feat: 功能融合页接入 LivingMemory 官方面板入口(4.3.0) - #252
Merged
Merged
Conversation
LivingMemory 2.6.0+ removed its standalone WebUI and now ships an AstrBot official plugin page (pages/dashboard/index.html). The integration service now detects that page from the star's module_path and the astrbot_config dashboard host/port, and exposes it as dashboard.official_page_url (AstrBot Dashboard hash route /#/plugin-page/<name>/<page>). Because official plugin pages are served with X-Frame-Options: SAMEORIGIN and fetch page assets with a short-lived JWT token, they cannot be embedded in an iframe; embeddable is therefore reported as false and the embed shell degrades from 'panel unavailable' to 'open in a new window'. The integrations page adds an official-panel button on the LivingMemory card. Companion contract re-check against livingmemory 2.7.0-beta.1 (9e1c2d7) and group_chat_plus V1.2.3.hotfix.2 (89ae2e1): registration name, initializer.memory_engine, memory_engine.graph_store, get_graph_snapshot signature/return keys and get_statistics are all unchanged, so the local graph adapter needs no further changes. The defensive full-graph snapshot caps added in LM 2.6.0 only affect get_full_graph_snapshot, which this plugin never calls. AstrBot API surface re-check against v4.28 (e606a3037): every symbol this plugin imports still exists and astrbot/api/event + astrbot/api/web saw no commits since v4.27.5.
Contributor
Reviewer's Guide本 PR 将 LivingMemory 2.6+ 的 AstrBot 官方插件页接入功能融合页:服务端通过插件文件结构和 AstrBot Dashboard 配置自动生成官方入口,前端以新窗口按钮打开并明确禁止 iframe 嵌入,同时补充测试、文档、构建产物和 4.3.0 版本同步。 Sequence diagram for LivingMemory official panel discovery and openingsequenceDiagram
participant Dashboard as AstrBot Dashboard
participant Service as IntegrationService
participant Star as LivingMemory Star
participant Config as AstrBotConfig
participant UI as IntegrationsPage
actor User
Service->>Star: module_path
Service->>Service: _discover_plugin_pages(module_path)
Service->>Config: dashboard.host and dashboard.port
Service->>Service: _astrbot_dashboard_origin(astrbot_config)
Service->>Service: _livingmemory_official_page_url(star)
Service-->>UI: dashboard.official_page_url
User->>UI: Click official panel
UI->>UI: openOfficialPage(item)
UI->>Dashboard: window.open(official_page_url)
Dashboard-->>User: Plugin page with existing JWT session
Flow diagram for LivingMemory panel fallback behaviorflowchart TD
A[LivingMemory integration status] --> B{official_page_url detected?}
B -- No --> C[Show existing panel or local graph entry]
B -- Yes --> D{Existing external dashboard URL?}
D -- Yes --> E[Open external panel]
D -- No --> F[Set embeddable to false]
F --> G[Show official panel button]
G --> H[Open AstrBot official plugin page in a new window]
File-Level Changes
Possibly linked issues
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
Contributor
There was a problem hiding this comment.
Hey - I've found 2 issues
Fixed security issues:
- Cross-site scripting (XSS) via untrusted HTML/JS injection in web rendering sinks (link) · Dashboard
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path="webui/services/integration_service.py" line_range="123-124" />
<code_context>
+ """
+ if not module_path:
+ return []
+ base = Path(str(module_path))
+ for pages_root in (base / "pages", base.parent / "pages"):
+ if not pages_root.is_dir():
+ continue
</code_context>
<issue_to_address>
**issue (bug_risk):** When AstrBot exposes `star.module_path` as the dotted import path used elsewhere in this repository (for example `data.plugins.astrbot_plugin_livingmemory.main`), `Path(module_path)` does not point to the installed plugin directory, so the `pages/` scan finds nothing and `official_page_url` is always `None`.
**Triggers:** When the runtime Star object uses a dotted module path rather than an entry-file filesystem path.
**Suggested fix:** Resolve dotted module paths through the loaded module or derive the plugin directory from `root_dir_name` before scanning `pages/`.
</issue_to_address>
### Comment 2
<location path="webui/services/integration_service.py" line_range="124-137" />
<code_context>
+ if not module_path:
+ return []
+ base = Path(str(module_path))
+ for pages_root in (base / "pages", base.parent / "pages"):
+ if not pages_root.is_dir():
+ continue
+ try:
</code_context>
<issue_to_address>
**issue (bug_risk):** A permission or filesystem error from `pages_root.is_dir()` is outside the `OSError` handler, so status generation raises instead of returning no official page when the plugin directory cannot be inspected.
