fix: reject extension API calls for disabled plugins - #9916
Open
lxfight wants to merge 1 commit into
Open
Conversation
_call_plugin_extension executed handlers of disabled plugins, while the static plugin pages already return 403 for the same state. Resolve the owning plugin from the handler module (function module or bound-method owner class) and return an error response when it is disabled. Legacy routes whose handlers live outside the plugin module namespaces are unaffected.
5 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation / 动机
插件动态 Web API(
context.register_web_api()注册、经/api/v1/plugins/extensions/...分发)在插件被禁用后仍然可以调用,而静态 Plugin Pages 在同一状态下返回 403(PluginPageService的activated检查)。两个入口行为不一致,禁用插件的后端接口没有真正下线。Modifications / 改动点
astrbot/dashboard/api/plugins.py:_call_plugin_extension()在路由匹配成功后,通过 handler 的归属模块(函数__module__或绑定方法的所属类__module__)解析所属插件,插件处于禁用状态时返回{"status": "error", "message": "插件未启用"}。归属解析基于插件模块命名空间(
data.plugins.<root_dir_name>/astrbot.builtin_stars.<root_dir_name>),因此不带插件前缀的 legacy 路由不受影响(现有/web/<item_id>、/upload等行为保持不变)。tests/test_fastapi_v1_dashboard.py:新增禁用插件被拒、启用插件正常放行两个用例。This is NOT a breaking change. / 这不是一个破坏性变更。
Screenshots or Test Results / 运行截图或测试结果
验证步骤:
register_web_api的插件并确认可正常调用其接口。插件未启用错误,与插件 Page 的 403 行为对齐。Checklist / 检查清单
😊 If there are new features added in the PR, I have discussed it with the authors through issues/emails, etc.
/ 如果 PR 中有新加入的功能,已经通过 Issue / 邮件等方式和作者讨论过。
👀 My changes have been well-tested, and "Verification Steps" and "Screenshots" have been provided above.
/ 我的更改经过了良好的测试,并已在上方提供了“验证步骤”和“运行截图”。
🤓 I have ensured that no new dependencies are introduced, OR if new dependencies are introduced, they have been added to the appropriate locations in
requirements.txtandpyproject.toml./ 我确保没有引入新依赖库,或者引入了新依赖库的同时将其添加到
requirements.txt和pyproject.toml文件相应位置。😮 My changes do not introduce malicious code.
/ 我的更改没有引入恶意代码。
Summary by Sourcery
Prevent disabled plugins from serving their registered extension APIs while keeping enabled plugin and legacy API behavior unchanged.
Bug Fixes:
Enhancements:
Tests: