feat: 平台治理与权限体系完善,存储进度/GPU预留/审批中心与日志整合
- 平台治理: 租户用户权限层次、资源ACL、审批中心与审批模板、访问申请 - 存储: MinIO 存储进度迁移、对象存储安全加固与测试 - 计算: GPU 资源预留、compute 轮询与同步增强 - 权限: permission v2 迁移、权限安全验收测试 - 日志: 后端运行日志中文说明、操作日志整合 - 数据处理/评测: 数据转换与模型评测优化 Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
30
backend/tests/test_permission_security.py
Normal file
30
backend/tests/test_permission_security.py
Normal file
@@ -0,0 +1,30 @@
|
||||
from __future__ import annotations
|
||||
|
||||
from app.api.v1.endpoints.platform import _public_model
|
||||
from app.core.audit import _safe_exception_reason
|
||||
from app.core.auth import RESOURCE_ACTIONS, RESOURCE_ACTION_ALIASES
|
||||
|
||||
|
||||
def test_public_model_never_exposes_provider_credentials() -> None:
|
||||
result = _public_model({
|
||||
"id": "m_1",
|
||||
"name": "online",
|
||||
"api_url": "https://example.invalid/v1",
|
||||
"api_key": "secret-value",
|
||||
})
|
||||
|
||||
assert "api_key" not in result
|
||||
assert result["api_key_configured"] is True
|
||||
assert result["name"] == "online"
|
||||
|
||||
|
||||
def test_resource_action_registry_keeps_export_separate_from_module_permissions() -> None:
|
||||
assert "download" in RESOURCE_ACTIONS
|
||||
assert "execute" in RESOURCE_ACTIONS
|
||||
assert RESOURCE_ACTION_ALIASES["export"] == "download"
|
||||
|
||||
|
||||
def test_audit_exception_reason_masks_credentials() -> None:
|
||||
reason = _safe_exception_reason(ValueError("api_key=secret-value"))
|
||||
assert "secret-value" not in reason
|
||||
assert "***" in reason
|
||||
26
backend/tests/test_storage_security.py
Normal file
26
backend/tests/test_storage_security.py
Normal file
@@ -0,0 +1,26 @@
|
||||
from __future__ import annotations
|
||||
|
||||
import pytest
|
||||
|
||||
from app.api.v1.endpoints.platform import _validate_storage_key
|
||||
|
||||
|
||||
def test_storage_key_is_scoped_to_resource_version() -> None:
|
||||
assert (
|
||||
_validate_storage_key("dataset", "ds_123", "v1", None, "train.jsonl")
|
||||
== "datasets/ds_123/versions/v1/train.jsonl"
|
||||
)
|
||||
|
||||
|
||||
@pytest.mark.parametrize(
|
||||
"object_key",
|
||||
[
|
||||
"models/other/versions/v1/model.bin",
|
||||
"datasets/ds_123/versions/v1/../secret.bin",
|
||||
"datasets/ds_123/versions/v1/../../secret.bin",
|
||||
"/datasets/ds_123/versions/v1/model.bin",
|
||||
],
|
||||
)
|
||||
def test_storage_key_rejects_escape_or_cross_resource_paths(object_key: str) -> None:
|
||||
with pytest.raises(ValueError):
|
||||
_validate_storage_key("dataset", "ds_123", "v1", object_key, None)
|
||||
Reference in New Issue
Block a user