mirror of
https://github.com/HKUDS/nanobot.git
synced 2026-08-17 09:36:33 +03:00
fix(session): store session history outside the agent workspace
Session files lived under <workspace>/sessions/ (since #713), which is the on-disk scope of the agent's filesystem tools. With restrict_to_workspace enabled, an agent could read_file / list_dir every session transcript — including other users' or channels' conversations — bypassing the scoped sessions.py access layer entirely. Move session storage to ~/.nanobot/sessions/<sha256-of-resolved-workspace>[:16]/, outside the workspace. Per-workspace isolation (the goal of #713) is preserved via a hash of the resolved workspace path, so different workspaces keep independent session stores. A one-shot, idempotent migration moves legacy in-workspace *.jsonl files into the new location at store init. Scope note: this protects sessions whenever restrict_to_workspace=true. The default restrict_to_workspace=false leaves read_file unrestricted in general (not only sessions) and is a separate concern. Refs #5278
This commit is contained in:
+14
@@ -6,6 +6,7 @@ import os
|
||||
import ssl
|
||||
import sys
|
||||
from collections.abc import Iterator
|
||||
from pathlib import Path
|
||||
|
||||
import certifi
|
||||
import pytest
|
||||
@@ -22,6 +23,19 @@ def _isolate_nanobot_log_activation() -> Iterator[None]:
|
||||
logger.enable("nanobot")
|
||||
|
||||
|
||||
@pytest.fixture(autouse=True)
|
||||
def _isolate_sessions_root(tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> Iterator[None]:
|
||||
"""Redirect session storage away from the real ~/.nanobot/sessions.
|
||||
|
||||
Session storage lives under get_legacy_sessions_dir() (outside the workspace,
|
||||
per ADR-0001), so without redirection tests would write into the real home.
|
||||
"""
|
||||
root = tmp_path / "sessions-root"
|
||||
monkeypatch.setattr("nanobot.session.manager.get_legacy_sessions_dir", lambda: root)
|
||||
monkeypatch.setattr("nanobot.config.paths.get_legacy_sessions_dir", lambda: root)
|
||||
yield
|
||||
|
||||
|
||||
@pytest.fixture(scope="session", autouse=True)
|
||||
def _use_windows_system_ca_for_default_http_clients() -> Iterator[None]:
|
||||
"""Avoid reparsing certifi's CA bundle for every offline HTTP client.
|
||||
|
||||
Reference in New Issue
Block a user