Skip to content

feat(server): trust configured Unix socket requests - #2853

Open
qbisi wants to merge 1 commit into
OpenListTeam:mainfrom
qbisi:unix_file_trusted
Open

feat(server): trust configured Unix socket requests#2853
qbisi wants to merge 1 commit into
OpenListTeam:mainfrom
qbisi:unix_file_trusted

Conversation

@qbisi

@qbisi qbisi commented Jul 27, 2026

Copy link
Copy Markdown

增加scheme.unix_file_trusted,使得对于来自 unix_socket 的请求免认证。一个主要的用途是供服务器内部程序使用 unix_sock 挂载 webdav 以避免使用/泄漏 API_KEY 或 PASSWORD,unix_socket 的权限组相当于已经做了身份认证,nginx proxy pass可以使用http 端口以要求身份认证

Summary / 摘要

  • Add scheme.unix_file_trusted and OPENLIST_UNIX_FILE_TRUSTED; the zero-value default remains false.

  • Treat requests received through the configured Unix socket as an administrator without requiring account credentials, passwords, or an API key, including WebDAV requests.

  • Skip protected-download signature validation only for trusted Unix socket requests.

  • Keep existing HTTP and HTTPS authentication behavior unchanged.

  • This PR has breaking changes.
    / 此 PR 包含破坏性变更。

  • This PR changes public API, config, storage format, or migration behavior.
    / 此 PR 修改了公开 API、配置、存储格式或迁移行为。

  • This PR requires corresponding changes in related repositories.
    / 此 PR 需要关联仓库同步修改。

Testing / 测试

  • go test ./...
  • go test ./internal/conf ./server/middlewares ./server ./internal/bootstrap
  • gofmt -d internal/bootstrap/run.go internal/conf/config.go server/middlewares/auth.go server/middlewares/down.go server/webdav.go (no output)
  • Manual test / 手动测试: Not run.

Checklist / 检查清单

  • I have read CONTRIBUTING.
    / 我已阅读 CONTRIBUTING
  • I confirm this contribution follows the repository license, contribution policy, and code of conduct.
    / 我确认此贡献符合仓库许可证、贡献规范和行为准则。
  • I have formatted the changed code with gofmt, go fmt, or prettier where applicable.
    / 我已按适用情况使用 gofmtgo fmtprettier 格式化变更代码。
  • I have requested review from relevant maintainers or code owners where applicable.
    / 我已在适用情况下请求相关维护者或代码所有者审查。

AI Disclosure / AI 使用声明

  • This PR includes AI-assisted content.
    / 此 PR 包含 AI 辅助内容。

Tools used / 使用工具:

  • Codex

Usage scope / 使用范围:

  • Code generation / 代码生成

  • Tests / 测试

  • Review assistance / 审查辅助

  • I have reviewed and validated all AI-assisted content included in this PR.
    / 我已审核并验证此 PR 中的所有 AI 辅助内容。

  • I have ensured that all AI-assisted commits include Co-Authored-By attribution.
    / 我已确保所有 AI 辅助提交都包含 Co-Authored-By 归属信息。

  • I can reproduce all AI-assisted content included in this PR without any AI tools.
    / 我可以在没有任何 AI 工具的情况下重现此 PR 中包含的所有 AI 辅助内容。

- add unix_file_trusted configuration with a disabled zero-value default
- grant trusted Unix socket requests an admin identity without credentials
- bypass WebDAV authentication and download signatures only on the trusted socket

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
@qbisi
qbisi force-pushed the unix_file_trusted branch from 74cfd07 to 1ef5dcd Compare July 27, 2026 09:18
@qbisi
qbisi marked this pull request as ready for review July 29, 2026 21:40
@xrgzs xrgzs added enhancement Module: Server API and protocol changes labels Jul 31, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement Module: Server API and protocol changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants