Files
john 4e21ca937a
Deploy Documentation / deploy (push) Has been cancelled
Canary / Prepare Version (push) Has been cancelled
Canary / build-cli (push) Has been cancelled
Canary / Upload Install Script (push) Has been cancelled
Canary / bundle-desktop (push) Has been cancelled
Canary / bundle-desktop-intel (push) Has been cancelled
Canary / bundle-desktop-linux (push) Has been cancelled
Canary / bundle-desktop-windows (push) Has been cancelled
Canary / bundle-desktop-windows-cuda (push) Has been cancelled
Canary / Release (push) Has been cancelled
Unused Dependencies / machete (push) Has been cancelled
CI / changes (push) Has been cancelled
CI / Check Rust Code Format (push) Has been cancelled
CI / Build and Test Rust Project (push) Has been cancelled
CI / Build Rust Project on Windows (push) Has been cancelled
CI / Check MSRV (push) Has been cancelled
CI / Lint Rust Code (push) Has been cancelled
CI / Check Generated Schemas are Up-to-Date (push) Has been cancelled
CI / Test and Lint Electron Desktop App (push) Has been cancelled
CI / H5 Plaza Tests and Build (push) Has been cancelled
Live Provider Tests / check-fork (push) Has been cancelled
Live Provider Tests / changes (push) Has been cancelled
Live Provider Tests / Build Binary (push) Has been cancelled
Live Provider Tests / Smoke Tests (push) Has been cancelled
Live Provider Tests / Smoke Tests (Code Execution) (push) Has been cancelled
Live Provider Tests / Compaction Tests (push) Has been cancelled
Live Provider Tests / goose server HTTP integration tests (push) Has been cancelled
Publish Ask AI Bot Docker Image / docker (push) Has been cancelled
Publish Docker Image / docker (push) Has been cancelled
Scorecard supply-chain security / Scorecard analysis (push) Has been cancelled
Add TKMind platform extensions, H5/MindSpace stack, and deployment tooling.
Fork goose with custom MCP widgets, platform extensions (aider, git, web, search),
MindSpace H5 backend/frontend, Plaza/Ops UIs, and deploy scripts for tkmind.cn.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-14 21:30:20 +08:00

7.4 KiB

sidebar_position, title, sidebar_label, description
sidebar_position title sidebar_label description
8 Security, Desensitization, and Audit Security MindSpace tenant isolation, file and HTML security, PII handling, sharing, and audit controls

安全、脱敏与审计

安全目标

  • 用户之间严格隔离。
  • 私人区默认拒绝公开和外链。
  • Agent 只能访问任务授权资产。
  • 生成 HTML 不得危害平台会话或访问者。
  • 发布内容可追溯、可下线、可复查。
  • 安全控制由服务端执行,前端提示不构成安全边界。

威胁模型

需要覆盖:

  • 路径穿越和符号链接逃逸。
  • 猜测或枚举资产 ID。
  • 修改请求中的 user_idspace_idcategory_id
  • MIME 伪造、恶意压缩包和文件炸弹。
  • XSS、恶意跳转、追踪像素和 Cookie 读取。
  • HTML 引用私人文件或跨用户资源。
  • 分享 token 泄露和密码暴力破解。
  • Agent prompt injection 和越权工具调用。
  • 自定义正则导致 ReDoS。
  • 日志泄露敏感正文、token 和路径。
  • 竞态绕过配额、下线或发布扫描。

用户隔离

  • 所有 repository 方法显式接收 actor 和 owner。
  • 所有查询包含所有权条件。
  • 对不存在和无权访问统一返回 404。
  • 管理员访问走独立服务和审计动作。
  • 测试必须包含用户 A 使用用户 B 的每类 ID。

禁止:

GET /files?path=/users/john/private/a.pdf

允许:

GET /assets/{opaque_asset_id}

服务端根据当前身份解析真实存储 key。

路径和存储安全

  • 文件名仅用于展示,不参与存储 key。
  • 规范化 Unicode 和路径分隔符。
  • 拒绝绝对路径、..、空字节和设备名。
  • 本地存储使用 openat 类安全模式或完成 canonical path 校验。
  • 禁止跟随指向根目录外的符号链接。
  • 对象存储 key 由服务端生成。
  • 临时目录按任务隔离并设置权限与 TTL。

文件上传安全

  • 服务端检测文件签名和 MIME。
  • 配置允许类型和大小。
  • 压缩包限制层数、文件数量、展开总大小和压缩比。
  • 扫描恶意文件和宏。
  • 未扫描文件进入 quarantine,不可预览、下载或交给 Agent。
  • 图片重新编码以移除不必要元数据。
  • 文档解析在资源受限的隔离进程中执行。

HTML 和页面安全

首期默认策略

  • 禁止任意外部 JavaScript。
  • 移除 inline event handler。
  • 禁止 javascript: URL。
  • 禁止未授权 iframe、object、embed 和 form action。
  • 限制 meta refresh。
  • 外部图片走代理或复制到公开资源。
  • 禁止页面域读取管理域 cookie。

