fix(ci): align lint-safe security paths

This commit is contained in:
elky
2026-09-05 03:19:53 +08:00
parent f5e1420ee6
commit 33d5cd5993
45 changed files with 180 additions and 132 deletions
@@ -686,8 +686,9 @@ pub(crate) async fn read_admin_external_models_cache(
match fetch_admin_external_models_from_source(state, request_id, proxy_node_id.as_deref()).await
{
Ok(payload) => {
if let Err(_) =
store_admin_external_models_cache(state, proxy_node_id.as_deref(), &payload).await
if store_admin_external_models_cache(state, proxy_node_id.as_deref(), &payload)
.await
.is_err()
{
warn!("failed to store fetched external models cache");
}
@@ -314,7 +314,7 @@ async fn release_codex_agent_identity_leases(
leases: Vec<RuntimeLockLease>,
) {
for lease in leases {
if let Err(_) = state.runtime_state().lock_release(&lease).await {
if state.runtime_state().lock_release(&lease).await.is_err() {
tracing::warn!(
lock_key = %lease.key,
"gateway Agent Identity enrollment lock release failed"
@@ -552,7 +552,13 @@ pub(super) async fn seed_provider_oauth_pool_score(
now_unix_secs,
pool_config.score_rules,
);
if let Err(_) = state.app().data.upsert_pool_member_score(upsert).await {
if state
.app()
.data
.upsert_pool_member_score(upsert)
.await
.is_err()
{
tracing::debug!(
provider_id = %provider_id,
key_id = %key.id,
@@ -7632,10 +7632,11 @@ impl<'a> AdminAppState<'a> {
// Legacy uploads historically normalize an omitted rate limit to zero. Rollback
// checkpoints instead preserve the nullable database value exactly.
let rate_limit = imported_rate_limit.unwrap_or(0);
let rate_limit_value = mode
.is_rollback_checkpoint()
.then_some(imported_rate_limit)
.unwrap_or(Some(rate_limit));
let rate_limit_value = if mode.is_rollback_checkpoint() {
imported_rate_limit
} else {
Some(rate_limit)
};
let concurrent_limit = invalid_value!(imported_optional_i32(
key.get("concurrent_limit"),
"concurrent_limit"
@@ -8364,7 +8365,7 @@ impl<'a> AdminAppState<'a> {
)));
}
if let Some(wallet_id) = created_wallet_id {
if let Some(journal) = mutation_journal.as_deref_mut() {
if let Some(journal) = mutation_journal {
journal
.user_wallet_snapshots
.insert((user_id.to_string(), wallet_id), synced);
@@ -8433,7 +8434,7 @@ impl<'a> AdminAppState<'a> {
)));
}
if let Some(wallet_id) = created_wallet_id {
if let Some(journal) = mutation_journal.as_deref_mut() {
if let Some(journal) = mutation_journal {
journal
.api_key_wallet_snapshots
.insert((api_key_id.to_string(), wallet_id), synced);
@@ -349,6 +349,9 @@ fn load_and_sanitize_update_history(path: &Path) -> (Vec<UpdateHistoryEntry>, bo
}
fn sanitize_update_history_entries(entries: &mut Vec<UpdateHistoryEntry>) -> bool {
// Deliberately use a non-short-circuiting fold: every historical entry
// must be sanitized even after one entry changes.
#[allow(clippy::unnecessary_fold)]
let mut changed = entries.iter_mut().fold(false, |changed, entry| {
sanitize_update_history_entry(entry) || changed
});
@@ -455,7 +458,7 @@ fn read_update_metadata_file(path: &Path, max_bytes: usize) -> Result<Option<Vec
if bytes.len() > max_bytes {
return Err("更新元数据超过大小限制".to_string());
}
return Ok(Some(bytes));
Ok(Some(bytes))
}
#[cfg(not(unix))]
@@ -536,7 +539,7 @@ fn write_update_metadata_atomic(path: &Path, bytes: &[u8]) -> Result<(), String>
if result.is_err() {
let _ = unix_update_unlink_at(&parent, &temp_name);
}
return result;
result
}
#[cfg(not(unix))]
@@ -711,7 +714,7 @@ fn remove_update_metadata_file(path: &Path) -> Result<(), String> {
parent
.sync_all()
.map_err(|err| format!("同步更新元数据目录失败: {err}"))?;
return Ok(());
Ok(())
}
#[cfg(not(unix))]
@@ -1867,7 +1870,7 @@ fn switch_current_symlink_at(base_dir: &Path, version: &str) -> Result<(), Strin
parent
.sync_all()
.map_err(|err| format!("同步版本入口目录失败: {err}"))?;
return Ok(());
Ok(())
}
#[cfg(not(unix))]
@@ -607,17 +607,15 @@ fn payment_order_payload(
// A gateway response is a live checkout capability, not durable order
// history. Once the order is paid, terminal, or expired, suppress URLs,
// form parameters, and provider metadata from the public payload.
let gateway_response = record
.status
.eq_ignore_ascii_case("pending")
.then(|| {
record
.expires_at_unix_secs
.is_some_and(|expires_at| expires_at > Utc::now().timestamp().max(0) as u64)
})
.unwrap_or(false)
.then(|| record.gateway_response.clone())
.flatten();
let gateway_response = if record.status.eq_ignore_ascii_case("pending")
&& record
.expires_at_unix_secs
.is_some_and(|expires_at| expires_at > Utc::now().timestamp().max(0) as u64)
{
record.gateway_response.clone()
} else {
None
};
json!({
"id": record.id,
"order_no": record.order_no,
@@ -383,8 +383,7 @@ fn forwarded_header_last(headers: &http::HeaderMap, name: &str) -> Option<String
.filter_map(|value| value.to_str().ok())
.flat_map(|value| value.split(','))
.map(str::trim)
.filter(|value| !value.is_empty())
.last()
.rfind(|value| !value.is_empty())
.map(ToOwned::to_owned)
}
@@ -1054,11 +1054,14 @@ fn redirect_to(target: &str, params: Option<RedirectParams>) -> Response<Body> {
fn build_redirect_location(target: &str, params: Option<RedirectParams>) -> String {
let relative_target =
url::Url::parse(target).is_err() && target.starts_with('/') && !target.starts_with("//");
let Ok(mut url) = url::Url::parse(target).or_else(|_| {
relative_target
.then(|| url::Url::parse("http://aether.invalid").and_then(|base| base.join(target)))
.unwrap_or_else(|| Err(url::ParseError::RelativeUrlWithoutBase))
}) else {
let parsed_target = url::Url::parse(target).or_else(|_| {
if relative_target {
url::Url::parse("http://aether.invalid").and_then(|base| base.join(target))
} else {
Err(url::ParseError::RelativeUrlWithoutBase)
}
});
let Ok(mut url) = parsed_target else {
return target.to_string();
};
match params {