mirror of
https://github.com/infiniflow/ragflow.git
synced 2026-07-22 16:36:47 +08:00
Fix: missing authorization checks in /files/link-to-datasets (#14649)
### Related issues Closes #14648 ### What problem does this PR solve? This PR fixes an authorization flaw in `POST /files/link-to-datasets`. Before this change, the endpoint only checked whether the supplied `file_ids` and `kb_ids` existed. It did not verify whether the authenticated user was actually allowed to access those files or target datasets. As a result, an authenticated user who knew valid IDs could relink another user's files to arbitrary datasets. This was especially risky because the relinking flow is state-changing: the background worker removes existing file-document mappings and then recreates documents under the attacker-supplied dataset IDs. This change makes the route enforce the same permission model already used by nearby file and document operations: - each resolved file must pass `check_file_team_permission(...)` - each target dataset must pass `check_kb_team_permission(...)` - authorization is enforced before scheduling background relinking work ### Type of change - [x] Bug Fix (non-breaking change which fixes an issue) - [ ] New Feature (non-breaking change which adds functionality) - [ ] Documentation Update - [ ] Refactoring - [ ] Performance Improvement - [ ] Other (please describe): ### Testing - Added regression coverage in `test/testcases/test_web_api/test_file_app/test_file2document_routes_unit.py` - Covered: - unauthorized file access is rejected - unauthorized dataset access is rejected - existing success path still returns immediately after scheduling background work - Attempted to run: - `python -m pytest test\\testcases\\test_web_api\\test_file_app\\test_file2document_routes_unit.py -q` - Local execution in this workspace is currently blocked by missing test dependencies during bootstrap, including `ragflow_sdk` --------- Co-authored-by: jony376 <jony376@gmail.com>
This commit is contained in:
@@ -18,6 +18,7 @@ import asyncio
|
||||
import logging
|
||||
from pathlib import Path
|
||||
|
||||
from api.common.check_team_permission import check_file_team_permission, check_kb_team_permission
|
||||
from api.db.services.file2document_service import File2DocumentService
|
||||
from api.db.services.file_service import FileService
|
||||
|
||||
@@ -28,6 +29,8 @@ from common.misc_utils import get_uuid
|
||||
from api.db import FileType
|
||||
from api.db.services.document_service import DocumentService
|
||||
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
|
||||
def _convert_files(file_ids, kb_ids, user_id):
|
||||
"""Synchronous worker: delete old docs and insert new ones for the given file/kb pairs."""
|
||||
@@ -88,13 +91,29 @@ async def convert():
|
||||
# Validate all files exist before starting any work
|
||||
for file_id in file_ids:
|
||||
if not files_set.get(file_id):
|
||||
logger.warning(
|
||||
"user_id=%s resource_type=file resource_id=%s action=validate_file_lookup result=not_found file_ids=%s kb_ids=%s",
|
||||
current_user.id,
|
||||
file_id,
|
||||
file_ids,
|
||||
kb_ids,
|
||||
)
|
||||
return get_data_error_result(message="File not found!")
|
||||
|
||||
# Validate all kb_ids exist before scheduling background work
|
||||
kb_map = {}
|
||||
for kb_id in kb_ids:
|
||||
e, _ = KnowledgebaseService.get_by_id(kb_id)
|
||||
e, kb = KnowledgebaseService.get_by_id(kb_id)
|
||||
if not e:
|
||||
logger.warning(
|
||||
"user_id=%s resource_type=dataset resource_id=%s action=validate_dataset_lookup result=not_found file_ids=%s kb_ids=%s",
|
||||
current_user.id,
|
||||
kb_id,
|
||||
file_ids,
|
||||
kb_ids,
|
||||
)
|
||||
return get_data_error_result(message="Can't find this dataset!")
|
||||
kb_map[kb_id] = kb
|
||||
|
||||
# Expand folders to their innermost file IDs
|
||||
all_file_ids = []
|
||||
@@ -106,6 +125,38 @@ async def convert():
|
||||
all_file_ids.append(file_id)
|
||||
|
||||
user_id = current_user.id
|
||||
for file_id in all_file_ids:
|
||||
e, file = FileService.get_by_id(file_id)
|
||||
if not e or not file:
|
||||
logger.warning(
|
||||
"user_id=%s resource_type=file resource_id=%s action=validate_expanded_file_lookup result=not_found file_ids=%s kb_ids=%s",
|
||||
user_id,
|
||||
file_id,
|
||||
file_ids,
|
||||
kb_ids,
|
||||
)
|
||||
return get_data_error_result(message="File not found!")
|
||||
if not check_file_team_permission(file, user_id):
|
||||
logger.warning(
|
||||
"user_id=%s resource_type=file resource_id=%s action=authorize_file result=denied file_ids=%s kb_ids=%s",
|
||||
user_id,
|
||||
file_id,
|
||||
file_ids,
|
||||
kb_ids,
|
||||
)
|
||||
return get_data_error_result(message="No authorization.")
|
||||
|
||||
for kb_id, kb in kb_map.items():
|
||||
if not check_kb_team_permission(kb, user_id):
|
||||
logger.warning(
|
||||
"user_id=%s resource_type=dataset resource_id=%s action=authorize_dataset result=denied file_ids=%s kb_ids=%s",
|
||||
user_id,
|
||||
kb_id,
|
||||
file_ids,
|
||||
kb_ids,
|
||||
)
|
||||
return get_data_error_result(message="No authorization.")
|
||||
|
||||
# Run the blocking DB work in a thread so the event loop is not blocked.
|
||||
# For large folders this prevents 504 Gateway Timeout by returning as
|
||||
# soon as the background task is scheduled.
|
||||
@@ -114,6 +165,12 @@ async def convert():
|
||||
future.add_done_callback(
|
||||
lambda f: logging.error("_convert_files failed: %s", f.exception()) if f.exception() else None
|
||||
)
|
||||
logger.info(
|
||||
"user_id=%s resource_type=file_to_dataset_link resource_id=batch action=schedule_convert result=scheduled file_ids=%s kb_ids=%s",
|
||||
user_id,
|
||||
all_file_ids,
|
||||
kb_ids,
|
||||
)
|
||||
return get_json_result(data=True)
|
||||
except Exception as e:
|
||||
return server_error_response(e)
|
||||
|
||||
Reference in New Issue
Block a user