fix: 渲染引擎全链路安全加固 P0+P1 (#317)
CI/CD Pipeline / Validate Code Quality And Tests (push) Has been cancelled
CI/CD Pipeline / Unit Tests (push) Has been cancelled
CI/CD Pipeline / Integration Tests (push) Has been cancelled
CI/CD Pipeline / Frontend Lint (push) Has been cancelled
CI/CD Pipeline / Build Staging API Image (push) Has been cancelled
CI/CD Pipeline / Build Staging Worker Image (push) Has been cancelled
CI/CD Pipeline / Build Staging Web Image (push) Has been cancelled
CI/CD Pipeline / Deploy Staging (Watchtower auto-deploy) (push) Has been cancelled
CI/CD Pipeline / Staging E2E Tests (push) Has been cancelled
CI/CD Pipeline / Staging API Integration Tests (push) Has been cancelled
CI/CD Pipeline / Build Production API Image (push) Has been cancelled
CI/CD Pipeline / Build Production Worker Image (push) Has been cancelled
CI/CD Pipeline / Build Production Web Image (push) Has been cancelled
CI/CD Pipeline / Deploy Production (push) Has been cancelled
CI/CD Pipeline / Production Browser E2E (push) Has been cancelled

This commit was merged in pull request #317.
This commit is contained in:
2026-07-14 18:15:21 +08:00
parent 7f767e2dd1
commit c88be032c1
20 changed files with 928 additions and 210 deletions
+44 -6
View File
@@ -392,10 +392,48 @@ class StickerEngine:
)
parsed_stickers.append((z, config))
else:
# 图片贴纸
image_path = s.get("image_path", "") or s.get("image_url", "")
if not image_path or not Path(image_path).exists():
logger.warning("贴纸素材不存在,跳过: %s", image_path)
# 图片贴纸 — 安全校验:区分本地路径和URL
image_path = s.get("image_path", "")
image_url = s.get("image_url", "")
safe_image_path: Path | None = None
if image_path:
# 本地路径:路径遍历防护
from video_processing.path_security import is_in_allowed_dirs
try:
p = Path(image_path)
if not p.exists():
logger.warning("贴纸素材不存在,跳过: %s", image_path[:80])
continue
if not is_in_allowed_dirs(p):
logger.warning("贴纸路径不在允许目录内,拒绝: %s", image_path[:80])
continue
safe_image_path = p.resolve()
except Exception as e:
logger.warning("贴纸路径校验失败,跳过: %s error=%s", image_path[:80], e)
continue
elif image_url:
# URL:SSRF 安全校验(暂不自动下载,仅校验安全性)
from video_processing.url_security import (
UrlSecurityError,
validate_url_safety,
)
try:
validate_url_safety(image_url, purpose="sticker_image")
except UrlSecurityError as e:
logger.warning("贴纸URL安全校验失败,跳过: %s error=%s", image_url[:80], e)
continue
# URL 类型暂不支持自动下载,跳过
logger.info("贴纸URL类型暂不支持自动下载,跳过: %s", image_url[:80])
continue
else:
logger.warning("贴纸缺少 image_path 和 image_url,跳过")
continue
if safe_image_path is None:
continue
config = ImageStickerConfig(
@@ -414,11 +452,11 @@ class StickerEngine:
fade_in=float(s.get("fade_in", 0)),
fade_out=float(s.get("fade_out", 0)),
z_index=z,
image_url=str(s.get("image_url", "")),
image_url=image_url,
)
parsed_stickers.append((z, config))
image_stickers.append(config)
image_paths.append(image_path)
image_paths.append(str(safe_image_path))
except Exception as e:
logger.warning("贴纸配置解析失败,跳过: %s", e)