fix: 修复Bandit安全扫描硬编码临时目录问题
Deploy / Deploy Staging (push) Failing after 137h5m41s
CI/CD Pipeline / Frontend Lint (push) Failing after 137h5m49s
CI/CD Pipeline / Validate Code Quality And Tests (push) Failing after 137h5m53s
Deploy / Staging E2E Tests (push) Failing after 1795h41m12s
Deploy / Deploy Production (push) Failing after 1795h41m15s
Deploy / Build Production Runtime Images (push) Failing after 1795h41m17s
Deploy / Production Browser E2E (push) Failing after 1796h12m37s

This commit is contained in:
灵应
2026-07-03 19:48:07 +08:00
parent 6140ba1545
commit 3dcba4c44c
2 changed files with 8 additions and 4 deletions
@@ -17,8 +17,9 @@ from packages.domain.editing_mode import EditingMode
logger = logging.getLogger(__name__)
# ========== 安全常量 ==========
# 允许的输出目录白名单
ALLOWED_OUTPUT_DIRS = ["/tmp/video_output", "/var/app/rendered"]
# 允许的输出目录白名单(使用环境变量或系统临时目录,避免硬编码 /tmp)
_VIDEO_OUTPUT_DIR = os.environ.get("VIDEO_OUTPUT_DIR", os.path.join(tempfile.gettempdir(), "video_output"))
ALLOWED_OUTPUT_DIRS = [_VIDEO_OUTPUT_DIR, "/var/app/rendered"]
# 允许的输入路径前缀白名单
ALLOWED_INPUT_PREFIXES = ("s3://", "oss://", "local://", "/var/storage/")
@@ -6,6 +6,7 @@
from __future__ import annotations
import logging
import os
import shutil
import subprocess
import tempfile
@@ -73,7 +74,8 @@ def compose_video(self, job_id: str, **kwargs):
# 构建合成命令
job_service.update_progress(job_id, progress=30.0, current_stage="构建 FFmpeg 命令")
output_path = f"/tmp/video_output/{job_id}.mp4"
_output_dir = os.environ.get("VIDEO_OUTPUT_DIR", os.path.join(tempfile.gettempdir(), "video_output"))
output_path = os.path.join(_output_dir, f"{job_id}.mp4")
compose_cmd = compose_svc.build_compose_command(plan_id, output_path)
# 执行 FFmpeg
@@ -129,7 +131,8 @@ def compose_video(self, job_id: str, **kwargs):
db.close()
# 清理临时文件
try:
output_path = f"/tmp/video_output/{job_id}.mp4"
_output_dir = os.environ.get("VIDEO_OUTPUT_DIR", os.path.join(tempfile.gettempdir(), "video_output"))
output_path = os.path.join(_output_dir, f"{job_id}.mp4")
if Path(output_path).exists():
Path(output_path).unlink()
except Exception as e: