eigent/backend/app/file_access/upload_file_access.py
Tong Chen 6c827a3d06
refactor: establish Brain-centered architecture and frontend/backend separation foundations (#1597)
Co-authored-by: Douglas <douglas.ym.lai@gmail.com>
Co-authored-by: Douglas Lai <115660088+Douglasymlai@users.noreply.github.com>
2026-05-01 17:03:33 +08:00

72 lines
2.8 KiB
Python

# ========= Copyright 2025-2026 @ Eigent.ai All Rights Reserved. =========
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
# ========= Copyright 2025-2026 @ Eigent.ai All Rights Reserved. =========
from pathlib import Path
from app.file_access.interface import IFileAccess
class UploadFileAccess(IFileAccess):
"""Only handle uploaded files, path restricted to workspace/{session_id}/ (Web/Channel)"""
def __init__(self, workspace_root: str = "~/.eigent/workspace") -> None:
self.workspace_root = Path(workspace_root).expanduser()
def read_file(self, path: str) -> str:
resolved = self._ensure_in_workspace(path)
return resolved.read_text(encoding="utf-8")
def read_file_binary(self, path: str) -> bytes:
resolved = self._ensure_in_workspace(path)
return resolved.read_bytes()
def write_file(self, path: str, content: str | bytes) -> None:
resolved = self._ensure_in_workspace(path)
resolved.parent.mkdir(parents=True, exist_ok=True)
if isinstance(content, str):
resolved.write_text(content, encoding="utf-8")
else:
resolved.write_bytes(content)
def exists(self, path: str) -> bool:
try:
resolved = self._ensure_in_workspace(path)
return resolved.exists()
except PermissionError:
return False
def list_dir(self, path: str) -> list[str]:
resolved = self._ensure_in_workspace(path)
return [p.name for p in resolved.iterdir()]
def get_working_directory(self, session_id: str) -> str:
return str(self.workspace_root / session_id)
def resolve_path(self, path_or_id: str, session_id: str) -> str:
if not path_or_id.startswith("upload://"):
raise PermissionError("Only uploaded files are accessible")
return self._resolve_upload_id(path_or_id, session_id)
def _resolve_upload_id(self, path_or_id: str, session_id: str) -> str:
file_id = path_or_id.removeprefix("upload://")
return str(self.workspace_root / session_id / "uploads" / file_id)
def _ensure_in_workspace(self, path: str) -> Path:
p = Path(path).resolve()
root = self.workspace_root.resolve()
try:
p.relative_to(root)
except ValueError:
raise PermissionError("Path outside workspace")
return p