Commit Graph

15 Commits

Author SHA1 Message Date
Serendipity 276a1401f4 fix: content 模式默认 file_name 改用 UUID 防并发覆盖 2026-07-10 15:27:19 +08:00
Serendipity 298f13721c fix: 统一 CLI/API 路径安全检查为 is_path_within_workspace 2026-07-10 15:19:17 +08:00
Serendipity 1eb6f44ef4 fix: delete_document 的 collection 参数添加正则校验 2026-07-10 15:18:56 +08:00
Serendipity 0a4a4c766c fix: search_documents 端点添加异常处理防止 traceback 泄露 2026-07-10 15:18:46 +08:00
Serendipity 284a4b9e09 fix: 修复 CORS allow_credentials 与 allow_origins=* 冲突 2026-07-10 15:18:39 +08:00
Serendipity 405303e82c fix: 修复 44 个代码审查问题 (CRITICAL/HIGH/MEDIUM/LOW)
Batch 1 — CRITICAL (1):
- 提取 is_safe_path() 到 src/core/security.py 公共模块
- CLI 和 ingest_obsidian.py 统一添加路径遍历防护

Batch 2 — HIGH (13) + 架构重构:
- CLI 复用 deps.py AppState, 消除 30 行重复代码
- AppState/get_state 添加线程安全锁
- serve 命令传递 --config 到 uvicorn (H1)
- OpenAIEmbedder 懒创建+复用 HTTP 客户端 (H2)
- DashscopeEmbedder import 移到模块顶部 (H3)
- 路径检查改用 os.path.commonpath (H4)
- embedder.embed() 返回值长度检查 (H5)
- 健康检查不泄露内部错误详情 (H7)
- /api/v1/collections 添加 API Key 认证 (H8)
- API Key 使用 hmac.compare_digest 恒定时间比较 (H9)
- 添加 CORS 中间件 (H10)
- ServerConfig 支持 SSL 配置 (H11)
- HF_ENDPOINT 修改添加详细注释 (H12)

Batch 3 — MEDIUM (20) + Splitter Protocol:
- 定义 Splitter(Protocol) 接口, DocumentIngestor 接受可选 splitter
- DashScope 响应添加结构验证 (M2)
- ingest_obsidian.py 支持 CLI 参数和 OBSIDIAN_DIRS 环境变量 (M6)
- scripts/serve.py 添加废弃警告 (M7)
- content 限制 500KB, collection 正则限制字符集 (M12-M14)
- 默认监听地址 127.0.0.1 (M16)
- 添加安全响应头中间件 (M17)
- verify_api_key 认证失败记录日志 (M19)

Batch 4 — LOW (10):
- CLI emoji 清理为纯文本标记 (L5)
- logging.basicConfig 移到 FastAPI lifespan (L1)
- VectorDB 添加 write_guard() 上下文管理器 (L3)
- IngestRequest file_path/content 互斥校验 (L10)
- ingest_obsidian.py 注释修正 (L6)

测试: 46 → 70 (+24)
- tests/test_security.py: 11 个路径安全测试
- tests/test_deps.py: 11 个依赖注入测试

Co-Authored-By: Claude <noreply@anthropic.com>
2026-07-06 16:56:38 +08:00
Serendipity 0aee167085 feat: multi-collection support — each project uses its own isolated collection 2026-07-05 02:07:02 +08:00
Serendipity 441ba8ab86 test: add DELETE endpoint tests and ingest integration tests 2026-07-05 01:46:59 +08:00
Serendipity 4114a168b4 refactor: FastAPI Depends injection replacing globals, real health check, logging config 2026-07-05 01:46:59 +08:00
Serendipity 10eda446ea fix: add field validation to API request models (top_k limit, file_name pattern) 2026-07-05 01:46:58 +08:00
Serendipity 157155c0d2 fix: add API key auth, rate limiting, and safe error messages 2026-07-05 01:46:58 +08:00
Serendipity 2ef0cf4a4e fix: add path traversal protection to ingest endpoint 2026-07-05 01:46:58 +08:00
Serendipity 5dcf1eed52 fix: remove api_key from config.yaml, read from EMBED_API_KEY env var; unify config path constant 2026-07-05 01:46:58 +08:00
Serendipity 2f0aa38fbf fix: add root redirect to /docs and show localhost in serve output 2026-07-05 01:46:58 +08:00
Serendipity d021390fd3 feat: add FastAPI HTTP API layer
- Implement FastAPI server with health, collections, ingest, search, and delete endpoints
- Add Pydantic request models for ingest and search
- Add lazy singleton initialization for DB, embedder, and services
- Support environment variable override for data dir and collection name
- Add integration tests with TestClient and temp directory
- Set TRANSFORMERS_OFFLINE/HF_HUB_OFFLINE for offline model loading in tests
2026-07-05 01:46:44 +08:00