You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Rails 7.0应用中隔离运行管理员编写的代码?

Rails 7 代码隔离运行实现方案

针对管理员在后台编写的小段代码,要实现安全隔离、防止访问敏感数据库数据的需求,可以从以下几个层面构建防护体系:

一、使用安全沙箱库创建隔离执行环境

借助Ruby生态中的成熟沙箱库,限制代码可访问的对象和方法,避免直接接触Rails应用的核心模型与服务。

比如使用sandbox gem(需兼容Rails 7),示例实现:

# Gemfile中添加依赖
gem 'sandbox'

# 代码执行服务类
class CodeExecutionService
  def self.run(code)
    # 初始化沙箱
    sandbox = Sandbox.new

    # 仅暴露允许使用的方法(比如基础运算、字符串处理)
    sandbox.eval(<<~RUBY)
      def add(a, b); a + b; end
      def greet(name); "Hello, \#{name}"; end
    RUBY

    # 禁止访问敏感常量与模块
    sandbox.prohibit_constant(:User)
    sandbox.prohibit_constant(:ActiveRecord)
    sandbox.prohibit_constant(:ObjectSpace)

    # 执行用户代码
    sandbox.eval(code)
  rescue Sandbox::SecurityError => e
    "执行错误:#{e.message}"
  rescue => e
    "代码执行失败:#{e.message}"
  end
end

二、自定义隔离上下文(无gem依赖方案)

如果不想引入第三方gem,可以手动构建一个纯净的执行上下文,仅注入安全的方法,切断与主应用环境的关联:

# 定义隔离上下文,仅包含允许的功能
class IsolatedCodeContext
  # 仅开放安全的自定义方法
  def calculate_product(a, b)
    a * b
  end

  def reverse_string(str)
    str.reverse
  end

  # 拦截未定义的常量访问,直接抛出错误
  def const_missing(name)
    raise "禁止访问未授权常量:#{name}"
  end
end

class CodeExecutionService
  def self.run(code)
    context = IsolatedCodeContext.new
    # 在隔离上下文内执行代码
    context.instance_eval(code)
  rescue => e
    "执行错误:#{e.message}"
  end
end

三、数据库层面的兜底防护

即使沙箱出现漏洞,也要在数据库层面限制访问权限:

  1. 创建专门的沙箱数据库用户,仅授予其访问测试/演示表的权限,禁止访问users等敏感表;
  2. 在执行代码时,临时切换到该限制用户的数据库连接:
class CodeExecutionService
  def self.run(code)
    ActiveRecord::Base.establish_connection(:sandbox)
    # 沙箱执行逻辑...
  ensure
    # 执行完成后切回原连接
    ActiveRecord::Base.establish_connection(:development) # 或对应环境
  end
end

config/database.yml中配置沙箱连接:

sandbox:
  adapter: postgresql
  database: my_app_sandbox
  username: sandbox_user
  password: secure_sandbox_password
  host: localhost

四、资源与执行时长限制

防止恶意代码占用过多资源或进入死循环,使用Timeout模块限制执行时长:

require 'timeout'

class CodeExecutionService
  def self.run(code)
    Timeout.timeout(5) do # 限制5秒内执行完成
      # 沙箱执行逻辑...
    end
  rescue Timeout::Error
    "代码执行超时"
  end
end

五、输入代码预校验

在执行前对代码做初步过滤,拦截明显的危险关键词:

class CodeExecutionService
  DANGER_PATTERNS = [/User\.|ActiveRecord|ObjectSpace|eval|exec|system|fork/].freeze

  def self.validate_code(code)
    DANGER_PATTERNS.each do |pattern|
      if code.match?(pattern)
        raise "代码包含危险内容:#{pattern.source}"
      end
    end
  end

  def self.run(code)
    validate_code(code)
    # 后续执行逻辑...
  end
end

内容的提问来源于stack exchange,提问作者Colibri

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 20:13:14