- Add missing snapshot-differ.test.ts to npm test script - Fix path traversal vulnerability in agent-mail.ts with message ID validation - Fix readLastTouchedVersion to log errors instead of silently swallowing them - Sanitize log statements to not leak full paths - Add projectRoot validation to all API routes - Fix activity persistence write race conditions with promise chaining Co-authored-by: openhands <openhands@all-hands.dev>
40 lines
1.3 KiB
TypeScript
40 lines
1.3 KiB
TypeScript
import { NextResponse } from 'next/server';
|
|
import path from 'node:path';
|
|
import { readIssuesFromDisk } from '../../../../../lib/read-issues';
|
|
import { activityEventBus } from '../../../../../lib/realtime';
|
|
import { getAgentMetrics } from '../../../../../lib/agent-sessions';
|
|
|
|
function isValidProjectRoot(root: string): boolean {
|
|
try {
|
|
const resolved = path.resolve(root);
|
|
return path.isAbsolute(resolved);
|
|
} catch {
|
|
return false;
|
|
}
|
|
}
|
|
|
|
export async function GET(
|
|
request: Request,
|
|
{ params }: { params: Promise<{ agentId: string }> }
|
|
): Promise<Response> {
|
|
const { agentId } = await params;
|
|
const url = new URL(request.url);
|
|
const projectRootParam = url.searchParams.get('projectRoot');
|
|
const projectRoot = projectRootParam ?? process.cwd();
|
|
|
|
if (projectRootParam && !isValidProjectRoot(projectRootParam)) {
|
|
return NextResponse.json({ ok: false, error: 'Invalid projectRoot path' }, { status: 400 });
|
|
}
|
|
|
|
try {
|
|
const issues = await readIssuesFromDisk({ projectRoot, preferBd: true });
|
|
const activity = activityEventBus.getHistory(projectRoot);
|
|
|
|
const metrics = await getAgentMetrics(agentId, issues, activity);
|
|
|
|
return NextResponse.json({ ok: true, metrics });
|
|
} catch (error) {
|
|
console.error('[API/Agents/Stats] Failed:', error);
|
|
return NextResponse.json({ ok: false, error: String(error) }, { status: 500 });
|
|
}
|
|
}
|