fix: disable unsolicited background UI automation
This commit is contained in:
@@ -6,8 +6,8 @@ namespace WxAgent.Host;
|
||||
|
||||
public sealed class WindowsAgentBackend(AccountBindingStore bindings, ServiceOptions options) : IAgentBackend, IAgentEventSource
|
||||
{
|
||||
private const bool ListenerEventsEnabled = true;
|
||||
private readonly bool validationOperationsEnabled = options.EnableValidationOperations;
|
||||
private readonly bool listenerEventsEnabled = options.EnableListenerEvents;
|
||||
private readonly SemaphoreSlim bindingGate = new(1, 1);
|
||||
|
||||
public IReadOnlyList<AgentCapability> Capabilities =>
|
||||
@@ -28,8 +28,8 @@ public sealed class WindowsAgentBackend(AccountBindingStore bindings, ServiceOpt
|
||||
new("db-messages", true, false, false, false, false, "read", false, 30, "Database key/account query acceptance is pending.", ["Requires explicit verified account key scope."], "4.1.13.65"),
|
||||
new("db-merged", true, false, false, false, false, "read", false, 30, "Database key/account query acceptance is pending.", ["Requires explicit verified account key scope."], "4.1.13.65"),
|
||||
new("group-members", true, true, true, false, false, "read", false, 30, null, ["docs/validation/WebUI-MCP-single-client-2026-09-19.md"], "4.1.13.65"),
|
||||
new("listener-events", true, ListenerEventsEnabled, ListenerEventsEnabled, true, false, "read", false, 30,
|
||||
ListenerEventsEnabled ? null : "Listener events are reserved for controlled validation.", ["docs/validation/WebUI-MCP-single-client-2026-09-19.md"], "4.1.13.65"),
|
||||
new("listener-events", true, listenerEventsEnabled, listenerEventsEnabled, true, false, "read", false, 30,
|
||||
listenerEventsEnabled ? null : "Background UI listener is disabled; enable it explicitly in the Tray settings window.", ["docs/validation/WebUI-MCP-single-client-2026-09-19.md"], "4.1.13.65"),
|
||||
new("send-text", true, true, validationOperationsEnabled, true, true, "write", true, 30,
|
||||
validationOperationsEnabled ? null : "Validation operations are disabled for this service session.", ["docs/validation/WebUI-MCP-single-client-2026-09-19.md"], "4.1.13.65"),
|
||||
new("broadcast-text", true, true, validationOperationsEnabled, true, true, "write", true, 300,
|
||||
@@ -42,6 +42,12 @@ public sealed class WindowsAgentBackend(AccountBindingStore bindings, ServiceOpt
|
||||
|
||||
public async IAsyncEnumerable<AgentEvent> ListenAsync([System.Runtime.CompilerServices.EnumeratorCancellation] CancellationToken cancellationToken)
|
||||
{
|
||||
if (!listenerEventsEnabled)
|
||||
{
|
||||
await Task.Delay(Timeout.InfiniteTimeSpan, cancellationToken);
|
||||
yield break;
|
||||
}
|
||||
|
||||
var active = bindings.ReadAll();
|
||||
if (active.Count != 1)
|
||||
{
|
||||
|
||||
@@ -25,6 +25,7 @@ public sealed class ServiceOptions
|
||||
// Explicitly opt-in for a single, user-authorized Windows validation session.
|
||||
// Production deployments remain read-only unless this local gate is enabled.
|
||||
public bool EnableValidationOperations { get; init; }
|
||||
public bool EnableListenerEvents { get; init; }
|
||||
public bool PreventAutoLock { get; init; }
|
||||
|
||||
// Kept only so older service.json files can be loaded and rewritten by the tray.
|
||||
@@ -34,9 +35,6 @@ public sealed class ServiceOptions
|
||||
[JsonIgnore]
|
||||
[Obsolete("Internal compatibility field; the value is ignored.")]
|
||||
public string ListenerSession { get; init; } = "文件传输助手";
|
||||
[JsonIgnore]
|
||||
[Obsolete("Internal compatibility field; the value is ignored.")]
|
||||
public bool EnableListenerEvents { get; init; }
|
||||
|
||||
public void Validate()
|
||||
{
|
||||
|
||||
@@ -359,7 +359,7 @@ internal static class ServiceSettingsEditor
|
||||
{
|
||||
Text = "WxAgent 服务设置",
|
||||
Width = 620,
|
||||
Height = 405,
|
||||
Height = 435,
|
||||
StartPosition = FormStartPosition.CenterScreen,
|
||||
MinimizeBox = false,
|
||||
MaximizeBox = false,
|
||||
@@ -385,18 +385,24 @@ internal static class ServiceSettingsEditor
|
||||
Text = "防止自动息屏、睡眠和锁屏",
|
||||
Checked = current.PreventAutoLock
|
||||
};
|
||||
var listenerEvents = new CheckBox
|
||||
{
|
||||
Left = 145, Top = 216, Width = 430,
|
||||
Text = "启用后台消息监听(会操作微信界面,默认关闭)",
|
||||
Checked = current.EnableListenerEvents
|
||||
};
|
||||
var note = new Label
|
||||
{
|
||||
Left = 18, Top = 220, Width = 570, Height = 48,
|
||||
Left = 18, Top = 250, Width = 570, Height = 48,
|
||||
Text = "仅保留一个访问凭据,可直接输入自定义内容(不能为空或包含空白字符)。\n验证写操作只应在明确授权的测试机启用;本机回环访问不需要凭据。"
|
||||
};
|
||||
var data = new Label
|
||||
{
|
||||
Left = 18, Top = 278, Width = 570, Height = 24,
|
||||
Left = 18, Top = 308, Width = 570, Height = 24,
|
||||
Text = $"数据目录:{current.DataDirectory}", AutoEllipsis = true
|
||||
};
|
||||
var save = new Button { Left = 370, Top = 330, Width = 105, Text = "保存" };
|
||||
var cancel = new Button { Left = 485, Top = 330, Width = 105, Text = "取消" };
|
||||
var save = new Button { Left = 370, Top = 360, Width = 105, Text = "保存" };
|
||||
var cancel = new Button { Left = 485, Top = 360, Width = 105, Text = "取消" };
|
||||
copy.Click += (_, _) => { Clipboard.SetText(tokenBox.Text); copy.Text = "已复制"; };
|
||||
regenerate.Click += (_, _) =>
|
||||
{
|
||||
@@ -425,6 +431,7 @@ internal static class ServiceSettingsEditor
|
||||
Reporting = current.Reporting,
|
||||
RemoteConfigurationFile = current.RemoteConfigurationFile,
|
||||
EnableValidationOperations = validation.Checked,
|
||||
EnableListenerEvents = listenerEvents.Checked,
|
||||
PreventAutoLock = preventAutoLock.Checked
|
||||
};
|
||||
try { edited.Validate(); }
|
||||
@@ -437,7 +444,7 @@ internal static class ServiceSettingsEditor
|
||||
form.Close();
|
||||
};
|
||||
cancel.Click += (_, _) => form.Close();
|
||||
form.Controls.AddRange([listenLabel, hostBox, portBox, external, tokenLabel, tokenBox, copy, regenerate, validation, preventAutoLock, note, data, save, cancel]);
|
||||
form.Controls.AddRange([listenLabel, hostBox, portBox, external, tokenLabel, tokenBox, copy, regenerate, validation, preventAutoLock, listenerEvents, note, data, save, cancel]);
|
||||
form.AcceptButton = save;
|
||||
form.CancelButton = cancel;
|
||||
form.ShowDialog();
|
||||
|
||||
Reference in New Issue
Block a user