chore(开源脱敏): find-ui 扫描器去掉硬编码服务器路径 + 登记档案 140

- scripts/find-ui-scan.py:PROFILE_GLOB 改由 DSHS_USERS_DIR 注入,缺失即显式失败(不再写死
  /var/lib/dshs)⇒ 补上上一轮涉密外置扫描的唯一漏项(大小写不敏感扫描 1 → 0)
- scripts/find-ui.mjs:用 config/index.cjs#usersDir() 取值并随 ssh 命令注入远端;
  解析不出 POSIX 绝对路径即报错退出(⛔ 不静默回落,避免假阴性)
- dsh-server-docs/INDEX.md:登记 04-140(涉密内容外置到配置目录)

验证:py 语法 OK / node --check OK / 缺 env 显式 exit=2 / 实跑命中 8-8 个 UI 分区(与原行为一致)
This commit is contained in:
admin committed 2026-09-19 15:42:56 +08:00
1 parent 452924d89c
commit 0cdbf52c4a
3 files changed
+23 -2

No files matched your search

+9 -1
View File
@@ -13,10 +13,18 @@ scan 顺序:**自研(@dsh-local)在前**,官方在后 —— 排查时
"""
import glob
import json
import os
import re
import sys
PROFILE_GLOB = '/var/lib/dshs/users/*/home/profiles/web/node_modules/@dsh-local/*/lib/client.js'
# 用户根目录由调用方(`scripts/find-ui.mjs`)通过 `DSHS_USERS_DIR` 传入 —— 它从 `config/` 读,
# 不在这里写死服务器布局。⛔ 缺失时**显式失败**,绝不回落到某个猜测值(静默 0 命中 = 假阴性)。
USERS_DIR = os.environ.get('DSHS_USERS_DIR', '').rstrip('/')
if not USERS_DIR:
sys.stderr.write('!! 未收到 DSHS_USERS_DIR(用户数据根)—— 由 scripts/find-ui.mjs 注入,勿手动直连\n')
sys.exit(2)
PROFILE_GLOB = USERS_DIR + '/*/home/profiles/web/node_modules/@dsh-local/*/lib/client.js'
OFFICIAL_GLOB = '/usr/local/lib/node_modules/@deepseek-ai/dsh/node_modules/@deepseek-ai/*/lib/client.js'
# 注册对象形如: { name: "settings.section", id: "x", order: 100, label: … }
+13 -1
View File
@@ -26,10 +26,22 @@ import { readFileSync } from 'node:fs'
import { spawnSync } from 'node:child_process'
import { fileURLToPath } from 'node:url'
import { dirname, join } from 'node:path'
import cfg from '../config/index.cjs'
const ROOT = join(dirname(fileURLToPath(import.meta.url)), '..')
const SSH = process.env.DSHS_SSH ?? 'bt-server'
// 用户数据根:从 `config/` 读(本机权威单一来源),随 ssh 命令注入远端扫描器 ——
// ⛔ 扫描器内不写死服务器布局。解析不出来就**显式失败**,不猜、不静默(静默 0 命中 = 假阴性)。
const USERS_DIR = cfg.usersDir().replace(/\\/g, '/').replace(/\/+$/, '')
if (!USERS_DIR.startsWith('/')) {
console.error(
'!! 解析不出远端用户数据根:' + USERS_DIR + '\n' +
' 本机 config/platform.env 需含 DSHS_DATA_ROOT(或用 DSHS_USERS_DIR 覆盖),见 config/README.md。',
)
process.exit(2)
}
const argv = process.argv.slice(2)
const asMd = argv.includes('--md')
const withGrep = argv.includes('--grep')
@@ -39,7 +51,7 @@ const keyword = argv.find((a) => !a.startsWith('--')) ?? ''
const scanner = readFileSync(join(ROOT, 'scripts', 'find-ui-scan.py'), 'utf8')
const r = spawnSync(
'ssh',
['-o', 'BatchMode=yes', '-o', 'ConnectTimeout=15', '-o', 'StrictHostKeyChecking=accept-new', SSH, 'python3 -'],
['-o', 'BatchMode=yes', '-o', 'ConnectTimeout=15', '-o', 'StrictHostKeyChecking=accept-new', SSH, `DSHS_USERS_DIR='${USERS_DIR}' python3 -`],
{ input: scanner, encoding: 'utf8', maxBuffer: 1 << 24 },
)
if (r.status !== 0 && (r.stdout ?? '') === '') {