CSP 基线

按实际构建调整,但原则为:

default-src 'none'
img-src 'self' data:
style-src 'self' 'unsafe-inline'
script-src 'self'
font-src 'self'
connect-src 'none'
frame-src 'none'
base-uri 'none'
form-action 'none'
frame-ancestors 'self'

如果模板需要脚本,使用平台签名和版本化脚本,不允许页面自由写入。

预览 sandbox

  • iframe 使用最小 sandbox 权限。
  • 默认不启用 allow-same-originallow-scripts 的危险组合。
  • 预览域与管理域隔离。
  • 预览 URL 短期有效。

私有资源引用检查

发布构建器解析:

  • HTML srchrefsrcset
  • CSS url()@import
  • JavaScript 中平台资源引用,首期建议禁止用户 JavaScript。
  • 页面 manifest。

每个资源必须:

  • 属于发布者。
  • 是当前页面版本允许的资源。
  • 已复制为公开资源。
  • 通过安全扫描。

发现私人、OA、跨用户或不存在资源时阻断发布。

敏感信息类型

默认检测:

  • 手机号
  • 邮箱
  • 身份证
  • 银行卡
  • 地址
  • 人名
  • 公司名
  • 金额
  • 合同编号
  • 病历号
  • 学号
  • 工号
  • 精确地理位置
  • API key、access token 和私钥

规则需要按国家、地区、语言和场景版本化,不能仅依赖单一正则。

脱敏策略

策略 示例
保留前后 138****1234
星号替换 ********
标签替换 [手机号]
范围模糊 上海市***
金额区间 约 1-2 万元
删除 移除字段
仅摘要 不输出原文
禁止发布 高风险或无法可靠脱敏

脱敏必须:

  • 生成新资产。
  • 保留来源关联。
  • 记录规则版本和用户选择。
  • 对输出再次扫描。
  • 不在扫描 finding 中保存完整敏感值。

风险和发布决策

风险 行为
none 允许发布
low 提示,可发布
medium 展示详情并明确确认
high 阻断,必须处理
critical 隔离内容并通知安全处置

密钥、私钥、完整身份证、银行卡和跨用户资源引用默认至少为 high。

分享链接安全

  • token 使用加密安全随机数,至少 128 bit 熵。
  • 数据库只保存 token hash。
  • 可设置过期、撤销和最大访问次数。
  • 密码使用强哈希,不与用户密码共用。
  • 密码尝试按 IP、token 和设备限流。
  • 响应头禁止搜索引擎索引受保护页面。
  • 私密链接页面不得在用户公开主页展示。
  • 复制链接 UI 明确显示访问模式和过期时间。

认证和会话

  • 密码使用 Argon2id 或当前推荐强哈希。
  • 安全、HttpOnly、SameSite cookie。
  • 敏感操作考虑近期登录确认。
  • 登录和密码尝试限流。
  • 账号冻结立即撤销活跃会话。
  • CSRF、CORS 和 origin 校验按部署方式配置。

Agent 安全

  • Agent 不接收用户根目录。
  • 输入使用只读临时挂载或受控下载接口。
  • 输出只允许写入任务目录。
  • 默认禁用网络,按任务允许域名。
  • 工具调用受权限策略检查。
  • 文档中的 prompt injection 视为不可信内容。
  • Agent 不能改变自己的权限范围。
  • 任务 token 与用户登录 token 完全分离。

审计策略

高风险动作同步写审计:

  • 私人文件预览和下载。
  • Agent 读取私人资产。
  • 创建脱敏副本。
  • 发布、重新发布和下线。
  • 修改分享密码和过期时间。
  • 管理员读取或处置用户内容。

审计内容:

  • 谁。
  • 何时。
  • 从哪里。
  • 对什么对象。
  • 执行什么动作。
  • 结果和风险等级。
  • 请求和任务关联 ID。

审计中不得写入:

  • 密码。
  • 分享 token。
  • 文件正文。
  • 完整敏感值。
  • 可直接访问的内部存储 key。

安全响应头

管理端:

  • CSP
  • HSTS
  • X-Content-Type-Options
  • Referrer-Policy
  • Permissions-Policy
  • frame-ancestors

公开页:

  • 独立 CSP
  • X-Content-Type-Options
  • Referrer-Policy
  • 对受保护页使用 noindex, nofollow
  • 下载资源设置正确 Content-Disposition

安全运营

  • 规则版本和扫描器版本可追溯。
  • critical 命中产生告警。
  • 支持管理员紧急下线 Publication。
  • 定期执行跨用户授权测试。
  • 定期对账公开 bundle 与 Publication 状态。
  • 依赖漏洞、恶意文件扫描器和密钥轮换纳入运维。

安全验收清单

  • 路径穿越无法读取任何系统或其他用户文件。
  • 用户 A 无法通过替换 ID 操作用户 B 的资源。
  • 私人原资产无法直接发布。
  • 已下线页面无法从 CDN 或缓存继续访问。
  • 发布页无法读取管理会话 cookie。
  • XSS payload 在预览和正式页均被阻断。
  • 分享密码无法被无速率限制地尝试。
  • Agent 超时后 token 立即失效。
  • 日志和审计不存在完整敏感值。