Authorization mode leaves generation, indexing, chat, and cache reads unprotected
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 35/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- python
- Ambito
- api, authentication, authorization, backend, security
Direzione di ricerca
Start with api/routers/auth.py, api/routers/wiki.py, api/routers/repo.py, and the existing DELETE /api/wiki_cache authorization check. Trace how WIKI_AUTH_MODE and WIKI_AUTH_CODE are validated, then inspect the routes named in the report and issue #595 for the stated fix. Done means protected routes consistently reject unauthenticated requests while authorized generation, indexing, chat, codemap, and cache access still work.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Affected versions: confirmed on main at commit d92819a9 (the project publishes no tagged release).
Summary
WIKI_AUTH_MODE's shared authorization code is checked by the frontend's gate screen and by DELETE /api/wiki_cache, but the backend never creates an authenticated session and does not enforce the code on any other route. Wiki generation, repo indexing, chat, codemap, and cache-read endpoints all perform zero authorization check regardless of WIKI_AUTH_MODE.
Details
# api/routers/auth.py
@router.post("/validate")
async def validate_auth_code(request: AuthorizationConfig):
return {"success": WIKI_AUTH_CODE == request.code} # no session created
# api/routers/wiki.py
@router.post("/wiki/tasks", response_model=WikiTaskSubmitResult)
async def submit_wiki_task(request: WikiTaskRequest):
return await registry.submit(...) # no auth check at all
# api/routers/repo.py
@router.post("/prepare")
async def prepare_repo_index(request: RepoPrepareRequest):
...
task = asyncio.create_task(prepare_index(request)) # no auth check at all
A full grep of api/ confirms WIKI_AUTH_CODE/WIKI_AUTH_MODE are referenced nowhere else in the router layer except the one DELETE /api/wiki_cache check.
POC
(available upon request)
Impact
An operator who enables WIKI_AUTH_MODE specifically to gate access to a deployment gets no actual protection on any route except cache deletion: anyone who bypasses the frontend gate screen (trivial, since it's enforced client-side) can trigger generation/indexing (provider-funded compute cost) and read chat/cache content.
Suggested fix: create a backend authentication dependency and apply it consistently to every protected route. A fix is included in the linked PR.
Fix: #595
- Lingua principale
- Python
- Stelle
- 18.1k
- Fork
- 2k
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di AsyncFuncAI/deepwiki-open
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
AsyncFuncAI/deepwiki-open#608 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
AsyncFuncAI/deepwiki-open#602 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
AsyncFuncAI/deepwiki-open#589 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
AsyncFuncAI/deepwiki-open#539 · 1 commento ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 45/100
AsyncFuncAI/deepwiki-open#610 ·
Tutte le issue di AsyncFuncAI/deepwiki-open
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
UKGovernmentBEIS/inspect_ai#5802 ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
no-human-ai/no_human#660 ·
I maintainer di solito rispondono entro 1 giorno
-
documentation good first issue
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
I maintainer di solito rispondono entro 1 giorno
-
documentation need help question
Difficoltà 1/5 1-3 ore Idoneità per principianti 66/100
phonology024/babelscribe#26 ·
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100