fix: code review fixes — auth gap, path traversal, dead code, health-check timeout
- backend/app.py: add Depends(_require_auth) to /api/copilotkit endpoint (critical security fix — endpoint was fully unprotected; now requires valid session cookie) - backend/app.py: move 'from ag_ui.core import RunStartedEvent' from inline function body to top-level imports (style consistency) - backend/auth.py: remove dead AUTH_PASS_HASH module-level constant (verify_password already reads from os.environ at call time; the cached binding was unused dead code) - backend/artifacts.py: add path traversal guards to list_artifacts, get_artifact, and save_artifact — resolve paths and verify they stay within ARTIFACTS_DIR - entrypoint.sh: health-check loop now sets READY flag and exits 1 if amplifierd fails to start within 30s (previously fell through silently, causing 502s) - tests/test_app.py: add TestCopilotKitAuth — verifies unauthenticated requests to /api/copilotkit return 401; includes note explaining why streaming is not tested here - tests/test_structure.sh: update to reflect that Dockerfile and entrypoint.sh now exist (created in Tasks 7+8); convert absent-checks to presence-checks Co-authored-by: Amplifier <amplifier@anthropic.com>
This commit is contained in:
+6
-4
@@ -12,6 +12,7 @@ from pathlib import Path
|
||||
from typing import Any, AsyncGenerator
|
||||
|
||||
import httpx
|
||||
from ag_ui.core import RunStartedEvent
|
||||
from fastapi import Cookie, Depends, FastAPI, HTTPException, Request, Response
|
||||
from fastapi.middleware.cors import CORSMiddleware
|
||||
from fastapi.responses import HTMLResponse, JSONResponse, StreamingResponse
|
||||
@@ -234,14 +235,15 @@ async def get_transcript(
|
||||
|
||||
|
||||
@app.post("/api/copilotkit")
|
||||
async def copilotkit(request: Request) -> StreamingResponse:
|
||||
async def copilotkit(
|
||||
request: Request,
|
||||
email: str = Depends(_require_auth),
|
||||
) -> StreamingResponse:
|
||||
"""AG-UI streaming endpoint.
|
||||
|
||||
Accepts CopilotKit protocol payload, executes via amplifierd, and streams
|
||||
AG-UI SSE events back to the client.
|
||||
AG-UI SSE events back to the client. Requires a valid session cookie.
|
||||
"""
|
||||
from ag_ui.core import RunStartedEvent
|
||||
|
||||
body = await request.json()
|
||||
thread_id: str = body.get("threadId", str(uuid.uuid4()))
|
||||
run_id: str = body.get("runId", str(uuid.uuid4()))
|
||||
|
||||
Reference in New Issue
Block a user