camel-ai / crab

CRAB: Cross-environment Agent Benchmark for Multimodal Language Model Agents. https://crab.camel-ai.org/
https://crab.camel-ai.org/
186 stars 26 forks source link

feat: add encryption support #20

Closed WHALEEYE closed 2 months ago

WHALEEYE commented 2 months ago

Add encryption support for communication between client and server. User can enable encryption by setting env variable CRAB_ENC_KEY.

Summary by CodeRabbit

coderabbitai[bot] commented 2 months ago

Walkthrough

The changes introduce enhancements to the crab project by implementing encryption and decryption mechanisms for secure data handling. Key functionalities include conditional encryption in action handling, updates to the API for raw action processing, and the introduction of utility functions for encryption. A new dependency on the cryptography package is added, along with unit tests to validate the encryption processes.

Changes

Files Change Summary
crab/core/environment.py Added _enc_key for encryption; modified _action_endpoint for conditional encryption and decryption.
crab/server/api.py Updated raw_action endpoint to read raw content and conditionally decrypt or encrypt responses based on the key.
crab/utils/__init__.py Introduced file to initialize utilities; imported functions for base64 and encryption handling.
crab/utils/encryption.py Implemented AES 256 encryption functions: encrypt_message, decrypt_message, and generate_key_from_env.
pyproject.toml Added cryptography package dependency for cryptographic functionalities.
test/core/test_utils.py Created unit test test_encrypt_decrypt to validate encryption and decryption functionality.
test/server/test_api.py Replaced test_raw_action with test_raw_action_unencrypted and test_raw_action_encrypted; added mock_env fixture.
crab/agents/backend_models/camel_model.py Updated type annotations to use pipe (|) syntax for type unions, enhancing readability.

Sequence Diagram(s)

sequenceDiagram
    participant Client
    participant API
    participant Environment
    participant Utils

    Client->>API: Send Action
    API->>Environment: Process Action
    Environment->>Utils: Encrypt Action Data (if key present)
    Utils-->>Environment: Encrypted Data
    Environment->>API: Send Encrypted Data
    API->>Client: Return Response
    Client->>API: Request Response
    API->>Environment: Process Response
    Environment->>Utils: Decrypt Response Data (if key present)
    Utils-->>Environment: Decrypted Data
    Environment->>API: Send Decrypted Data
    API->>Client: Return Decrypted Response

Poem

πŸ‡ In the burrow deep, where secrets lie,
A key was found, oh my, oh my!
With whispers of code, the data's tight,
Encryption dances in the moonlight.
Hops of joy, let’s cheer and play,
For safety's here in a brand new way! πŸŒ™βœ¨


Thank you for using CodeRabbit. We offer it for free to the OSS community and would appreciate your support in helping us grow. If you find it useful, would you consider giving us a shout-out on your favorite social media?

Share - [X](https://twitter.com/intent/tweet?text=I%20just%20used%20%40coderabbitai%20for%20my%20code%20review%2C%20and%20it%27s%20fantastic%21%20It%27s%20free%20for%20OSS%20and%20offers%20a%20free%20trial%20for%20the%20proprietary%20code.%20Check%20it%20out%3A&url=https%3A//coderabbit.ai) - [Mastodon](https://mastodon.social/share?text=I%20just%20used%20%40coderabbitai%20for%20my%20code%20review%2C%20and%20it%27s%20fantastic%21%20It%27s%20free%20for%20OSS%20and%20offers%20a%20free%20trial%20for%20the%20proprietary%20code.%20Check%20it%20out%3A%20https%3A%2F%2Fcoderabbit.ai) - [Reddit](https://www.reddit.com/submit?title=Great%20tool%20for%20code%20review%20-%20CodeRabbit&text=I%20just%20used%20CodeRabbit%20for%20my%20code%20review%2C%20and%20it%27s%20fantastic%21%20It%27s%20free%20for%20OSS%20and%20offers%20a%20free%20trial%20for%20proprietary%20code.%20Check%20it%20out%3A%20https%3A//coderabbit.ai) - [LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fcoderabbit.ai&mini=true&title=Great%20tool%20for%20code%20review%20-%20CodeRabbit&summary=I%20just%20used%20CodeRabbit%20for%20my%20code%20review%2C%20and%20it%27s%20fantastic%21%20It%27s%20free%20for%20OSS%20and%20offers%20a%20free%20trial%20for%20proprietary%20code)
Tips ### Chat There are 3 ways to chat with [CodeRabbit](https://coderabbit.ai): > :bangbang: **IMPORTANT** > Auto-reply has been disabled for this repository in the CodeRabbit settings. The CodeRabbit bot will not respond to your replies unless it is explicitly tagged. - Files and specific lines of code (under the "Files changed" tab): Tag `@coderabbitai` in a new review comment at the desired location with your query. Examples: - `@coderabbitai generate unit testing code for this file.` - `@coderabbitai modularize this function.` - PR comments: Tag `@coderabbitai` in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples: - `@coderabbitai generate interesting stats about this repository and render them as a table.` - `@coderabbitai show all the console.log statements in this repository.` - `@coderabbitai read src/utils.ts and generate unit testing code.` - `@coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.` - `@coderabbitai help me debug CodeRabbit configuration file.` Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. ### CodeRabbit Commands (Invoked using PR comments) - `@coderabbitai pause` to pause the reviews on a PR. - `@coderabbitai resume` to resume the paused reviews. - `@coderabbitai review` to trigger an incremental review. This is useful when automatic reviews are disabled for the repository. - `@coderabbitai full review` to do a full review from scratch and review all the files again. - `@coderabbitai summary` to regenerate the summary of the PR. - `@coderabbitai resolve` resolve all the CodeRabbit review comments. - `@coderabbitai configuration` to show the current CodeRabbit configuration for the repository. - `@coderabbitai help` to get help. ### Other keywords and placeholders - Add `@coderabbitai ignore` anywhere in the PR description to prevent this PR from being reviewed. - Add `@coderabbitai summary` to generate the high-level summary at a specific location in the PR description. - Add `@coderabbitai` anywhere in the PR title to generate the title automatically. ### CodeRabbit Configuration File (`.coderabbit.yaml`) - You can programmatically configure CodeRabbit by adding a `.coderabbit.yaml` file to the root of your repository. - Please see the [configuration documentation](https://docs.coderabbit.ai/guides/configure-coderabbit) for more information. - If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: `# yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json` ### Documentation and Community - Visit our [Documentation](https://coderabbit.ai/docs) for detailed information on how to use CodeRabbit. - Join our [Discord Community](https://discord.com/invite/GsXnASn26c) to get help, request features, and share feedback. - Follow us on [X/Twitter](https://twitter.com/coderabbitai) for updates and announcements.
dandansamax commented 2 months ago

Overall it looks very good. We can consider add an API test for encrypt mode.

Ref:

https://github.com/camel-ai/crab/blob/main/test/server/test_api.py

dandansamax commented 2 months ago

close #18