mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-10-06 11:12:10 +00:00
fix: temporarily disable requests (#452)
* fix: temporarily disable requests * cr
This commit is contained in:
parent
d7cf3e0fb5
commit
9a4b63b798
1 changed files with 185 additions and 181 deletions
|
|
@ -1,24 +1,24 @@
|
||||||
import { Auth, HTTPException } from "@langchain/langgraph-sdk/auth";
|
import { Auth, HTTPException } from "@langchain/langgraph-sdk/auth";
|
||||||
import {
|
// import {
|
||||||
verifyGithubUser,
|
// verifyGithubUser,
|
||||||
GithubUser,
|
// GithubUser,
|
||||||
verifyGithubUserId,
|
// verifyGithubUserId,
|
||||||
} from "@open-swe/shared/github/verify-user";
|
// } from "@open-swe/shared/github/verify-user";
|
||||||
import {
|
// import {
|
||||||
API_KEY_REQUIRED_MESSAGE,
|
// API_KEY_REQUIRED_MESSAGE,
|
||||||
GITHUB_INSTALLATION_NAME,
|
// GITHUB_INSTALLATION_NAME,
|
||||||
GITHUB_INSTALLATION_TOKEN_COOKIE,
|
// GITHUB_INSTALLATION_TOKEN_COOKIE,
|
||||||
GITHUB_TOKEN_COOKIE,
|
// GITHUB_TOKEN_COOKIE,
|
||||||
GITHUB_USER_ID_HEADER,
|
// GITHUB_USER_ID_HEADER,
|
||||||
GITHUB_USER_LOGIN_HEADER,
|
// GITHUB_USER_LOGIN_HEADER,
|
||||||
} from "@open-swe/shared/constants";
|
// } from "@open-swe/shared/constants";
|
||||||
import { decryptSecret } from "@open-swe/shared/crypto";
|
// import { decryptSecret } from "@open-swe/shared/crypto";
|
||||||
import { verifyGitHubWebhookOrThrow } from "./github.js";
|
// import { verifyGitHubWebhookOrThrow } from "./github.js";
|
||||||
import { createWithOwnerMetadata, createOwnerFilter } from "./utils.js";
|
import { createWithOwnerMetadata, createOwnerFilter } from "./utils.js";
|
||||||
import { LANGGRAPH_USER_PERMISSIONS } from "../constants.js";
|
// import { LANGGRAPH_USER_PERMISSIONS } from "../constants.js";
|
||||||
import { getGitHubPatFromRequest } from "../utils/github-pat.js";
|
// import { getGitHubPatFromRequest } from "../utils/github-pat.js";
|
||||||
import { isAllowedUser } from "../utils/github/allowed-users.js";
|
// import { isAllowedUser } from "../utils/github/allowed-users.js";
|
||||||
import { validate } from "uuid";
|
// import { validate } from "uuid";
|
||||||
|
|
||||||
// TODO: Export from LangGraph SDK
|
// TODO: Export from LangGraph SDK
|
||||||
export interface BaseAuthReturn {
|
export interface BaseAuthReturn {
|
||||||
|
|
@ -34,185 +34,189 @@ interface AuthenticateReturn extends BaseAuthReturn {
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
function apiKeysInRequestBody(
|
// function apiKeysInRequestBody(
|
||||||
bodyStr: string | Record<string, unknown>,
|
// bodyStr: string | Record<string, unknown>,
|
||||||
): boolean {
|
// ): boolean {
|
||||||
try {
|
// try {
|
||||||
const body = typeof bodyStr === "string" ? JSON.parse(bodyStr) : bodyStr;
|
// const body = typeof bodyStr === "string" ? JSON.parse(bodyStr) : bodyStr;
|
||||||
if (
|
// if (
|
||||||
body.config?.configurable &&
|
// body.config?.configurable &&
|
||||||
("anthropicApiKey" in body.config.configurable.apiKeys ||
|
// ("anthropicApiKey" in body.config.configurable.apiKeys ||
|
||||||
"openaiApiKey" in body.config.configurable.apiKeys ||
|
// "openaiApiKey" in body.config.configurable.apiKeys ||
|
||||||
"googleApiKey" in body.config.configurable.apiKeys)
|
// "googleApiKey" in body.config.configurable.apiKeys)
|
||||||
) {
|
// ) {
|
||||||
return true;
|
// return true;
|
||||||
}
|
// }
|
||||||
return false;
|
// return false;
|
||||||
} catch {
|
// } catch {
|
||||||
// no-op
|
// // no-op
|
||||||
return false;
|
// return false;
|
||||||
}
|
// }
|
||||||
}
|
// }
|
||||||
|
|
||||||
function isRunReq(reqUrl: string): boolean {
|
// function isRunReq(reqUrl: string): boolean {
|
||||||
