Commit Graph
9 Commits
Author SHA1 Message Date
Zayn Jarvis 0ea5815748 fix(crypto): 禁止重写 Vault root key on 临时 (503) read failures (#3423)
* fix(crypto): never overwrite Vault root key on transient read failures

Sweep finding B-01

* fix(crypto): clear cached ephemeral root key when Vault persist fails

The InvalidPath create branch cached the freshly generated root key in
self._root_key before encrypting/persisting it. If _encrypt_with_vault or
the KV write failed (transient transit/KV outage), get_root_key raised but
left the never-persisted key cached, so a retry returned it via the
`self._root_key is not None` fast path and encrypted data with a key that
vanishes on restart — the data-loss class this provider guards.

Wrap encrypt+persist in one try and null the cache before raising; add a
regression asserting the cache is cleared and the next call re-reads Vault.

Addresses the blocking review finding on #3423.
2026-07-24 17:30:34 +08:00
baojun-zhang e492cbd16f refactor(encryption): using rust refactor encryption (#2444) 2026-06-05 17:26:26 +08:00
Qin Haojie 38c324bc97 fix(security): clean up code scanning and runtime findings (#1596)
* fix(security): clean up code scanning and runtime findings

Harden path and logging boundaries, remove noisy cleanup issues,
and keep observability failures from breaking runtime flows.

* fix(security): close werewolf and feishu validation gaps

Block the remaining path traversal bypass in the werewolf demo,
and validate Feishu hosts on the main parse() entry point.
2026-04-21 10:06:46 +08:00
MaojiaSheng b13410546b fix: auth and system cmds (#1545) 2026-04-17 20:04:30 +08:00
baojun-zhang b441622ee6 feat(metric): add metric system (#1357)
* feat(metric): add metric system

* feat(metric): add metric system

* feat(metric): add metric system

* fix(metric): do not cancel refresh tasks on deadline; trust only authenticated account id; avoid per-scrape rerank clients

* doc(metric): add metric guide doc

* doc(metric): add metric guide doc

* doc(metric): add metric guide doc

* doc(metric): add metric guide doc

* feat(metric): fix bug & change account dimension switch to default true
2026-04-14 20:55:02 +08:00
yc111233andyc111233 7295660cd8 fix: decrypt raises 'Ciphertext too short' on plaintext files shorter than 4 bytes (#1163)
* fix: decrypt raises 'Ciphertext too short' on plaintext files shorter than 4 bytes

The decrypt() method checked ciphertext length before checking the magic
header. This caused plaintext files shorter than 4 bytes (including empty
files) to raise InvalidMagicError('Ciphertext too short') before the
'is this plaintext?' check could return them as-is.

Fix: swap the order — check if content starts with OVE1 magic first,
then only check length for actual encrypted content.

This fixes failures when append_file() reads an empty messages.jsonl
session file and tries to decrypt it.

* fix: add strict=True to zip() in summarizer (B905 lint)

---------

Co-authored-by: yc111233 <yc111233@gmail.com>
2026-04-04 14:25:21 +08:00
MaojiaShengandopenviking ce998873f9 lisence: change the main lisence to AGPL-3.0 (#1085)
* lisence: change the main lisence from Apache-2.0 to AGPL-v3

* lisence: change the main lisence from Apache-2.0 to AGPL-v3

* lisence: change the main lisence from Apache-2.0 to AGPL-v3

---------

Co-authored-by: openviking <openviking@example.com>
2026-03-30 14:37:42 +08:00
baojun-zhang 5bbb22a6ef feat: add encrypt doc && refactoring encrypt code (#893)
* feat: add encrypt doc && fix Partial reads/wrong location problem && refactoring duplicated code && add

* feat: reformat code

* feat: resolve comment

* feat: resolve comment

* feat: resolve comment
2026-03-23 19:23:11 +08:00
baojun-zhang 8cdecd9163 feat: Add multi-tenant file encryption capability (#828)
* feat: Add multi-tenant file encryption capability

* feat: move cli command `ov crypto` to `ov system crypto` && ruff format && add encryption config example

* feat: reformat code

* feat: adjust crypto.rs to support diff platform

* feat: reformat code
2026-03-21 13:35:46 +08:00