Skip to content

fix: reject extension API calls for disabled plugins - #9916

Open
lxfight wants to merge 1 commit into
AstrBotDevs:masterfrom
lxfight:fix/plugin-extension-activated-check
Open

fix: reject extension API calls for disabled plugins#9916
lxfight wants to merge 1 commit into
AstrBotDevs:masterfrom
lxfight:fix/plugin-extension-activated-check

Conversation

@lxfight

@lxfight lxfight commented Sep 2, 2026

Copy link
Copy Markdown
Member

Motivation / 动机

插件动态 Web API(context.register_web_api() 注册、经 /api/v1/plugins/extensions/... 分发)在插件被禁用后仍然可以调用,而静态 Plugin Pages 在同一状态下返回 403(PluginPageServiceactivated 检查)。两个入口行为不一致,禁用插件的后端接口没有真正下线。

Modifications / 改动点

  • astrbot/dashboard/api/plugins.py_call_plugin_extension() 在路由匹配成功后,通过 handler 的归属模块(函数 __module__ 或绑定方法的所属类 __module__)解析所属插件,插件处于禁用状态时返回 {"status": "error", "message": "插件未启用"}

  • 归属解析基于插件模块命名空间(data.plugins.<root_dir_name> / astrbot.builtin_stars.<root_dir_name>),因此不带插件前缀的 legacy 路由不受影响(现有 /web/<item_id>/upload 等行为保持不变)。

  • tests/test_fastapi_v1_dashboard.py:新增禁用插件被拒、启用插件正常放行两个用例。

  • This is NOT a breaking change. / 这不是一个破坏性变更。

Screenshots or Test Results / 运行截图或测试结果

$ uv run pytest tests/test_fastapi_v1_dashboard.py tests/test_dashboard.py -q
174 passed

验证步骤:

  1. 安装一个注册了 register_web_api 的插件并确认可正常调用其接口。
  2. 在 WebUI 中禁用该插件,再次请求其扩展 API → 返回 插件未启用 错误,与插件 Page 的 403 行为对齐。
  3. 重新启用插件后接口恢复可用。

Checklist / 检查清单

  • 😊 If there are new features added in the PR, I have discussed it with the authors through issues/emails, etc.
    / 如果 PR 中有新加入的功能,已经通过 Issue / 邮件等方式和作者讨论过。

  • 👀 My changes have been well-tested, and "Verification Steps" and "Screenshots" have been provided above.
    / 我的更改经过了良好的测试,并已在上方提供了“验证步骤”和“运行截图”

  • 🤓 I have ensured that no new dependencies are introduced, OR if new dependencies are introduced, they have been added to the appropriate locations in requirements.txt and pyproject.toml.
    / 我确保没有引入新依赖库,或者引入了新依赖库的同时将其添加到 requirements.txtpyproject.toml 文件相应位置。

  • 😮 My changes do not introduce malicious code.
    / 我的更改没有引入恶意代码。

Summary by Sourcery

Prevent disabled plugins from serving their registered extension APIs while keeping enabled plugin and legacy API behavior unchanged.

Bug Fixes:

  • Reject extension API requests owned by disabled plugins while preserving access for activated plugins and legacy routes.

Enhancements:

  • Align dynamic plugin extension API behavior with static plugin pages by enforcing plugin activation state.

Tests:

  • Add coverage for rejecting disabled-plugin extension requests and allowing activated-plugin requests.

_call_plugin_extension executed handlers of disabled plugins, while the
static plugin pages already return 403 for the same state. Resolve the
owning plugin from the handler module (function module or bound-method
owner class) and return an error response when it is disabled. Legacy
routes whose handlers live outside the plugin module namespaces are
unaffected.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!

Sourcery assessment

Approved.


Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant