From cf465a700b06e767e008a8fba1c7ce6b3a4ee00d Mon Sep 17 00:00:00 2001 From: chen qiang <343005560@qq.com> Date: Fri, 14 Aug 2026 15:54:23 +0800 Subject: [PATCH] chore: refresh public mirror --- AGENTS.md | 2 ++ CHANGELOG.md | 6 ++++++ SKILL.md | 2 +- VERSION | 2 +- scripts/oracle_skill.py | 13 ++++++++----- tests/test_awr.py | 10 ++++++++++ 6 files changed, 28 insertions(+), 7 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 0418cd2..29778f8 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -13,3 +13,5 @@ Release 1.5.33: when AWR readiness reports missing function or view permission, Release 1.5.34: update archived `HENLO_AWR_EXPORT` to v1.1 so null rows do not reach `DBMS_LOB.WRITEAPPEND`, preserve report row boundaries with newlines, and keep deployment strictly manual through the DBA SQL output. Release 1.5.35: change the Skill default transit endpoint to `https://ts.henlo.net`, update configuration and documentation examples, preserve existing login/session fields while migrating only `transit_url`, validate, commit and push to Gitea, then pull and verify the installed Skill. + +Release 1.5.36: remove the hard-coded Agent-update administrator token fallback. `agent_update` must require `ORACLE_JUMP_UPGRADE_ADMIN_TOKEN` or `upgrade_admin_token` and fail locally without issuing a request when neither is configured. This rule is mandatory before publishing the manually approved, no-history public mirror snapshot. diff --git a/CHANGELOG.md b/CHANGELOG.md index 3315e27..a7127aa 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,9 @@ +## 1.5.36 (2026-08-14) + +### Public mirror safety +- Removed the hard-coded `"123"` fallback for the Agent update administrator token. +- `agent_update` now fails locally with a clear configuration error when neither `ORACLE_JUMP_UPGRADE_ADMIN_TOKEN` nor `upgrade_admin_token` is configured; it does not issue an update request without a token. + ## 1.5.35 (2026-08-14) ### HTTPS transit endpoint diff --git a/SKILL.md b/SKILL.md index d9bc3f3..62f44f1 100644 --- a/SKILL.md +++ b/SKILL.md @@ -5,7 +5,7 @@ description: Oracle 跳板查询技能。通过中转服务查询远程 Oracle # Oracle 跳板查询 -> **版本:v1.5.35** · [更新日志](./CHANGELOG.md) +> **版本:v1.5.36** · [更新日志](./CHANGELOG.md) ## 使用原则 diff --git a/VERSION b/VERSION index ff4e38d..599410a 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -1.5.35 +1.5.36 diff --git a/scripts/oracle_skill.py b/scripts/oracle_skill.py index 1bf8ef9..59fe997 100644 --- a/scripts/oracle_skill.py +++ b/scripts/oracle_skill.py @@ -1706,10 +1706,7 @@ def get_upgrade_admin_token(cfg: Optional[Dict[str, Any]] = None) -> str: token = str(cfg.get("upgrade_admin_token", "") or "").strip() if token: return token - raise RuntimeError( - "Agent update requires ORACLE_JUMP_UPDATE_ADMIN_TOKEN or " - "agent_update_admin_token in the local config." - ) + return "" def agent_update(client_code: str = "", timeout: int = 300) -> Dict[str, Any]: @@ -1724,9 +1721,15 @@ def agent_update(client_code: str = "", timeout: int = 300) -> Dict[str, Any]: return {"success": False, "error": "clientCode is required"} if timeout <= 0 or timeout > 600: timeout = 300 + upgrade_token = get_upgrade_admin_token(config) + if not upgrade_token: + return { + "success": False, + "error": "upgrade admin token is not configured; set ORACLE_JUMP_UPGRADE_ADMIN_TOKEN or upgrade_admin_token", + } payload = {"server_id": client_code, "timeout": timeout} headers = make_headers() - headers["X-Upgrade-Admin-Token"] = get_upgrade_admin_token(config) + headers["X-Upgrade-Admin-Token"] = upgrade_token try: resp = requests.post( f"{transit_url}/api/admin/agent_update/trigger", diff --git a/tests/test_awr.py b/tests/test_awr.py index 116b013..5946aba 100644 --- a/tests/test_awr.py +++ b/tests/test_awr.py @@ -33,6 +33,16 @@ class AWRSkillTests(unittest.TestCase): def test_default_transit_url_uses_https_domain(self): self.assertEqual(skill.TRANSIT_URL, "https://ts.henlo.net") + def test_agent_update_requires_explicit_admin_token(self): + config = self.config() + with mock.patch.object(skill, "get_config", return_value=config), mock.patch.object( + skill, "ensure_logged_in", return_value=True + ), mock.patch.object(skill.requests, "post") as post: + result = skill.agent_update("WEIRUI") + self.assertFalse(result["success"]) + self.assertIn("upgrade admin token is not configured", result["error"]) + post.assert_not_called() + def config(self): return { "access_token": "test-token",