| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280 | package decoderimport (	"archive/zip"	"bytes"	"errors"	"fmt"	"io"	"io/fs"	"os"	"path"	"path/filepath"	"strconv"	"strings"	"github.com/langgenius/dify-plugin-daemon/internal/utils/parser"	"github.com/langgenius/dify-plugin-daemon/pkg/entities/plugin_entities")type ZipPluginDecoder struct {	PluginDecoder	PluginDecoderHelper	reader *zip.Reader	err    error	sig        string	createTime int64	thirdPartySignatureVerificationConfig *ThirdPartySignatureVerificationConfig}type ThirdPartySignatureVerificationConfig struct {    Enabled bool    PublicKeyPaths []string}func newZipPluginDecoder(binary []byte, thirdPartySignatureVerificationConfig *ThirdPartySignatureVerificationConfig) (*ZipPluginDecoder, error) {	reader, err := zip.NewReader(bytes.NewReader(binary), int64(len(binary)))	if err != nil {		return nil, errors.New(strings.ReplaceAll(err.Error(), "zip", "difypkg"))	}	decoder := &ZipPluginDecoder{		reader: reader,		err:    err,		thirdPartySignatureVerificationConfig: thirdPartySignatureVerificationConfig,	}	err = decoder.Open()	if err != nil {		return nil, err	}	if _, err := decoder.Manifest(); err != nil {		return nil, err	}	return decoder, nil}// NewZipPluginDecoder is a helper function to create ZipPluginDecoderfunc NewZipPluginDecoder(binary []byte) (*ZipPluginDecoder, error) {	return newZipPluginDecoder(binary, nil)}// NewZipPluginDecoderWithThirdPartySignatureVerificationConfig is a helper function// to create a ZipPluginDecoder with a third party signature verificationfunc NewZipPluginDecoderWithThirdPartySignatureVerificationConfig(binary []byte, thirdPartySignatureVerificationConfig *ThirdPartySignatureVerificationConfig) (*ZipPluginDecoder, error) {	return newZipPluginDecoder(binary, thirdPartySignatureVerificationConfig)}// NewZipPluginDecoderWithSizeLimit is a helper function to create a ZipPluginDecoder with a size limit// It checks the total uncompressed size of the plugin package and returns an error if it exceeds the max sizefunc NewZipPluginDecoderWithSizeLimit(binary []byte, maxSize int64) (*ZipPluginDecoder, error) {	reader, err := zip.NewReader(bytes.NewReader(binary), int64(len(binary)))	if err != nil {		return nil, errors.New(strings.ReplaceAll(err.Error(), "zip", "difypkg"))	}	totalSize := int64(0)	for _, file := range reader.File {		totalSize += int64(file.UncompressedSize64)		if totalSize > maxSize {			return nil, errors.New(				"plugin package size is too large, please ensure the uncompressed size is less than " +					strconv.FormatInt(maxSize, 10) + " bytes",			)		}	}	return newZipPluginDecoder(binary, nil)}func (z *ZipPluginDecoder) Stat(filename string) (fs.FileInfo, error) {	f, err := z.reader.Open(filename)	if err != nil {		return nil, err	}	defer f.Close()	return f.Stat()}func (z *ZipPluginDecoder) Open() error {	if z.reader == nil {		return z.err	}	return nil}func (z *ZipPluginDecoder) Walk(fn func(filename string, dir string) error) error {	if z.reader == nil {		return z.err	}	for _, file := range z.reader.File {		// split the path into directory and filename		dir, filename := path.Split(file.Name)		if err := fn(filename, dir); err != nil {			return err		}	}	return nil}func (z *ZipPluginDecoder) Close() error {	return nil}func (z *ZipPluginDecoder) ReadFile(filename string) ([]byte, error) {	if z.reader == nil {		return nil, z.err	}	file, err := z.reader.Open(filename)	if err != nil {		return nil, err	}	defer file.Close()	data := new(bytes.Buffer)	_, err = data.ReadFrom(file)	if err != nil {		return nil, err	}	return data.Bytes(), nil}func (z *ZipPluginDecoder) ReadDir(dirname string) ([]string, error) {	if z.reader == nil {		return nil, z.err	}	files := make([]string, 0)	dirNameWithSlash := strings.TrimSuffix(dirname, "/") + "/"	for _, file := range z.reader.File {		if strings.HasPrefix(file.Name, dirNameWithSlash) {			files = append(files, file.Name)		}	}	return files, nil}func (z *ZipPluginDecoder) FileReader(filename string) (io.ReadCloser, error) {	return z.reader.Open(filename)}func (z *ZipPluginDecoder) decode() error {	if z.reader == nil {		return z.err	}	signatureData, err := parser.UnmarshalJson[struct {		Signature string `json:"signature"`		Time      int64  `json:"time"`	}](z.reader.Comment)	if err != nil {		return err	}	pluginSig := signatureData.Signature	pluginTime := signatureData.Time	z.sig = pluginSig	z.createTime = pluginTime	return nil}func (z *ZipPluginDecoder) Signature() (string, error) {	if z.sig != "" {		return z.sig, nil	}	if z.reader == nil {		return "", z.err	}	err := z.decode()	if err != nil {		return "", err	}	return z.sig, nil}func (z *ZipPluginDecoder) CreateTime() (int64, error) {	if z.createTime != 0 {		return z.createTime, nil	}	if z.reader == nil {		return 0, z.err	}	err := z.decode()	if err != nil {		return 0, err	}	return z.createTime, nil}func (z *ZipPluginDecoder) Manifest() (plugin_entities.PluginDeclaration, error) {	return z.PluginDecoderHelper.Manifest(z)}func (z *ZipPluginDecoder) Assets() (map[string][]byte, error) {	return z.PluginDecoderHelper.Assets(z)}func (z *ZipPluginDecoder) Checksum() (string, error) {	return z.PluginDecoderHelper.Checksum(z)}func (z *ZipPluginDecoder) UniqueIdentity() (plugin_entities.PluginUniqueIdentifier, error) {	return z.PluginDecoderHelper.UniqueIdentity(z)}func (z *ZipPluginDecoder) ExtractTo(dst string) error {	// copy to working directory	if err := z.Walk(func(filename, dir string) error {		workingPath := path.Join(dst, dir)		// check if directory exists		if err := os.MkdirAll(workingPath, 0755); err != nil {			return err		}		bytes, err := z.ReadFile(filepath.Join(dir, filename))		if err != nil {			return err		}		filename = filepath.Join(workingPath, filename)		// copy file		if err := os.WriteFile(filename, bytes, 0644); err != nil {			return err		}		return nil	}); err != nil {		// if error, delete the working directory		os.RemoveAll(dst)		return errors.Join(fmt.Errorf("copy plugin to working directory error: %v", err), err)	}	return nil}func (z *ZipPluginDecoder) CheckAssetsValid() error {	return z.PluginDecoderHelper.CheckAssetsValid(z)}
 |