Conversation
PROPFIND 返回的 D:href 由 davPath 拼出,而 davPathOf() 已经把 /dav 挂载 前缀剥掉。RFC 4918 要求 D:href 是完整请求 URI,因此按请求路径解析 href 的客户端 (rclone、Windows 资源管理器、RaiDrive 等)会丢弃全部条目,表现为目录为空。 改为从请求 URL 推导前缀,而不是硬编码 /dav —— index.ts 还会把发往任意路径的 WebDAV 方法交给同一个 router,此时前缀为空。 GuangYaPan 的 get_res_center_token 把 OSS 凭据嵌套在 data.creds 下,而类型定义 与校验都按平铺在 data 上读取,于是 accessKeyID / secretAccessKey 恒为 undefined, 所有上传都抛 "upload token is incomplete"。改为优先取 creds 并保留平铺回退,同时 把 OSS 签名与 x-oss-security-token 头也改用取到的局部变量。
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary / 摘要
修复两处独立缺陷,均已在真实 Cloudflare Workers 部署上验证:
1. WebDAV PROPFIND 的
D:href缺少挂载前缀davPathOf()剥掉了/dav前缀得到虚拟路径,PROPFIND 却直接把该虚拟路径当作href输出,违反 RFC 4918(D:href必须是完整请求 URI)。按请求路径解析 href 的客户端会丢弃全部条目:rclone 打印
Item with unknown path received: "/wewe/70rop/", "/dav/wewe/"并显示空目录;Windows 资源管理器、RaiDrive 同样。
GET下载不受影响(走 302),所以表现为「能下不能列」,容易被误判为客户端问题。
修复:从请求 URL 推导前缀,而不硬编码
/dav——index.ts会把发往任意路径的WebDAV 方法也交给本 router(为兼容把用户填写的地址当 WebDAV 根的客户端),此时前缀为空。
2. GuangYaPan 上传凭据读取位置错误
get_res_center_token把 OSS 凭据嵌套在data.creds下,而GypUploadTokenData与
put()的校验都按平铺在data上读取,导致accessKeyID/secretAccessKey恒为 undefined,任何写入(WebDAV PUT、MKCOL、网页端上传)都失败并抛
upload token is incomplete。凭据字段其实一个都不缺。修复:优先读
creds,保留平铺回退;并把 OSS 签名与x-oss-security-token头也改用取到的局部变量——只改校验处会留下隐蔽的 STS header 缺失。
Related Issues / 关联 Issue
Fixes #104
Fixes #105
Testing / 测试
在自建 Cloudflare Workers 部署(
DB_DRIVER=kv、DB_FORMAT=map、DB_CIPHER=aes-256-gcm)上实测:WebDAV href
PROPFIND /dav/的 href/、/WESSSDQ、/wewe/dav/、/dav/WESSSDQ、/dav/wewerclone lsdrclone sizeGuangYaPan 上传
PUTupload token is incompleteDELETEnode scripts/build-edge.mjs构建通过npx tsc -p tsconfig.json --noEmit无新增错误(仍为仓库既有的 2 个db_cipher.test.ts重复标识符)driver.test.ts6/6 通过未做的验证:未在 Node.js 容器模式下跑端到端;两处改动均不涉及运行时差异,
但建议合并前由维护者确认。
Checklist / 检查清单
AI Disclosure / AI 使用声明
Tools used / 使用工具:
Usage scope / 使用范围:
Code generation / 代码生成
Review assistance / 审查辅助
我已审核并验证本 PR 中所有 AI 辅助内容(两处缺陷的根因定位、修复方案、
以及上表中的全部实测数据,均由我在真实部署上复现与验证)