refactor(monitoring): N2 - tach monitoring_tab.py, CanonicalAuditLogger, MonitoringQueryService, go circular import, sandbox matrix
- ui/monitoring_tab.py (1546 dong) tach thanh presentation/monitoring/** (container + 7 tab/card + shared helper), ui/monitoring_tab.py con lai re-export shim de app.py khong doi. - infrastructure/telemetry/audit_logger.py: CanonicalAuditLogger, core/audit_log.py thanh wrapper mong, tuong thich nguoc 100% voi schema .jsonl cu. - application/monitoring/monitoring_query_service.py: MonitoringQueryService read-only, filter/sort/pagination, khong import PySide6. - Go circular import model_pricing<->usage_tracker va agent_security<-> agent_security_alert (core/agent_security_types.py moi). - infrastructure/sandbox/sandbox_capabilities.py: SandboxCapabilityMatrix theo OS (Windows/Linux/macOS), chua dau noi vao core/sandbox_manager.py. - conftest.py: sua loi checkout khong ten cowork_local khien pytest import nham thu muc khac. - 77 test moi, 167/167 pass. QA da xac nhan UI/business logic khong doi (xem evidence/report/unified_report.html). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
86c27e2e79
commit
40b12ecb15
+2
-19
@@ -27,27 +27,12 @@ from __future__ import annotations
|
||||
|
||||
import json
|
||||
import re
|
||||
from dataclasses import dataclass
|
||||
from typing import List, Optional
|
||||
|
||||
from ..providers.base import Provider
|
||||
from . import security_rules
|
||||
|
||||
|
||||
class SecurityBlocked(RuntimeError):
|
||||
"""A guardrail refused an action. ``verdict`` carries the full detail for
|
||||
the admin alert; ``str(exc)`` is the short, user-facing reason."""
|
||||
|
||||
def __init__(self, verdict: "SecurityVerdict"):
|
||||
super().__init__(verdict.reason or f"Blocked by agent security ({verdict.layer}).")
|
||||
self.verdict = verdict
|
||||
|
||||
|
||||
@dataclass
|
||||
class SecurityVerdict:
|
||||
allowed: bool
|
||||
reason: str = ""
|
||||
layer: str = "" # "prompt" | "attachment" | "command"
|
||||
from .agent_security_alert import notify_admin
|
||||
from .agent_security_types import SecurityBlocked, SecurityVerdict
|
||||
|
||||
|
||||
def combined_rules_text(config, max_chars: int = 8000, agent_kind: str = "cowork") -> str:
|
||||
@@ -236,7 +221,6 @@ def enforce_prompt(provider: Provider, messages: List[dict], config, emit,
|
||||
emit({"type": "notice", "level": "warning",
|
||||
"text": f"🛡 Yêu cầu bị chặn bởi Agent Security: {verdict.reason}"})
|
||||
from . import audit_log
|
||||
from .agent_security_alert import notify_admin
|
||||
|
||||
audit_log.record("security_block", "prompt", False, verdict.reason)
|
||||
notify_admin(config, verdict, detail=user_text[:1000])
|
||||
@@ -266,7 +250,6 @@ def enforce_command(provider: Provider, name: str, args: dict, config, emit,
|
||||
emit({"type": "notice", "level": "warning",
|
||||
"text": f"🛡 Lệnh bị chặn bởi Agent Security ({verdict.layer}): {verdict.reason}"})
|
||||
from . import audit_log
|
||||
from .agent_security_alert import notify_admin
|
||||
|
||||
audit_log.record("security_block", name, False, f"{verdict.layer}: {verdict.reason}")
|
||||
notify_admin(config, verdict, detail=command)
|
||||
|
||||
Reference in New Issue
Block a user