fix(security): 16 mittlere Probleme behoben (P18-P33)
Check Cross-Plugin Imports / check (push) Has been cancelled
Check Cross-Plugin Imports / check (push) Has been cancelled
P18: require_permission zu forgejo_error_reporter und ai_ui_control routes hinzugefügt P19: Cross-Tenant Permission-Cache-Invalidierung bei Rollenänderungen P20: Session/Permission-Cache-Invalidierung bei Gruppen-Änderungen P21: ENTITY_MODELS Registry um fehlende Plugin-Modelle erweitert P22: Entity-Links prüfen verknüpfte Entity-Permissions P23: authStore persist Middleware entfernt (kein localStorage mehr) P24: 5xx Retry nur noch für GET-Requests P25: KI-Kommentar in address.py (bekannte Inkonsistenz) P26: DeletionLog in EntityHistory gemerged (action=delete) P27: KI-Kommentar in entity_policy.py (ABAC nicht aktiv genutzt) P28: db.commit() aus bulk_permission_service entfernt P29: CSV-Export in export_service.py ausgelagert P30: plugins.py Business-Logik in plugin_install_service.py ausgelagert P31: KI-Kommentar in session.py (Dual-System dokumentiert) P32: Migration 0115: crm_platform_admin Role droppen P33: Cross-Plugin Imports über contracts.py behoben (10 Violations → 0)
This commit is contained in:
@@ -14,6 +14,7 @@ import uuid
|
||||
from fastapi import APIRouter, WebSocket, WebSocketDisconnect, Depends, HTTPException, Request
|
||||
from fastapi.responses import JSONResponse
|
||||
|
||||
from app.deps import require_permission
|
||||
from app.plugins.builtins.ai_ui_control.schemas import (
|
||||
UICommand,
|
||||
UICommandCreate,
|
||||
@@ -31,7 +32,7 @@ router = APIRouter(prefix="/api/v1/ai-ui-control", tags=["ai-ui-control"])
|
||||
|
||||
# ─── REST endpoints (for AI agents) ───
|
||||
|
||||
@router.post("/command", response_model=UICommandResponse)
|
||||
@router.post("/command", response_model=UICommandResponse, dependencies=[Depends(require_permission("ai_ui_control:write"))])
|
||||
async def send_ui_command(
|
||||
request: Request,
|
||||
body: UICommandCreate,
|
||||
@@ -168,7 +169,7 @@ async def get_command_status(
|
||||
)
|
||||
|
||||
|
||||
@router.get("/online-users")
|
||||
@router.get("/online-users", dependencies=[Depends(require_permission("ai_ui_control:read"))])
|
||||
async def get_online_users(request: Request):
|
||||
"""Check which users are currently online (have active frontend WS connections)."""
|
||||
from app.config import get_settings
|
||||
|
||||
Reference in New Issue
Block a user