mirror of
https://github.com/zhu1090093659/dsh-web.git
synced 2026-09-28 06:13:45 +08:00
Root pnpm typecheck failed: shared sources must not import @deepseek-ai/cordis (no such dependency in the shared package). The fence now reads a structural two-member context shape that cordis Context satisfies; wrapper signatures and behavior are unchanged.
49 lines
1.9 KiB
TypeScript
49 lines
1.9 KiB
TypeScript
/**
|
|
* Pairing trust fence shared by plugins that expose host routes: loopback
|
|
* (the desktop) always passes; a live paired-device cookie is an additional
|
|
* allow path when remote-web-ui is loaded. The consuming plugin never
|
|
* depends on that plugin — without the service the fence stays
|
|
* loopback-only.
|
|
*
|
|
* Per-package wrappers (access.ts) call this with their own name so each
|
|
* plugin keeps a self-describing export; the security decision lives only
|
|
* here.
|
|
*/
|
|
import type { IncomingMessage } from 'node:http'
|
|
import { isLoopbackRequest } from './loopback.ts'
|
|
|
|
/** Structural pairing lookup (no package dependency on remote-web-ui). */
|
|
interface PairingAccess {
|
|
isPairedDevice(request: IncomingMessage): boolean
|
|
}
|
|
|
|
/**
|
|
* Structural host-context shape: shared sources carry no @deepseek-ai
|
|
* dependency (the shared package must typecheck standalone), so the fence
|
|
* reads only the two members it needs; cordis Context satisfies this.
|
|
* ctx.get is optional on the test harness; production Context always has it.
|
|
*/
|
|
interface LookupCtx {
|
|
get?(name: string, strict?: boolean): unknown
|
|
remoteWebUiPairing?: PairingAccess
|
|
}
|
|
|
|
/**
|
|
* Whether this request may enter the plugin's host routes.
|
|
* @param ctx - host context; may expose remoteWebUiPairing.
|
|
* @param request - the incoming HTTP request.
|
|
* @returns true for loopback, or a live paired-device cookie.
|
|
*/
|
|
export function isPairedOrLoopbackAllowed(ctx: LookupCtx, request: IncomingMessage): boolean {
|
|
if (isLoopbackRequest(request)) return true
|
|
const fromGet = typeof ctx.get === 'function' ? ctx.get('remoteWebUiPairing', false) : undefined
|
|
const pairing = (isPairingAccess(fromGet) ? fromGet : ctx.remoteWebUiPairing)
|
|
return pairing?.isPairedDevice(request) === true
|
|
}
|
|
|
|
function isPairingAccess(value: unknown): value is PairingAccess {
|
|
return value !== undefined
|
|
&& value !== null
|
|
&& typeof (value as PairingAccess).isPairedDevice === 'function'
|
|
}
|