feat(security): support prefix matching for MCP tools in policy checker and fix health endpoints
This commit is contained in:
parent
0bb6fa4d73
commit
5f34600270
3 changed files with 22 additions and 7 deletions
|
|
@ -744,7 +744,7 @@ func (c *ModelConfig) SetAPIKey(value string) {
|
||||||
|
|
||||||
type GatewayConfig struct {
|
type GatewayConfig struct {
|
||||||
Host string `json:"host" env:"PICOCLAW_GATEWAY_HOST"`
|
Host string `json:"host" env:"PICOCLAW_GATEWAY_HOST"`
|
||||||
Port int `json:"port" env:"PICOCLAW_GATEWAY_PORT,PORT"`
|
Port int `json:"port" env:"PICOCLAW_GATEWAY_PORT"`
|
||||||
APIKey string `json:"api_key" env:"PICOCLAW_GATEWAY_API_KEY"`
|
APIKey string `json:"api_key" env:"PICOCLAW_GATEWAY_API_KEY"`
|
||||||
ChatEnabled bool `json:"chat_enabled" env:"PICOCLAW_GATEWAY_CHAT_ENABLED"`
|
ChatEnabled bool `json:"chat_enabled" env:"PICOCLAW_GATEWAY_CHAT_ENABLED"`
|
||||||
HotReload bool `json:"hot_reload" env:"PICOCLAW_GATEWAY_HOT_RELOAD"`
|
HotReload bool `json:"hot_reload" env:"PICOCLAW_GATEWAY_HOT_RELOAD"`
|
||||||
|
|
|
||||||
|
|
@ -63,11 +63,6 @@ type StatusResponse struct {
|
||||||
}
|
}
|
||||||
|
|
||||||
func NewServer(host string, port int) *Server {
|
func NewServer(host string, port int) *Server {
|
||||||
if envPort := os.Getenv("PORT"); envPort != "" {
|
|
||||||
if _, err := fmt.Sscanf(envPort, "%d", &port); err == nil {
|
|
||||||
logger.Infof("Overriding server port with PORT environment variable: %d", port)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
mux := http.NewServeMux()
|
mux := http.NewServeMux()
|
||||||
s := &Server{
|
s := &Server{
|
||||||
ready: false,
|
ready: false,
|
||||||
|
|
|
||||||
|
|
@ -3,6 +3,7 @@ package policy
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"strings"
|
||||||
|
|
||||||
"github.com/sipeed/picoclaw/pkg/agent"
|
"github.com/sipeed/picoclaw/pkg/agent"
|
||||||
)
|
)
|
||||||
|
|
@ -50,7 +51,26 @@ func (c *Checker) ApproveTool(ctx context.Context, req *agent.ToolApprovalReques
|
||||||
|
|
||||||
// 2. Whitelisting (if enabled)
|
// 2. Whitelisting (if enabled)
|
||||||
if len(c.Config.AllowedTools) > 0 {
|
if len(c.Config.AllowedTools) > 0 {
|
||||||
if !c.Config.AllowedTools[req.Tool] {
|
allowed := false
|
||||||
|
if c.Config.AllowedTools[req.Tool] {
|
||||||
|
allowed = true
|
||||||
|
} else {
|
||||||
|
// Check for prefix matches (e.g. "monday" matches "mcp_monday_...")
|
||||||
|
// Match logic consistent with ToolRegistry.Filter
|
||||||
|
for w, ok := range c.Config.AllowedTools {
|
||||||
|
if !ok {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if strings.HasPrefix(req.Tool, "mcp_"+w+"_") ||
|
||||||
|
strings.HasPrefix(req.Tool, "tool_"+w+"_") ||
|
||||||
|
strings.HasPrefix(req.Tool, w+"_") {
|
||||||
|
allowed = true
|
||||||
|
break
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if !allowed {
|
||||||
return agent.ApprovalDecision{
|
return agent.ApprovalDecision{
|
||||||
Approved: false,
|
Approved: false,
|
||||||
Reason: fmt.Sprintf("Tool %q is not in the allowed tools whitelist", req.Tool),
|
Reason: fmt.Sprintf("Tool %q is not in the allowed tools whitelist", req.Tool),
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue