-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathconfig_api.py
More file actions
196 lines (167 loc) · 7.01 KB
/
Copy pathconfig_api.py
File metadata and controls
196 lines (167 loc) · 7.01 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
"""
API routes for configuration — mirrors:
src/app/api/detect-environment/route.ts GET /api/detect-environment
src/app/api/validate-path/route.ts POST /api/validate-path
src/app/api/set-workspace/route.ts POST /api/set-workspace
src/app/api/get-username/route.ts GET /api/get-username
"""
import logging
import os
import subprocess
import sys
from flask import Blueprint, Response, request
from api.flask_config import json_response
from utils.path_validation import WorkspacePathError, validate_workspace_path
from utils.workspace_path import set_workspace_path_override
bp = Blueprint("config_api", __name__)
_logger = logging.getLogger(__name__)
@bp.route("/api/detect-environment")
def detect_environment() -> Response:
"""Detect runtime OS, WSL, and SSH-remote context (GET /api/detect-environment).
Returns:
JSON with ``os``, ``isWSL``, and ``isRemote``. Falls back to safe defaults
on detection errors.
"""
try:
is_wsl = False
is_remote = bool(
os.environ.get("SSH_CONNECTION")
or os.environ.get("SSH_CLIENT")
or os.environ.get("SSH_TTY")
)
if sys.platform != "win32":
try:
release = subprocess.check_output(
["uname", "-r"], text=True, stderr=subprocess.DEVNULL
).lower()
is_wsl = "microsoft" in release or "wsl" in release
except Exception:
pass
return json_response({
"os": sys.platform,
"isWSL": is_wsl,
"isRemote": is_remote,
})
except Exception as e:
_logger.warning(
"Failed to detect environment: %s (%s)",
e,
type(e).__name__,
exc_info=True,
)
return json_response({"os": "unknown", "isWSL": False, "isRemote": False})
@bp.route("/api/validate-path", methods=["POST"])
def validate_path() -> tuple[Response, int] | Response:
"""Validate a workspace storage path without persisting it (POST /api/validate-path).
Uses the same rules as :func:`set_workspace` (realpath, Cursor markers; issue #15).
Args:
path: Workspace storage root from JSON body ``{"path": "..."}``.
Returns:
JSON with ``valid``, ``workspaceCount``, and canonical ``path`` on success.
``valid`` is ``false`` when the path fails validation or contains no
workspace folders with ``state.vscdb``. Invalid JSON body returns
``{"valid": false, "error": "invalid JSON body", "workspaceCount": 0}``.
Path validation errors return ``{"valid": false, "error": "...", "workspaceCount": 0}``.
500 with ``{"valid": false, "error": "Failed to validate path"}`` on
unexpected failure.
"""
try:
body = request.get_json(silent=True) or {}
if not isinstance(body, dict):
return json_response(
{"valid": False, "error": "invalid JSON body", "workspaceCount": 0}
)
raw = body.get("path", "")
try:
canonical = validate_workspace_path(raw)
except WorkspacePathError as e:
return json_response({"valid": False, "error": str(e), "workspaceCount": 0})
workspace_count = 0
for name in os.listdir(canonical):
full = os.path.join(canonical, name)
if os.path.isdir(full):
db = os.path.join(full, "state.vscdb")
if os.path.isfile(db):
workspace_count += 1
return json_response(
{
"valid": workspace_count > 0,
"workspaceCount": workspace_count,
"path": canonical,
}
)
except Exception as e:
_logger.error(
"Validation error: %s (%s)",
e,
type(e).__name__,
exc_info=True,
)
return json_response({"valid": False, "error": "Failed to validate path"}, 500)
@bp.route("/api/set-workspace", methods=["POST"])
def set_workspace() -> tuple[Response, int] | Response:
"""Persist a validated workspace storage path (POST /api/set-workspace).
Args:
path: Workspace storage root from JSON body ``{"path": "..."}``.
Canonicalized via :func:`utils.path_validation.validate_workspace_path`
before storing the thread-safe module override.
Returns:
``{"success": true, "path": "..."}`` on success. 400 for invalid path or
body; 500 when override storage fails.
"""
# Reject non-dict JSON bodies (array / string / number / null). Without
# this, get_json returns the value directly, the truthy fallback `or {}`
# is bypassed, and `body.get("path", "")` raises AttributeError — which
# the outer Exception handler then mis-reports as a 500 server error
# instead of a 400 client error. (CodeRabbit on PR #16.)
body = request.get_json(silent=True)
if not isinstance(body, dict):
return json_response({"error": "request body must be a JSON object"}, 400)
raw = body.get("path", "")
# Validate the supplied path BEFORE storing the override (issue #15).
# validate_workspace_path collapses `..` traversal AND resolves symlinks
# via realpath, then enforces that the canonical target is an existing
# directory containing Cursor workspace markers. Returns the canonical
# path so we store that, not whatever the caller sent.
try:
canonical = validate_workspace_path(raw)
except WorkspacePathError as e:
return json_response({"error": str(e)}, 400)
except Exception: # noqa: BLE001 — only here as a fallback
return json_response({"error": "Failed to validate workspace path"}, 500)
try:
set_workspace_path_override(canonical)
except Exception: # noqa: BLE001 — keep the response shape structured JSON
return json_response({"error": "Failed to set workspace path"}, 500)
return json_response({"success": True, "path": canonical})
@bp.route("/api/get-username")
def get_username() -> Response:
"""Return the detected Windows/WSL username (GET /api/get-username).
Returns:
JSON ``{"username": "..."}``. Falls back to ``YOUR_USERNAME`` when
detection fails.
"""
try:
username = "YOUR_USERNAME"
if sys.platform == "win32":
username = os.environ.get("USERNAME") or os.getlogin()
else:
try:
output = subprocess.check_output(
["cmd.exe", "/c", "echo", "%USERNAME%"],
text=True,
stderr=subprocess.DEVNULL,
)
username = output.strip()
except Exception:
import getpass
username = getpass.getuser()
return json_response({"username": username})
except Exception as e:
_logger.warning(
"Failed to get username: %s (%s)",
e,
type(e).__name__,
exc_info=True,
)
return json_response({"username": "YOUR_USERNAME"})