safePython.py 3.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105
  1. #!/usr/bin/env python3
  2. # -*- coding: utf-8 -*-
  3. # File : safePython.py
  4. # Author: DaShenHan&道长-----先苦后甜,任凭晚风拂柳颜------
  5. # Date : 2022/8/28
  6. import io
  7. import tokenize
  8. from func_timeout import func_set_timeout
  9. from func_timeout.exceptions import FunctionTimedOut
  10. from urllib.parse import urljoin,quote,unquote
  11. import requests
  12. import time
  13. import json
  14. import re
  15. from lxml import etree
  16. import datetime
  17. import base64
  18. from utils.log import logger
  19. time_out_sec = 8 # 安全执行python代码超时
  20. class my_exception(Exception):
  21. def __init__(self, message):
  22. self.message = message
  23. def __str__(self):
  24. message = f'函数执行超时: "{self.message}"'
  25. return message
  26. @func_set_timeout(time_out_sec)
  27. def excute(*args):
  28. exec(*args)
  29. def check_unsafe_attributes(string):
  30. """
  31. 安全检测需要exec执行的python代码
  32. :param string:
  33. :return:
  34. """
  35. g = tokenize.tokenize(io.BytesIO(string.encode('utf-8')).readline)
  36. pre_op = ''
  37. for toktype, tokval, _, _, _ in g:
  38. if toktype == tokenize.NAME and pre_op == '.' and tokval.startswith('_'):
  39. attr = tokval
  40. msg = "access to attribute '{0}' is unsafe.".format(attr)
  41. raise AttributeError(msg)
  42. elif toktype == tokenize.OP:
  43. pre_op = tokval
  44. DEFAULT_PYTHON_CODE = """# 可用内置环境变量:
  45. # - log: log(message): 打印日志功能
  46. # - error: 弹出用户错误的弹窗
  47. # 返回变量值: result = {...}\n\n
  48. zyw_lists = env['hikerule.zyw.list'].with_context(active_test=True).sudo().search(
  49. [('option', '=', 'zy'), ('cate_id.name', '!=', '18+'),('cate_id.is_bad', '!=', True)])
  50. result = env['hikerule.zyw.list2data.wizard'].sudo().get_publish_value(zyw_lists)
  51. """
  52. class safePython:
  53. def __init__(self,name, code):
  54. self.name = name or '未定义'
  55. self.code = code
  56. def action_task_exec(self,call=None,params=None):
  57. """
  58. 接口调用执行函数
  59. :return:
  60. """
  61. if not params:
  62. params = []
  63. builtins = __builtins__
  64. builtins = dict(builtins).copy()
  65. for key in ['__import__','eval','exec','globals','dir','copyright','open','quit']:
  66. del builtins[key] # 删除不安全的关键字
  67. # print(builtins)
  68. global_dict = {'__builtins__': builtins,
  69. 'requests': requests, 'urljoin':urljoin,'quote':quote,'unquote': unquote,
  70. 'log': logger.info, 'json': json,'print':print,
  71. 're':re,'etree':etree,'time':time,'datetime':datetime,'base64':base64
  72. } # 禁用内置函数,不允许导入包
  73. try:
  74. check_unsafe_attributes(self.code)
  75. localdict = {'result': None}
  76. # 待解决windows下运行超时的问题
  77. base_code = self.code.strip()
  78. if call:
  79. logger.info(f'开始执行:{call}')
  80. try:
  81. # excute(to_run_code, global_dict, localdict)
  82. excute(base_code, global_dict, localdict)
  83. run = localdict.get(call)
  84. if run:
  85. localdict['result'] = run(*params)
  86. except FunctionTimedOut:
  87. raise my_exception(f'函数[{self.name}]运行时间超过{time_out_sec}秒,疑似死循环,已被系统切断')
  88. except Exception as e:
  89. ret = f'执行报错:{e}'
  90. logger.info(ret)
  91. return ret
  92. else:
  93. # print(global_dict)
  94. # print(localdict)
  95. ret = localdict['result']
  96. return ret