收紧移动壳文件导入边界

移动壳文本和音频导入读取前校验可信文件大小

补充缺少 picker size 时的 File.size 回归测试

扩展移动壳配置门禁防止绕过读前大小检查

更新 HostBridge 载荷边界文档和共享决策
This commit is contained in:
2026-06-19 03:04:09 +08:00
parent deea0e8655
commit 9fcba9f4a5
6 changed files with 175 additions and 18 deletions
@@ -195,6 +195,33 @@ function extractMobileBridgeHandledMethods(source) {
return [...match[1].matchAll(/case '([^']+)':/g)].map((entry) => entry[1]);
}
function extractFunctionBody(source, functionName) {
const start = source.indexOf(`function ${functionName}`);
if (start === -1) {
throw new Error(`unable to read function ${functionName}`);
}
const openBrace = source.indexOf('{', start);
if (openBrace === -1) {
throw new Error(`unable to read function body ${functionName}`);
}
let depth = 0;
for (let index = openBrace; index < source.length; index += 1) {
const character = source[index];
if (character === '{') {
depth += 1;
} else if (character === '}') {
depth -= 1;
if (depth === 0) {
return source.slice(openBrace + 1, index);
}
}
}
throw new Error(`unable to read complete function body ${functionName}`);
}
function assertNoBlockedMobileChannelDependencies(packageJson, packageLabel) {
const dependencySections = [
'dependencies',
@@ -559,6 +586,24 @@ for (const localBoundary of forbiddenLocalPayloadBoundaryDeclarations) {
}
}
if (!hostBridgeSource.includes('function assertImportedFileSizeWithinLimit')) {
throw new Error('mobile shell must centralize imported file size checks');
}
for (const [functionName, readCall] of [
['importTextFile', 'file.text()'],
['importAudioFile', 'file.base64()'],
]) {
const functionBody = extractFunctionBody(hostBridgeSource, functionName);
const sizeCheckIndex = functionBody.indexOf('assertImportedFileSizeWithinLimit(');
const readIndex = functionBody.indexOf(readCall);
if (sizeCheckIndex === -1 || readIndex === -1 || sizeCheckIndex > readIndex) {
throw new Error(
`mobile shell ${functionName} must check file size before ${readCall}`,
);
}
}
for (const profileSource of [
'HOST_BRIDGE_EXPO_MOBILE_BASE_CAPABILITIES',
'HOST_BRIDGE_EXPO_MOBILE_IOS_CAPABILITIES',