**Triggers:** When the installed plugin path or its `pages/` directory is inaccessible or disappears during status generation.
**Suggested fix:** Include the `is_dir()` checks inside the existing `OSError` handling and return an empty page list on filesystem errors.
```suggestion
for pages_root in (base / "pages", base.parent / "pages"):
try:
if not pages_root.is_dir():
continue
names = sorted(
item.name
for item in pages_root.iterdir()
if item.is_dir() and (item / "index.html").is_file()
)
except OSError:
return []
if names:
return names
return []
```
</issue_to_address>Sourcery assessment
Approval pending. 2 findings to address first.
Blocking findings: webui/services/integration_service.py:124, webui/services/integration_service.py:137
AstrBot's star/base.py overwrites StarMetadata.module_path with cls.__module__ (e.g. data.plugins.<name>.main), so scanning Path(module_path) alone never finds pages/ and official_page_url stayed None in production. Resolve dotted import paths through sys.modules[...].__file__ and keep scanning filesystem paths directly. Also guard the pages/ directory inspection against OSError so an unreadable plugin directory degrades to 'no official page' instead of failing status generation. Addresses the Sourcery review findings on PR #252.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
概述
功能融合页接入 LivingMemory 官方面板入口,并完成对伴随插件与 AstrBot 最新版本的兼容性核对。版本 4.2.0 → 4.3.0。
背景
LivingMemory 2.6.0 起移除了独立 WebUI(
config_manager.webui_settings已删除),改为自带 AstrBot 官方插件页(pages/dashboard/index.html)。self_learning 的功能融合页因此一直显示「面板不可用:该插件面板未开启或尚未检测到可用入口」——实际上 LM 有了新的入口,只是本插件没有对接。改动
module_path定位插件pages/<页名>/index.html,结合 AstrBot 主配置dashboard.host/port生成dashboard.official_page_url(AstrBot Dashboard 前端 hash 路由/#/plugin-page/<插件名>/<页名>,该路由在 v4.27.4–v4.28 保持稳定)。X-Frame-Options: SAMEORIGIN且资产需 JWT(Authorization 头)换取,iframe 带不了凭据——embeddable相应置为false,嵌入壳由「面板不可用」变为「面板禁止内嵌 + 新窗口打开」。docs/integrations.md)、CHANGELOG、7 处版本号同步。伴随插件核对(逐项契约,无需破坏性改动)
对照本地拉取最新后逐项核对:
astrbot_plugin_livingmemoryinitializer.memory_enginememory_engine.graph_storeget_graph_snapshot(session_id, persona_id, limit_*)返回 nodes/edges/entries/memoriesget_full_graph_snapshotmemory_engine.get_statistics()group_chat_plus HEAD 仍为 89ae2e1(V1.2.3.hotfix.2,与上次核对基线一致),无漂移。
AstrBot 兼容性核对(v4.28,e606a3037)
astrbot.api.{logger, AstrBotConfig}、astrbot.api.event.{AstrMessageEvent, filter}(filter 为子包)、astrbot.api.star.{Context, StarTools}、astrbot.api.web.request(web.py:322)、astrbot.core.{agent.message.TextPart, db.po.Personality, message.components.Plain, platform.message_type.MessageType, provider.entities.*, provider.provider.*, utils.astrbot_path.get_astrbot_data_path}。astrbot/api/event与astrbot/api/web自 v4.27.5 以来零提交;context.register_web_api在 v4.28 仍存在(context.py:705)。本地验证
pytest tests/ -q:786 passed(含本 PR 新增 2 个 official_page_url 用例)web_src:pnpm build产物已提交;pnpm test50 passedruff check通过;已安装至本地AstrBot/data/plugins并做导入级验证(4.3.0,真实 LM 安装探测到dashboard页)上游动态扫描(过去 24h)
版本
4.2.0 → 4.3.0(metadata.yaml、
__init__.py、web_src/package.json、README 徽章 ×2、docs/README.md)Summary by Sourcery
Integrate LivingMemory’s official AstrBot panel into the feature integration dashboard while preserving compatibility with existing memory and companion-plugin integrations.
New Features:
Bug Fixes:
Enhancements:
Build:
Documentation:
Tests:
Chores: