mirror of
https://github.com/tiennm99/goclaw.git
synced 2026-10-04 14:13:15 +00:00
* refactor(bitrix24): rename "Path B" framing to maintainer-specified naming [B24:2794] Per maintainer hard rule #10 (no generic "Path A/B" framing) from PR #1061 review. The Bitrix24 MCP auto-onboard flow is Bitrix-specific glue ("Bitrix24 OAuth -> existing mcp_user_credentials bridge"), NOT a generic MCP architecture pattern. Naming convention applied consistently: - First mention per file: full "Bitrix24 OAuth -> existing mcp_user_credentials bridge" (matches maintainer comment verbatim). - Subsequent mentions in same file: shortened "mcp_user_credentials bridge". - Test/log context referencing literal endpoint /api/auto-onboard: keep "auto-onboard" reference (it's the actual API endpoint name). Changes are documentation-only: - Rename in code comments + test descriptions + plan docs. - Clarify framing in mcp_client.go + provisioner.go doc comments to emphasize Bitrix-specific glue (not generic MCP infra). - Reuse existing mcp_user_credentials table + MCPServerStore methods (no schema / store / abstraction change). Files: - cmd/gateway.go (factory registration doc) - internal/channels/bitrix24/{channel,factory,mcp_client,provisioner}.go - internal/channels/bitrix24/{mcp_client,provisioner}_test.go - plan/goclaw-mcp-integration.md (21 occurrences) Verified: go build + MCP-related tests pass (TestProvision*, TestInitMCPProvisioner*, TestMCPClient*). Phase 1 of Path C execution per plans/reports/decision-log-260519-1555-bitrix24-pr-fork-decision.md. * fix: confine outbound media paths to agent workspace [B24:2794] Tool MEDIA:<path> output reached channel file-upload sinks (Bitrix imbot.v2.File.upload, Telegram sendDocument, etc.) verbatim via parseMediaResult, with no workspace-boundary check. A malicious or buggy tool emitting MEDIA:/etc/passwd could exfiltrate arbitrary files to chat. Extract the EvalSymlinks+Rel containment from extractMediaFromContent into a shared confineToWorkspace helper and apply it at the parseMediaResult sink in processToolResult. Fixing at the source/egress boundary protects every channel at once rather than per-channel. Paths that escape the workspace are dropped and logged (security.media_path_rejected). Add TestConfineToWorkspace (boundary unit) and TestParseMediaResultConfinedToWorkspace (sink regression for H2). * feat(bitrix24): support inbound + outbound media via imbot.v2 File API [B24:2794] Bitrix24 channel was text-only; attachments were parsed but dropped. - Inbound: download chat files via imbot.v2.File.download (one-time URL), forward to the agent with MIME preserved (internal/channels/bitrix24/download.go). - Outbound: upload agent media to the chat via imbot.v2.File.upload (internal/channels/bitrix24/send_media.go). - Add BaseChannel.HandleMessageMedia to preserve MIME/filename through the bus. - Per-channel media_max_mb cap (default 20) applies to both directions. Tests: 92 pass (internal/channels/bitrix24 + internal/channels), go vet clean (PG + sqliteonly). * refactor(bitrix24): migrate messaging/bot-list/unregister to imbot v2 API [B24:2794] Move outbound REST calls to the imbot v2 family (keeps register on v1): - imbot.message.add -> imbot.v2.Chat.Message.send (fields.message shape, live-verified) - imbot.bot.list (+ legacy imbot.list fallback) -> imbot.v2.Bot.list; add botListRows to normalize the v2 {bots:[...]} envelope, legacy array, and id-keyed map forms - imbot.unregister -> imbot.v2.Bot.unregister Bot registration stays on v1 imbot.register: v2 imbot.v2.Bot.register changes the event-delivery model (per-event handler URLs -> eventMode), which would require rewriting the inbound event parser. No user-facing behavior change. Tests: bitrix24 package green; go vet ./... clean. * feat(bitrix24): route whisper via v1 SKIP_CONNECTOR + add v2 replyId [B24:2794] Bot was leaking HiddenMessage (whisper) replies to the external Zalo connector because every outbound call went through imbot.v2.Chat.Message.send, which has no equivalent of the v1 SKIP_CONNECTOR flag. Branch the outbound path on inbound visibility: whisper → imbot.message.add + SKIP_CONNECTOR=Y (v1, send_v1.go) public → imbot.v2.Chat.Message.send + fields.replyId (v2, send_v2.go) Pipeline: events.go parse data[PARAMS][PARAMS][COMPONENT_ID]=HiddenMessage into EventParams.IsHiddenMessage (form + JSON variants) handle.go set bitrix_visibility on InboundMessage.Metadata consumer forward visibility + message_id into OutboundMessage send.go resolveSendOptions + sendChunk dispatcher + shared callWithRateLimitRetry helper metadata_keys.go single source of truth for the keys + values Defaults preserve pre-refactor behaviour: callers that don't populate bitrix_visibility still go through v2 public, and replyId is omitted unless a numeric bitrix_message_id arrives in metadata. Tests: TestParseEvent_FormURLEncoded_IsHiddenMessage (3 cases) TestParseEvent_JSON_IsHiddenMessage (3 cases) TestResolveSendOptions (8 cases) TestSend_BranchesOnVisibility (4 cases) * feat(bitrix24): openline sender-tag echo on replies [B24:2794] Openline sender-tag echo (this change): - Capture the connector sender tag ("[name #id]:" or "[name] #id:") from inbound openline group messages, strip it from the body the agent sees, and re-prepend the canonical "[name] #id:" form to the reply so the Open Channel connector routes the answer back to the right external user. - New sender_prefix.go helper (+ test) accepts both inbound layouts and emits one canonical form; scoped to messages carrying the tag, so plain chats are unaffected. - metadata_keys.go: MetaKeySenderPrefix; handle.go capture/strip/stash; gateway_consumer_normal.go forwards the key; send.go prepends it on the first chunk before chunking. Bundled bitrix24 channel-core work already on this branch: - handle.go: @mention is the sole trigger for both staff and connector customers; unmentioned traffic is dropped (was: drop all connector msgs). - isGroupMessageType: treat SONET_GROUP "B" as a group. - handle_test.go, mcp_client_test.go: cover the above. * feat(bitrix24): accept colon-less openline sender tag, echo [name] #id [B24:2794] The Open Channel connector dropped the trailing colon from its sender tag: inbound now arrives as "[Name] #id <msg>" (was "[Name] #id: <msg>"). The id-bearing patterns required the colon, so the tag fell through to the name-only branch and the reply echoed "[Name]" — dropping the #id the connector needs to route the answer back. - sender_prefix.go: make the trailing ":" optional on both id layouts ([name #id] / [name] #id, with or without colon) and echo the canonical "[name] #id" (no colon) to match the connector's current format. Bare "[name]" (no id) still echoes "[name]" for Open Channel only. - handle.go: gate the bare name-only layout to Open Channel (isOpenChannel) so ordinary group chats starting with "[x] ..." are left untouched. - sender_prefix_test.go: cover colon/no-colon x id-inside/id-outside, the name-only openline case, and the non-openline no-op. * fix: security and robustness fixes from the bitrix24 channel review [B24:2794] - download.go: block redirect-based SSRF on inbound media. CheckRedirect re-validates each hop (http(s) only, reject private/loopback/link-local hosts, cap hops); the initial portal-domain pin is no longer bypassable via a 3xx to an internal service. Public-host redirects still allowed. - handle.go: extract/echo the openline sender tag only for Open Channel sessions (was: any group chat), removing bogus prefixes in CRM group chats and narrowing the forged-tag misroute surface. - loop_tools.go + loop_media.go: confine result.Media to the agent / team / tenant-allowed roots (new confineToAnyRoot) before a channel uploads it, so a prompt-injected out-of-workspace path (e.g. /etc/passwd) cannot exfiltrate, while legitimate cross-workspace media (team files, delegatee output) still flows. - send_media.go: bounded outbound read via io.LimitReader replaces the os.Stat + os.ReadFile pair, closing the TOCTOU size-cap bypass; cap a single message's outbound attachments at 10 (mirrors inbound). - register.go: paginate imbot.v2.Bot.list (limit/offset + hasNextPage, capped at 40 pages) so verify/lookup see bots past the first 50. - mcp_client.go: redact access_token / refresh_token / client_secret from an echoed MCP error body before it is logged or returned (+ test). * fix(security): validate resolved dial IP on Bitrix media redirects [B24:2794] The inbound media download redirect guard only string-checked the redirect hostname (isPrivateOrLoopback on req.URL.Hostname()), so a redirect to a public hostname that resolves to 127.0.0.1 / 169.254.169.254 / an RFC1918 address — or a DNS-rebinding swap between check and dial — still passed the guard and the client would connect. Reported in PR review. Add security.NewRedirectFollowingSafeClient: it follows redirects but validates the RESOLVED destination IP of every hop at dial time via net.Dialer.Control, reusing the existing blocked-CIDR list. The IP it checks is the IP actually dialed, so both redirect-to-internal and DNS rebinding are refused, while legitimate public CDN redirects still succeed. download.go now uses it instead of the hostname-string guard. Tests: deterministic dial-control table (loopback / link-local / private / multicast / unspecified / public, v4 + v6), malformed/non-IP addr, test bypass, loopback-dial-blocked client wiring, and redirect cap + scheme checks. * feat(bitrix24): per-participant Zalo openline identity from 3-token sender tag [B24:2794] Parse the connector's "[Name] #uid #msgId" sender tag so each external customer in a shared Open Channel group gets its own contact + USER.md instead of collapsing onto the connector proxy id. Identity minting is gated on IS_CONNECTOR=Y to reject operator forged tags. Echo back the msgId only ("#msgId") on replies; keep the legacy single-number and name-only layouts unchanged. Zero DB migration. - sender_prefix.go: parseOpenlineSenderTag() classifies 3-token / legacy / name-only - handle.go: synthetic senderID "openlines:{instance}:{chat}:{uid}" + participant_user_id metadata, gated on FromIsConnector - gateway_consumer_normal.go: deriveGroupUserID() routes participant -> per-person scope, group fallback otherwise - send.go: buildAddressMention numeric-id guard so synthetic ids don't emit invalid [USER=...] BBCode - MetaKeyMessageID kept as Bitrix MESSAGE_ID (drives v2 fields.replyId); connector msgId surfaced only via echo prefix --------- Co-authored-by: DangTinh311 <dangtinh31193@gmail.com> Co-authored-by: Chinh Dang <chinhdang@192.168.68.104>
259 lines
8.0 KiB
Go
259 lines
8.0 KiB
Go
package agent
|
|
|
|
import (
|
|
"os"
|
|
"path/filepath"
|
|
"testing"
|
|
)
|
|
|
|
// writeTempFile drops a zero-byte file at workspace/relPath, creating dirs.
|
|
func writeTempFile(t *testing.T, workspace, relPath string) string {
|
|
t.Helper()
|
|
full := filepath.Join(workspace, relPath)
|
|
if err := os.MkdirAll(filepath.Dir(full), 0o755); err != nil {
|
|
t.Fatalf("mkdir: %v", err)
|
|
}
|
|
if err := os.WriteFile(full, nil, 0o644); err != nil {
|
|
t.Fatalf("write: %v", err)
|
|
}
|
|
return full
|
|
}
|
|
|
|
func TestExtractMediaFromContent(t *testing.T) {
|
|
wsRaw := t.TempDir()
|
|
// Resolve workspace symlinks up front (macOS has /var → /private/var) so
|
|
// expected paths match what the extractor returns after EvalSymlinks.
|
|
ws, err := filepath.EvalSymlinks(wsRaw)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
reportPath := writeTempFile(t, ws, "deliver/report.pdf")
|
|
audioA := writeTempFile(t, ws, "a.mp3")
|
|
audioB := writeTempFile(t, ws, "b.mp3")
|
|
chartPath := writeTempFile(t, ws, "charts/q4.png")
|
|
|
|
// Outside-workspace file: should be rejected by containment check.
|
|
outsideDir := t.TempDir()
|
|
outsidePath := filepath.Join(outsideDir, "leak.pdf")
|
|
if err := os.WriteFile(outsidePath, nil, 0o644); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
|
|
// Symlink inside workspace pointing to outside: must be rejected by
|
|
// EvalSymlinks-then-Rel containment. Covers the P0 ancestor-symlink
|
|
// escape the lexical-only Rel check would have allowed.
|
|
symlinkFile := filepath.Join(ws, "shortcut-to-leak.pdf")
|
|
if err := os.Symlink(outsidePath, symlinkFile); err != nil {
|
|
t.Skipf("symlink not supported: %v", err)
|
|
}
|
|
// Ancestor symlink case: dir symlink inside ws pointing outside.
|
|
symDirParent := t.TempDir()
|
|
if err := os.WriteFile(filepath.Join(symDirParent, "victim.pdf"), nil, 0o644); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
ancestorSym := filepath.Join(ws, "shared")
|
|
if err := os.Symlink(symDirParent, ancestorSym); err != nil {
|
|
t.Skipf("symlink not supported: %v", err)
|
|
}
|
|
|
|
tests := []struct {
|
|
name string
|
|
content string
|
|
workspace string
|
|
wantPaths []string
|
|
}{
|
|
{
|
|
name: "empty content",
|
|
content: "",
|
|
},
|
|
{
|
|
name: "no media prefix",
|
|
content: "Just a regular response with no attachments.",
|
|
},
|
|
{
|
|
name: "relative path resolved + exists",
|
|
content: "MEDIA:deliver/report.pdf",
|
|
workspace: ws,
|
|
wantPaths: []string{reportPath},
|
|
},
|
|
{
|
|
name: "multiple tokens deduped",
|
|
content: "First: MEDIA:a.mp3\nSecond: MEDIA:b.mp3\nAgain: MEDIA:a.mp3",
|
|
workspace: ws,
|
|
wantPaths: []string{audioA, audioB},
|
|
},
|
|
{
|
|
name: "markdown wrapped and punctuation stripped",
|
|
content: `. See "MEDIA:deliver/report.pdf".`,
|
|
workspace: ws,
|
|
wantPaths: []string{chartPath, reportPath},
|
|
},
|
|
{
|
|
name: "hallucinated path dropped (file missing)",
|
|
content: "MEDIA:not-real.pdf",
|
|
workspace: ws,
|
|
},
|
|
{
|
|
name: "path traversal escape blocked",
|
|
content: "MEDIA:../leak.pdf",
|
|
workspace: ws,
|
|
},
|
|
{
|
|
name: "absolute path outside workspace blocked",
|
|
content: "MEDIA:" + outsidePath,
|
|
workspace: ws,
|
|
},
|
|
{
|
|
name: "absolute path with no workspace dropped",
|
|
content: "MEDIA:" + reportPath,
|
|
},
|
|
{
|
|
name: "symlink leaf rejected by Lstat",
|
|
content: "MEDIA:shortcut-to-leak.pdf",
|
|
workspace: ws,
|
|
},
|
|
{
|
|
name: "ancestor symlink escape blocked (P0)",
|
|
content: "MEDIA:shared/victim.pdf",
|
|
workspace: ws,
|
|
},
|
|
}
|
|
for _, tt := range tests {
|
|
t.Run(tt.name, func(t *testing.T) {
|
|
got := extractMediaFromContent(tt.content, tt.workspace)
|
|
if len(got) != len(tt.wantPaths) {
|
|
t.Fatalf("count = %d, want %d; got=%+v", len(got), len(tt.wantPaths), got)
|
|
}
|
|
for i, want := range tt.wantPaths {
|
|
if got[i].Path != want {
|
|
t.Errorf("path[%d] = %q, want %q", i, got[i].Path, want)
|
|
}
|
|
}
|
|
})
|
|
}
|
|
}
|
|
|
|
// TestConfineToWorkspace exercises the shared media path-containment boundary
|
|
// directly. It is the single guard that both feeders of MediaResult.Path rely
|
|
// on, so a regression here would reopen the outbound-exfiltration hole (H2).
|
|
func TestConfineToWorkspace(t *testing.T) {
|
|
wsRaw := t.TempDir()
|
|
ws, err := filepath.EvalSymlinks(wsRaw)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
insidePath := writeTempFile(t, ws, "deliver/report.pdf")
|
|
|
|
// File outside the workspace (stands in for /etc/passwd).
|
|
outsideDir := t.TempDir()
|
|
outsidePath := filepath.Join(outsideDir, "secret.txt")
|
|
if err := os.WriteFile(outsidePath, nil, 0o644); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
|
|
// Leaf symlink inside ws pointing outside: must be rejected by Lstat.
|
|
leafSymlink := filepath.Join(ws, "shortcut.txt")
|
|
symlinkSupported := os.Symlink(outsidePath, leafSymlink) == nil
|
|
|
|
// Ancestor dir symlink inside ws pointing outside.
