputDir != "" {
|
|
safePath, err := sanitizeOutputDir(outputDir)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
outputDir = safePath
|
|
}
|
|
|
|
domain := core.ResolveEndpoints(cfg.Brand).Open
|
|
|
|
// Surface auth errors before forking the bus daemon. A dry run instead
|
|
// reports the unusable credential as a blocked precondition: the caller
|
|
// asked what would happen, and "a real run would refuse to authenticate"
|
|
// is a legitimate part of that answer.
|
|
var tokenErr error
|
|
if _, err := resolveTenantToken(cmd.Context(), f, cfg.AppID); err != nil {
|
|
if !o.dryRun {
|
|
return err
|
|
}
|
|
tokenErr = err
|
|
}
|
|
|
|
apiClient, err := f.NewAPIClient()
|
|
if err != nil {
|
|
return err
|
|
}
|
|
runtime := &consumeRuntime{client: apiClient, accessIdentity: identity}
|
|
// botRuntime pins AsBot: /app_versions rejects UAT (99991668) and /connection is app-level.
|
|
botRuntime := &consumeRuntime{client: apiClient, accessIdentity: core.AsBot}
|
|
|
|
// Weak-dependency fetch: failures leave appVer==nil and downgrade preflight to a no-op.
|
|
preflightErrOut := f.IOStreams.ErrOut
|
|
if o.quiet {
|
|
preflightErrOut = io.Discard
|
|
}
|
|
appVer, appVerErr := appmeta.FetchCurrentPublished(cmd.Context(), botRuntime, cfg.AppID)
|
|
switch {
|
|
case appVerErr != nil:
|
|
fmt.Fprintf(preflightErrOut, "[event] skipped console precheck: %s\n", describeAppMetaErr(appVerErr))
|
|
case appVer == nil:
|
|
fmt.Fprintln(preflightErrOut, "[event] skipped console precheck: app has no published version")
|
|
}
|
|
|
|
// Callback subscriptions live in application/get, not app_versions; fetch the
|
|
// callback 底账 only for callback-type EventKeys. Weak dependency: on error,
|
|
// leave subscribedCallbacks nil so the callback precheck skips.
|
|
var subscribedCallbacks []string
|
|
if keyDef.SubscriptionType == eventlib.SubTypeCallback {
|
|
cbs, cbErr := appmeta.FetchSubscribedCallbacks(cmd.Context(), botRuntime, cfg.AppID)
|
|
if cbErr != nil {
|
|
fmt.Fprintf(preflightErrOut, "[event] skipped console precheck: %s\n", describeAppMetaErr(cbErr))
|
|
} else {
|
|
subscribedCallbacks = cbs
|
|
}
|
|
}
|
|
|
|
pf := &preflightCtx{
|
|
factory: f,
|
|
appID: cfg.AppID,
|
|
brand: cfg.Brand,
|
|
eventKey: eventKey,
|
|
identity: identity,
|
|
keyDef: keyDef,
|
|
appVer: appVer,
|
|
subscribedCallbacks: subscribedCallbacks,
|
|
}
|
|
|
|
svc := &appconsume.Service{
|
|
Strategies: consumeStrategies,
|
|
Identity: identityResolverFunc(func(context.Context, *catalog.Entry) (string, error) { return string(identity), nil }),
|
|
Preflight: preflightReaderFunc(func(ctx context.Context, _ *catalog.Entry, _ string) ([]appconsume.Precondition, error) {
|
|
return readPreconditions(ctx, pf, appVerErr, tokenErr), nil
|
|
}),
|
|
}
|
|
req := appconsume.Request{
|
|
EventKey: eventKey,
|
|
Params: paramMap,
|
|
JQExpr: o.jqExpr,
|
|
OutputDir: outputDir,
|
|
DryRun: o.dryRun,
|
|
MaxEvents: o.maxEvents,
|
|
Timeout: o.timeout,
|
|
IsTTY: f.IOStreams.IsTerminal,
|
|
}
|
|
decision, err := svc.Decide(cmd.Context(), entry, req, appconsume.ExecutionContext{API: runtime})
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
if o.dryRun {
|
|
return render.WriteDecisionJSON(f.IOStreams.Out, f.IOStreams.ErrOut, string(identity), decision.View())
|
|
}
|
|
|
|
ctx, cancel := context.WithCancel(cmd.Context())
|
|
defer cancel()
|
|
|
|
sigCh := make(chan os.Signal, 1)
|
|
signal.Notify(sigCh, syscall.SIGINT, syscall.SIGTERM)
|
|
defer signal.Stop(sigCh)
|
|
go func() {
|
|
select {
|
|
case <-sigCh:
|
|
if !o.quiet && f.IOStreams.IsTerminal {
|
|
fmt.Fprintln(f.IOStreams.ErrOut, "\nShutting down...")