try {
|
// try {
|
||||||
const url = new URL(reqUrl);
|
// const url = new URL(reqUrl);
|
||||||
const pathnameParts = url.pathname.split("/");
|
// const pathnameParts = url.pathname.split("/");
|
||||||
const isCreateAndWait = !!(
|
// const isCreateAndWait = !!(
|
||||||
pathnameParts[1] === "threads" &&
|
// pathnameParts[1] === "threads" &&
|
||||||
validate(pathnameParts[2]) &&
|
// validate(pathnameParts[2]) &&
|
||||||
pathnameParts[3] === "runs" &&
|
// pathnameParts[3] === "runs" &&
|
||||||
pathnameParts[4] === "wait" &&
|
// pathnameParts[4] === "wait" &&
|
||||||
pathnameParts.length === 5
|
// pathnameParts.length === 5
|
||||||
);
|
// );
|
||||||
const isCreateBackground = !!(
|
// const isCreateBackground = !!(
|
||||||
pathnameParts[1] === "threads" &&
|
// pathnameParts[1] === "threads" &&
|
||||||
validate(pathnameParts[2]) &&
|
// validate(pathnameParts[2]) &&
|
||||||
pathnameParts[3] === "runs" &&
|
// pathnameParts[3] === "runs" &&
|
||||||
pathnameParts.length === 4
|
// pathnameParts.length === 4
|
||||||
);
|
// );
|
||||||
const isCreateStream = !!(
|
// const isCreateStream = !!(
|
||||||
pathnameParts[1] === "threads" &&
|
// pathnameParts[1] === "threads" &&
|
||||||
validate(pathnameParts[2]) &&
|
// validate(pathnameParts[2]) &&
|
||||||
pathnameParts[3] === "runs" &&
|
// pathnameParts[3] === "runs" &&
|
||||||
pathnameParts[4] === "stream" &&
|
// pathnameParts[4] === "stream" &&
|
||||||
pathnameParts.length === 5
|
// pathnameParts.length === 5
|
||||||
);
|
// );
|
||||||
|
|
||||||
return !!isCreateAndWait || !!isCreateBackground || !!isCreateStream;
|
// return !!isCreateAndWait || !!isCreateBackground || !!isCreateStream;
|
||||||
} catch {
|
// } catch {
|
||||||
// no-op
|
// // no-op
|
||||||
return false;
|
// return false;
|
||||||
}
|
// }
|
||||||
}
|
// }
|
||||||
|
|
||||||
export const auth = new Auth()
|
export const auth = new Auth()
|
||||||
.authenticate<AuthenticateReturn>(async (request: Request) => {
|
.authenticate<AuthenticateReturn>(async (_request: Request) => {
|
||||||
if (request.method === "OPTIONS") {
|
return new HTTPException(504, {
|
||||||
return {
|
message: "Open SWE temporarily disabled.",
|
||||||
identity: "anonymous",
|
}) as any;
|
||||||
permissions: [],
|
|
||||||
is_authenticated: false,
|
|
||||||
display_name: "CORS Preflight",
|
|
||||||
metadata: {
|
|
||||||
installation_name: "n/a",
|
|
||||||
},
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
const isProd = process.env.NODE_ENV === "production";
|
// if (request.method === "OPTIONS") {
|
||||||
|
// return {
|
||||||
|
// identity: "anonymous",
|
||||||
|
// permissions: [],
|
||||||
|
// is_authenticated: false,
|
||||||
|
// display_name: "CORS Preflight",
|
||||||
|
// metadata: {
|
||||||
|
// installation_name: "n/a",
|
||||||
|
// },
|
||||||
|
// };
|
||||||
|
// }
|
||||||
|
|
||||||
const ghSecretHashHeader = request.headers.get("X-Hub-Signature-256");
|
// const isProd = process.env.NODE_ENV === "production";
|
||||||
if (ghSecretHashHeader) {
|
|
||||||
// This will either return a valid user, or throw an error
|
|
||||||
return await verifyGitHubWebhookOrThrow(request);
|
|
||||||
}
|
|
||||||
|
|
||||||
const encryptionKey = process.env.SECRETS_ENCRYPTION_KEY;
|
// const ghSecretHashHeader = request.headers.get("X-Hub-Signature-256");
|
||||||
if (!encryptionKey) {
|
// if (ghSecretHashHeader) {
|
||||||
throw new Error("Missing SECRETS_ENCRYPTION_KEY environment variable.");
|
// // This will either return a valid user, or throw an error
|
||||||
}
|
// return await verifyGitHubWebhookOrThrow(request);
|
||||||
|
// }
|
||||||
|
|
||||||
// Check for GitHub PAT authentication (simpler mode for evals, etc.)
|
// const encryptionKey = process.env.SECRETS_ENCRYPTION_KEY;
|
||||||
const githubPat = getGitHubPatFromRequest(request, encryptionKey);
|
// if (!encryptionKey) {
|
||||||
if (githubPat && !isProd) {
|
// throw new Error("Missing SECRETS_ENCRYPTION_KEY environment variable.");
|
||||||
const user = await verifyGithubUser(githubPat);
|
// }
|
||||||
if (!user) {
|
|
||||||
throw new HTTPException(401, {
|
|
||||||
message: "Invalid GitHub PAT",
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
return {
|
// // Check for GitHub PAT authentication (simpler mode for evals, etc.)
|
||||||
identity: user.id.toString(),
|
// const githubPat = getGitHubPatFromRequest(request, encryptionKey);
|
||||||
is_authenticated: true,
|
// if (githubPat && !isProd) {
|
||||||
display_name: user.login,
|
// const user = await verifyGithubUser(githubPat);
|
||||||
metadata: {
|
// if (!user) {
|
||||||
installation_name: "pat-auth",
|
// throw new HTTPException(401, {
|
||||||
},
|
// message: "Invalid GitHub PAT",
|
||||||
permissions: LANGGRAPH_USER_PERMISSIONS,
|
// });
|
||||||
};
|
// }
|
||||||
}
|
|
||||||
|
|
||||||
// GitHub App authentication mode (existing logic)
|
// return {
|
||||||
const installationNameHeader = request.headers.get(
|
// identity: user.id.toString(),
|
||||||
GITHUB_INSTALLATION_NAME,
|
// is_authenticated: true,
|
||||||
);
|
// display_name: user.login,
|
||||||
if (!installationNameHeader) {
|
// metadata: {
|
||||||
throw new HTTPException(401, {
|
// installation_name: "pat-auth",
|
||||||
message: "GitHub installation name header missing",
|
// },
|
||||||
});
|
// permissions: LANGGRAPH_USER_PERMISSIONS,
|
||||||
}
|
// };
|
||||||
|
// }
|
||||||
|
|
||||||
// We don't do anything with this token right now, but still confirm it
|
// // GitHub App authentication mode (existing logic)
|
||||||
// exists as it will cause issues later on if it's not present.
|
// const installationNameHeader = request.headers.get(
|
||||||
const encryptedInstallationToken = request.headers.get(
|
// GITHUB_INSTALLATION_NAME,
|
||||||
GITHUB_INSTALLATION_TOKEN_COOKIE,
|
// );
|
||||||
);
|
// if (!installationNameHeader) {
|
||||||
if (!encryptedInstallationToken) {
|
// throw new HTTPException(401, {
|
||||||
throw new HTTPException(401, {
|
// message: "GitHub installation name header missing",
|
||||||
message: "GitHub installation token header missing",
|
// });
|
||||||
});
|
// }
|
||||||
}
|
|
||||||
|
|
||||||
const encryptedAccessToken = request.headers.get(GITHUB_TOKEN_COOKIE);
|
// // We don't do anything with this token right now, but still confirm it
|
||||||
const decryptedAccessToken = encryptedAccessToken
|
// // exists as it will cause issues later on if it's not present.
|
||||||
? decryptSecret(encryptedAccessToken, encryptionKey)
|
// const encryptedInstallationToken = request.headers.get(
|
||||||
: undefined;
|
// GITHUB_INSTALLATION_TOKEN_COOKIE,
|
||||||
const decryptedInstallationToken = decryptSecret(
|
// );
|
||||||
encryptedInstallationToken,
|
// if (!encryptedInstallationToken) {
|
||||||
encryptionKey,
|
// throw new HTTPException(401, {
|
||||||
);
|
// message: "GitHub installation token header missing",
|
||||||
|
// });
|
||||||
|
// }
|
||||||
|
|
||||||
let user: GithubUser | undefined;
|
// const encryptedAccessToken = request.headers.get(GITHUB_TOKEN_COOKIE);
|
||||||
|
// const decryptedAccessToken = encryptedAccessToken
|
||||||
|
// ? decryptSecret(encryptedAccessToken, encryptionKey)
|
||||||
|
// : undefined;
|
||||||
|
// const decryptedInstallationToken = decryptSecret(
|
||||||
|
// encryptedInstallationToken,
|
||||||
|
// encryptionKey,
|
||||||
|
// );
|
||||||
|
|
||||||
if (!decryptedAccessToken) {
|
// let user: GithubUser | undefined;
|
||||||
// If there isn't a user access token, check to see if the user info is in headers.
|
|
||||||
// This would indicate a bot created the request.
|
|
||||||
const userIdHeader = request.headers.get(GITHUB_USER_ID_HEADER);
|
|
||||||
const userLoginHeader = request.headers.get(GITHUB_USER_LOGIN_HEADER);
|
|
||||||
if (!userIdHeader || !userLoginHeader) {
|
|
||||||
throw new HTTPException(401, {
|
|
||||||
message: "Github-User-Id or Github-User-Login header missing",
|
|
||||||
});
|
|
||||||
}
|
|
||||||
user = await verifyGithubUserId(
|
|
||||||
decryptedInstallationToken,
|
|
||||||
Number(userIdHeader),
|
|
||||||
userLoginHeader,
|
|
||||||
);
|
|
||||||
} else {
|
|
||||||
// Ensure we decrypt the token before passing to the verification function.
|
|
||||||
user = await verifyGithubUser(decryptedAccessToken);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (!user) {
|
// if (!decryptedAccessToken) {
|
||||||
throw new HTTPException(401, {
|
// // If there isn't a user access token, check to see if the user info is in headers.
|
||||||
message: "User not found",
|
// // This would indicate a bot created the request.
|
||||||
});
|
// const userIdHeader = request.headers.get(GITHUB_USER_ID_HEADER);
|
||||||
}
|
// const userLoginHeader = request.headers.get(GITHUB_USER_LOGIN_HEADER);
|
||||||
|
// if (!userIdHeader || !userLoginHeader) {
|
||||||
|
// throw new HTTPException(401, {
|
||||||
|
// message: "Github-User-Id or Github-User-Login header missing",
|
||||||
|
// });
|
||||||
|
// }
|
||||||
|
// user = await verifyGithubUserId(
|
||||||
|
// decryptedInstallationToken,
|
||||||
|
// Number(userIdHeader),
|
||||||
|
// userLoginHeader,
|
||||||
|
// );
|
||||||
|
// } else {
|
||||||
|
// // Ensure we decrypt the token before passing to the verification function.
|
||||||
|
// user = await verifyGithubUser(decryptedAccessToken);
|
||||||
|
// }
|
||||||
|
|
||||||
const reqCopy = request.clone();
|
// if (!user) {
|
||||||
const reqBody = await reqCopy.text();
|
// throw new HTTPException(401, {
|
||||||
if (!isAllowedUser(user.login)) {
|
// message: "User not found",
|
||||||
if (isRunReq(request.url)) {
|
// });
|
||||||
if (!apiKeysInRequestBody(reqBody)) {
|
// }
|
||||||
throw new HTTPException(401, {
|
|
||||||
message: API_KEY_REQUIRED_MESSAGE,
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return {
|
// const reqCopy = request.clone();
|
||||||
identity: user.id.toString(),
|
// const reqBody = await reqCopy.text();
|
||||||
is_authenticated: true,
|
// if (!isAllowedUser(user.login)) {
|
||||||
display_name: user.login,
|
// if (isRunReq(request.url)) {
|
||||||
metadata: {
|
// if (!apiKeysInRequestBody(reqBody)) {
|
||||||
installation_name: installationNameHeader,
|
// throw new HTTPException(401, {
|
||||||
},
|
// message: API_KEY_REQUIRED_MESSAGE,
|
||||||
permissions: LANGGRAPH_USER_PERMISSIONS,
|
// });
|
||||||
};
|
// }
|
||||||
|
// }
|
||||||
|
// }
|
||||||
|
|
||||||
|
// return {
|
||||||
|
// identity: user.id.toString(),
|
||||||
|
// is_authenticated: true,
|
||||||
|
// display_name: user.login,
|
||||||
|
// metadata: {
|
||||||
|
// installation_name: installationNameHeader,
|
||||||
|
// },
|
||||||
|
// permissions: LANGGRAPH_USER_PERMISSIONS,
|
||||||
|
// };
|
||||||
})
|
})
|
||||||
|
|
||||||
// THREADS: create operations with metadata
|
// THREADS: create operations with metadata
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue