Repository navigation
feat(browser): Full CDP 调试通道与高度敏感权限隔离 - #77
Merged
Merged
Conversation
5 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
背景
issue #42(父任务 #33):Prayu 已区分受限 CDP 与完整 CDP 的权限概念,但 Full CDP 仍没有真实、独立的产品执行通道。需要在不污染 Safe Web 的前提下,为受信任调试场景实现显式、限时、高度敏感的 CDP 能力。
本次改动
browser_full_cdp_authorization.v1):AuthorizeFullCDP仅在 Run 使用full_debug权限 + 操作者确认 + 进程FullDebugEnabled+RestrictedCDPEnabled+ 逐次确认 同时满足时签发;TTL 5 分钟,绑定 Run/Workspace/可执行身份/权限 revision/scope;InstructionAuthorized恒为 false(网页指令永不提升权限)。browser_full_cdp_start_authorization.v1):AuthorizeFullCDPStart独立于 Safe Web 启动,要求 maximum-access debug 权限,且不携带 Safe Web 的 WFP 隔离/loopback 导航标志。FullCDPSession复用受限 CDP WebSocket 客户端,但仅在fullCDP=true时接纳额外高敏方法集(Network.getCookies/Network.getAllCookies/Storage.getCookies/Fetch.fulfillRequest/Runtime.*/Log.enable);RequestCapture/CookieAccess返回元数据 only(无 header/cookie 值/body),脱敏由类型构造保证。FullCDPService.Open(app 层)串起构建 ProfileCTFLab 会话 → AuthorizeFullCDP → OpenFullCDPSession。测试覆盖
browserruntime:AuthorizeFullCDP(正常 + 4 个拒绝路径:Safe Web 会话/restricted 权限/未确认/full-debug 门关/restricted-cdp 门关)+ 5 个篡改拒收;AuthorizeFullCDPStart(FullDebug 通过 / restricted 拒绝)。application:FullCDPService.Open未确认 fail-closed(自包含 fixture,不依赖 feat(browser): 受限 Safe Web 操作者入口与 readiness 收据 #41)。browserLaunchFixture+production_runtime_test的既有事实链,不引入真实浏览器依赖。验证结果
go build ./...、go vet ./...通过。go test ./internal/browserruntime、go test ./internal/application全量通过。安全边界与非目标
RelaxOriginPolicy/AllowInsecureContent/IgnoreCertificateErrors恒拒绝);不连接已有浏览器;不用于后台无人值守公网攻击。run-permission-settings.tsx(full_debug的dangerous标签 + 独立PermissionConfirmation);调试操作走 CDP 传输而非 HTTP/UI,与 Safe Web 模式一致。Closes #42