security: Sentinel 路由鉴权 + API Key CSRF + SSRF 防护

修复:
- Sentinel 路由 require_auth=False → True (严重: 未认证可访问)
- API Key 创建/删除加 csrf_protect=True
- SSRF 防护: 测试连接仅允许 http/https scheme
- 插件网络鉴权: 已加载插件自动放行 (不再要求 plugin.network.access)
- Sentinel 权限列表补充 plugin.network.access

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
qinglong
2026-06-13 15:13:56 +08:00
parent 5e74b0aad7
commit 634496d975
9 changed files with 71 additions and 36 deletions
+2 -2
View File
@@ -171,6 +171,6 @@ def setup_routes(app, prefix=""):
return web.json_response({"error": str(e)}, status=500)
app.router.add_get(f"{prefix}/api/apikeys", panel_auth(list_keys))
app.router.add_post(f"{prefix}/api/apikeys", panel_auth(create_key))
app.router.add_delete(f"{prefix}/api/apikeys", panel_auth(delete_key))
app.router.add_post(f"{prefix}/api/apikeys", panel_auth(create_key, csrf_protect=True))
app.router.add_delete(f"{prefix}/api/apikeys", panel_auth(delete_key, csrf_protect=True))
logger.info(f"🔑 API Key 管理路由已注册 ({prefix}/api/apikeys)")