Restrict HTTP file artifact inputs
This commit is contained in:
@@ -34,6 +34,7 @@ schema_dir: /opt/scriptorium/schemas
|
||||
|
||||
server:
|
||||
addr: 127.0.0.1:8080
|
||||
artifact_root: /var/lib/scriptorium/artifacts
|
||||
|
||||
defaults:
|
||||
render_format: text
|
||||
@@ -47,12 +48,14 @@ Top-level fields:
|
||||
- `profile_dir` (optional): default custom profile definition directory.
|
||||
- `schema_dir` (optional): base directory for schema files used by `json_schema` validation.
|
||||
- `server.addr` (optional): default listen address for `serve`.
|
||||
- `server.artifact_root` (optional): base directory for HTTP `file` input references.
|
||||
- `defaults.render_format` (optional): default `render` output format (`text` or `json`).
|
||||
|
||||
Built-in defaults:
|
||||
|
||||
- `schema_dir`: `.`
|
||||
- `server.addr`: `:8080`
|
||||
- `server.artifact_root`: unset; HTTP `file` input references are rejected until configured.
|
||||
- `defaults.render_format`: `text`
|
||||
|
||||
Validation behavior:
|
||||
@@ -60,6 +63,15 @@ Validation behavior:
|
||||
- Config decoding is strict; unknown YAML fields are rejected.
|
||||
- Raw API key fields are not supported in `config.yml`.
|
||||
|
||||
HTTP artifact root behavior:
|
||||
|
||||
- `server.artifact_root` applies only to `serve`.
|
||||
- HTTP `inline` input references work without an artifact root.
|
||||
- HTTP `file` input references are resolved against `server.artifact_root` and must stay inside it.
|
||||
- Relative traversal and absolute paths outside the root are rejected.
|
||||
- Symlinks inside the root are followed by the operating system; do not make the artifact root writable by untrusted users.
|
||||
- CLI `run` and `render` file inputs keep their normal direct filesystem path behavior.
|
||||
|
||||
## Prompt Definition Files
|
||||
|
||||
Prompt definitions are YAML files anywhere under `prompt_dir`, including nested subdirectories.
|
||||
@@ -269,6 +281,9 @@ Rules:
|
||||
- Invalid generated JSON causes validation status `failed` (not a runtime error).
|
||||
|
||||
Supported artifact reference types for request inputs are `file` and `inline`.
|
||||
For HTTP `serve`, `file` references require `server.artifact_root` and must stay
|
||||
inside that root. CLI `run` and `render` file inputs are not restricted by
|
||||
`server.artifact_root`.
|
||||
|
||||
## Secrets Handling
|
||||
|
||||
|
||||
Reference in New Issue
Block a user