|
|
}
|
|
cancel()
|
|
case <-ctx.Done():
|
|
}
|
|
}()
|
|
|
|
errOut := f.IOStreams.ErrOut
|
|
if o.quiet {
|
|
errOut = io.Discard
|
|
}
|
|
|
|
runner := streamRunnerFunc(func(ctx context.Context, prepare appconsume.PrepareFunc) error {
|
|
// Non-TTY unbounded consumers use stdin EOF as shutdown for subprocess
|
|
// callers. Bounded runs already have --max-events/--timeout as their
|
|
// lifecycle control.
|
|
//
|
|
// The watcher starts here rather than before the decision is executed:
|
|
// a blocked decision never reaches this point, and starting it earlier
|
|
// announced "stdin closed — shutting down" on a run that was actually
|
|
// refused for an unmet precondition, pointing the caller at the wrong
|
|
// cause.
|
|
if shouldWatchStdinEOF(f.IOStreams.IsTerminal, o.maxEvents, o.timeout) {
|
|
watchStdinEOF(os.Stdin, cancel, errOut)
|
|
}
|
|
|
|
return consume.Run(ctx, transport.New(), cfg.AppID, cfg.ProfileName, domain,
|
|
applyDecision(consume.Options{
|
|
EventKey: eventKey,
|
|
Def: keyDef,
|
|
JQExpr: o.jqExpr,
|
|
Quiet: o.quiet,
|
|
OutputDir: outputDir,
|
|
Runtime: runtime,
|
|
Out: f.IOStreams.Out,
|
|
ErrOut: errOut,
|
|
RemoteAPIClient: botRuntime,
|
|
MaxEvents: o.maxEvents,
|
|
Timeout: o.timeout,
|
|
IsTTY: f.IOStreams.IsTerminal,
|
|
}, decision, prepare))
|
|
})
|
|
return svc.Execute(ctx, entry, decision, runner, appconsume.ExecutionContext{API: runtime})
|
|
}
|
|
|
|
// applyDecision transfers the decided parts of a consume onto the host's
|
|
// options. It exists as a named function because these three assignments are
|
|
// couplings the command alone can get wrong, and a test can only pin them where
|
|
// they are written.
|
|
//
|
|
// The parameters and the flag travel together: the deciding layer already ran
|
|
// the normalizer on exactly these values to compute the subscription identity.
|
|
// The flag without the values would leave the host normalizing input the bus
|
|
// was never told about; the values without the flag would run a
|
|
// once-per-consumer hook a second time. Prepare carries the strategy the
|
|
// decision settled on, so what was decided is what executes instead of the
|
|
// declaration's own hook.
|
|
func applyDecision(opts consume.Options, decision *appconsume.Decision, prepare appconsume.PrepareFunc) consume.Options {
|
|
opts.Params = decision.NormalizedParams()
|
|
opts.ParamsNormalized = true
|
|
opts.Prepare = prepare
|
|
return opts
|
|
}
|
|
|
|
// resolveIdentity resolves the session identity and enforces keyDef.AuthTypes as a whitelist.
|
|
func resolveIdentity(cmd *cobra.Command, f *cmdutil.Factory, keyDef *eventlib.KeyDefinition) (core.Identity, error) {
|
|
flagAs := core.Identity(cmd.Flag("as").Value.String())
|
|
identity := f.ResolveAs(cmd.Context(), cmd, flagAs)
|
|
if len(keyDef.AuthTypes) > 0 {
|
|
if err := f.CheckIdentity(identity, keyDef.AuthTypes); err != nil {
|
|
return "", err
|
|
}
|
|
}
|
|
return identity, nil
|
|
}
|
|
|
|
type preflightCtx struct {
|
|
factory *cmdutil.Factory
|
|
appID string
|
|
brand core.LarkBrand
|
|
eventKey string
|
|
identity core.Identity
|
|
keyDef *eventlib.KeyDefinition
|
|
appVer *appmeta.AppVersion
|
|
// subscribedCallbacks is the application/get 底账 for callback-type EventKeys;
|
|
// nil means "not fetched / unavailable" → callback precheck skips (weak dependency).
|
|
subscribedCallbacks []string
|
|
}
|
|
|
|
// preflightScopes compares required scopes against session-available scopes
|
|
// (user: UAT stored; bot: appVer.TenantScopes). checked reports whether a
|
|
// comparison actually happened: "the ledger was unavailable" and "the check
|
|
// passed" are different answers, and only the caller can decide how loudly to
|
|
// say the first one.
|
|
func preflightScopes(ctx context.Context, pf *preflightCtx) (checked bool, err error) {
|
|
if len(pf.keyDef.Scopes) == 0 || pf.identity == "" {
|
|
return true, nil
|
|
}
|
|
if ctx == nil {
|
|
ctx = context.Background()
|
|
}
|
|
|
|
var storedScopes string
|
|
switch {
|
|
case pf.identity.IsBot():
|
|
if pf.appVer == nil {
|
|
return false, nil
|
|
}
|
|
storedScopes = strings.Join(pf.appVer.TenantScopes, " ")
|
|
case pf.identity == core.AsUser:
|
|
result, err := pf.factory.Credential.ResolveToken(ctx, credential.NewTokenSpec(pf.identity, pf.appID))
|
|
if err != nil || result == nil || result.Scopes == "" {
|
|
return false, nil //nolint:nilerr // best-effort: the bus handshake surfaces the real auth error
|
|
}
|
|
storedScopes = result.Scopes
|
|
default:
|
|
return false, nil
|
|
}
|
|
|
|
missing := auth.MissingScopes(storedScopes, pf.keyDef.Scopes)
|
|
if len(missing) == 0 {
|
|
return true, nil
|
|
}
|
|
permissionErr := errs.NewPermissionError(errs.SubtypeMissingScope,
|
|
"missing required scopes for EventKey %s (as %s): %s",
|
|
pf.eventKey, pf.identity, strings.Join(missing, ", ")).
|
|
WithIdentity(string(pf.identity)).
|
|
WithMissingScopes(missing...)
|
|
if pf.identity.IsBot() {
|
|
permissionErr.WithHint("%s", botScopeRemediationHint(pf.brand, pf.appID, missing))
|
|
}
|
|
// The scope check itself completed, so the precondition is answered even
|
|
// though it answered "missing". A user-identity hint is deliberately left
|
|
// unset: the root presenter generates it from the identity and missing
|
|
// scopes, projected onto the commands this distribution actually ships.
|
|
return true, permissionErr
|
|
}
|
|
|
|
// scopeRemediationHint returns an identity-appropriate fix for missing scopes.
|
|
// The bot-specific scan-to-enable link adds the scopes to the app manifest,
|
|
// after which the tenant token carries them. User recovery is generated from
|
|
// the PermissionError's identity and missing_scopes by the root presenter.
|
|
func botScopeRemediationHint(brand core.LarkBrand, appID string, missing []string) string {
|
|
return fmt.Sprintf("grant these scopes by scanning: %s",
|
|
addonsHintURL(brand, appID, missingScopeAddons(core.AsBot, missing)))
|
|
}
|
|
|
|
// preflightEventTypes verifies every RequiredConsoleEvents entry is subscribed
|
|
// in the app's console 底账 — published app_versions for event subscriptions,
|
|
// application/get subscribed_callbacks for callback subscriptions.
|
|
func preflightEventTypes(pf *preflightCtx) error {
|
|
if len(pf.keyDef.RequiredConsoleEvents) == 0 {
|
|
return nil
|
|
}
|
|
|
|
var subscribed []string
|
|
noun := "event types"
|
|
if pf.keyDef.SubscriptionType == eventlib.SubTypeCallback {
|
|
if pf.subscribedCallbacks == nil {
|
|
return nil
|
|
}
|
|
subscribed = pf.subscribedCallbacks
|
|
noun = "callbacks"
|
|
} else {
|
|
if pf.appVer == nil {
|
|
return nil
|
|
}
|
|
subscribed = pf.appVer.EventTypes
|
|
}
|
|
|
|
have := make(map[string]bool, len(subscribed))
|
|
for _, t := range subscribed {
|
|
have[t] = true
|
|
}
|
|
var missing []string
|
|
for _, t := range pf.keyDef.RequiredConsoleEvents {
|
|
if !have[t] {
|
|
missing = append(missing, t)
|
|
}
|
|
}
|
|
if len(missing) == 0 {
|
|
return nil
|
|
}
|
|
|
|
url := addonsHintURL(pf.brand, pf.appID, missingSubscriptionAddons(pf.keyDef.SubscriptionType, pf.identity, missing))
|
|
return errs.NewValidationError(errs.SubtypeFailedPrecondition,
|
|
"EventKey %s requires %s not subscribed in console: %s",
|
|
pf.keyDef.Key, noun, strings.Join(missing, ", ")).
|
|
WithHint("subscribe these %s by scanning: %s", noun, url)
|
|
}
|
|
|
|
// sanitizeOutputDir defers to the built-in path policy (SafeOutputPath):
|
|
// allowed roots are cwd, /tmp, and ~/files; the denylist wins over all.
|
|
func sanitizeOutputDir(dir string) (string, error) {
|
|
safe, err := validate.SafeOutputPath(dir)
|
|
if err != nil {
|
|
return "", errs.NewValidationError(errs.SubtypeInvalidArgument,
|
|
"%s %q: %s", errOutputDirUnsafe, dir, err).
|
|
WithParam("--output-dir").
|
|
WithCause(errOutputDirUnsafe)
|
|
}
|
|
return safe, nil
|
|
}
|
|
|
|
// resolveTenantToken fetches the app's tenant access token.
|
|
func resolveTenantToken(ctx context.Context, f *cmdutil.Factory, appID string) (string, error) {
|
|
if ctx == nil {
|
|
ctx = context.Background()
|
|
}
|
|
result, err := f.Credential.ResolveToken(ctx, credential.NewTokenSpec(core.AsBot, appID))
|
|
if err != nil {
|
|
if _, ok := errs.ProblemOf(err); ok {
|
|
return "", err
|
|
}
|
|
return "", errs.NewAuthenticationError(errs.SubtypeTokenMissing,
|
|
"resolve tenant access token: %s", err).WithCause(err)
|
|
}
|
|
if result == nil || result.Token == "" {
|
|
return "", errs.NewAuthenticationError(errs.SubtypeTokenMissing,
|
|
"no tenant access token available for app %s", appID).
|
|
WithHint("check that app_secret is configured for this distribution")
|
|
}
|
|
return result.Token, nil
|
|
}
|
|
|
|
// Sentinels for errors.Is checks; call sites wrap them as typed ValidationError causes.
|
|
var (
|
|
errInvalidParamFormat = errors.New("invalid --param format") //nolint:forbidigo // sentinel, typed at call sites
|
|
errOutputDirUnsafe = errors.New("unsafe --output-dir") //nolint:forbidigo // sentinel, typed at call sites
|
|
)
|
|
|
|
func parseParams(raw []string) (map[string]string, error) {
|
|
m := make(map[string]string)
|
|
for _, kv := range raw {
|
|
k, v, ok := strings.Cut(kv, "=")
|
|
if !ok || k == "" {
|
|
return nil, errs.NewValidationError(errs.SubtypeInvalidArgument,
|
|
"%s %q: expected key=value", errInvalidParamFormat, kv).
|
|
WithParam("--param").
|
|
WithCause(errInvalidParamFormat)
|
|
}
|
|
m[k] = v
|
|
}
|
|
return m, nil
|
|
}
|
|
|
|
// watchStdinEOF drains r until EOF, writes a diagnostic, then cancels; only safe in non-TTY mode.
|
|
func watchStdinEOF(r io.Reader, cancel context.CancelFunc, errOut io.Writer) {
|
|
go func() {
|
|
_, _ = io.Copy(io.Discard, r)
|
|
fmt.Fprintln(errOut, "[event] stdin closed — shutting down. "+
|
|
"consume treats stdin EOF as exit signal (wired for AI subprocess callers). "+
|
|
"To keep running: pass --max-events/--timeout for bounded run, "+
|
|
"or keep stdin open (e.g. `< /dev/tty` interactive, `< <(tail -f /dev/null)` script), "+
|
|
"or stop via SIGTERM instead of closing stdin.")
|
|
cancel()
|
|
}()
|
|
}
|
|
|
|
// shouldWatchStdinEOF gates the stdin-EOF shutdown watcher: non-TTY unbounded runs only (<= 0 mirrors downstream's >0-is-bounded semantics, so negative bounds stay unbounded).
|
|
func shouldWatchStdinEOF(isTerminal bool, maxEvents int, timeout time.Duration) bool {
|
|
return !isTerminal && maxEvents <= 0 && timeout <= 0
|
|
}
|