|
|
symDirParent := t.TempDir()
|
|
if err := os.WriteFile(filepath.Join(symDirParent, "victim.txt"), nil, 0o644); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
ancestorSym := filepath.Join(ws, "shared")
|
|
if symlinkSupported {
|
|
if err := os.Symlink(symDirParent, ancestorSym); err != nil {
|
|
symlinkSupported = false
|
|
}
|
|
}
|
|
|
|
tests := []struct {
|
|
name string
|
|
path string
|
|
workspace string
|
|
wantOK bool
|
|
wantPath string
|
|
symlink bool // requires symlink support
|
|
}{
|
|
{name: "relative inside workspace", path: "deliver/report.pdf", workspace: ws, wantOK: true, wantPath: insidePath},
|
|
{name: "absolute inside workspace", path: insidePath, workspace: ws, wantOK: true, wantPath: insidePath},
|
|
{name: "absolute outside workspace rejected", path: outsidePath, workspace: ws, wantOK: false},
|
|
{name: "traversal escape rejected", path: "../secret.txt", workspace: ws, wantOK: false},
|
|
{name: "missing file rejected", path: "nope.pdf", workspace: ws, wantOK: false},
|
|
{name: "empty workspace rejected", path: insidePath, workspace: "", wantOK: false},
|
|
{name: "empty path rejected", path: "", workspace: ws, wantOK: false},
|
|
{name: "leaf symlink rejected", path: "shortcut.txt", workspace: ws, wantOK: false, symlink: true},
|
|
{name: "ancestor symlink escape rejected", path: "shared/victim.txt", workspace: ws, wantOK: false, symlink: true},
|
|
}
|
|
for _, tt := range tests {
|
|
t.Run(tt.name, func(t *testing.T) {
|
|
if tt.symlink && !symlinkSupported {
|
|
t.Skip("symlinks not supported on this platform")
|
|
}
|
|
got, ok := confineToWorkspace(tt.path, tt.workspace)
|
|
if ok != tt.wantOK {
|
|
t.Fatalf("ok = %v, want %v (got path %q)", ok, tt.wantOK, got)
|
|
}
|
|
if tt.wantOK && got != tt.wantPath {
|
|
t.Errorf("path = %q, want %q", got, tt.wantPath)
|
|
}
|
|
})
|
|
}
|
|
}
|
|
|
|
// TestParseMediaResultConfinedToWorkspace reproduces the processToolResult sink
|
|
// (parseMediaResult → confineToWorkspace) and asserts that a tool emitting a
|
|
// MEDIA: path outside the agent workspace is dropped, not shipped to a channel.
|
|
// This is the regression guard for H2: MEDIA:/etc/passwd must never become an
|
|
// outbound MediaResult.
|
|
func TestParseMediaResultConfinedToWorkspace(t *testing.T) {
|
|
wsRaw := t.TempDir()
|
|
ws, err := filepath.EvalSymlinks(wsRaw)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
insidePath := writeTempFile(t, ws, "chart.png")
|
|
|
|
outsideDir := t.TempDir()
|
|
outsidePath := filepath.Join(outsideDir, "passwd")
|
|
if err := os.WriteFile(outsidePath, nil, 0o644); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
|
|
// confineSink mirrors the loop_tools.go branch: parse, then confine.
|
|
confineSink := func(toolOutput string) (MediaResult, bool) {
|
|
mr := parseMediaResult(toolOutput)
|
|
if mr == nil {
|
|
return MediaResult{}, false
|
|
}
|
|
cleaned, ok := confineToWorkspace(mr.Path, ws)
|
|
if !ok {
|
|
return MediaResult{}, false
|
|
}
|
|
mr.Path = cleaned
|
|
return *mr, true
|
|
}
|
|
|
|
t.Run("inside workspace shipped", func(t *testing.T) {
|
|
got, ok := confineSink("MEDIA:" + insidePath)
|
|
if !ok {
|
|
t.Fatal("expected in-workspace media to be shipped")
|
|
}
|
|
if got.Path != insidePath {
|
|
t.Errorf("path = %q, want %q", got.Path, insidePath)
|
|
}
|
|
})
|
|
|
|
t.Run("outside workspace dropped", func(t *testing.T) {
|
|
if _, ok := confineSink("MEDIA:" + outsidePath); ok {
|
|
t.Fatal("expected out-of-workspace media to be dropped")
|
|
}
|
|
})
|
|
|
|
t.Run("traversal dropped", func(t *testing.T) {
|
|
if _, ok := confineSink("MEDIA:../passwd"); ok {
|
|
t.Fatal("expected traversal media to be dropped")
|
|
}
|
|
})
|
|
}
|