Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Authorization mode leaves generation, indexing, chat, and cache reads unprotected

Aperta
#604 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
35/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
python

Direzione di ricerca

Start with api/routers/auth.py, api/routers/wiki.py, api/routers/repo.py, and the existing DELETE /api/wiki_cache authorization check. Trace how WIKI_AUTH_MODE and WIKI_AUTH_CODE are validated, then inspect the routes named in the report and issue #595 for the stated fix. Done means protected routes consistently reject unauthenticated requests while authorized generation, indexing, chat, codemap, and cache access still work.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Affected versions: confirmed on main at commit d92819a9 (the project publishes no tagged release).

Summary

WIKI_AUTH_MODE's shared authorization code is checked by the frontend's gate screen and by DELETE /api/wiki_cache, but the backend never creates an authenticated session and does not enforce the code on any other route. Wiki generation, repo indexing, chat, codemap, and cache-read endpoints all perform zero authorization check regardless of WIKI_AUTH_MODE.

Details

# api/routers/auth.py
@router.post("/validate")
async def validate_auth_code(request: AuthorizationConfig):
    return {"success": WIKI_AUTH_CODE == request.code}   # no session created
# api/routers/wiki.py
@router.post("/wiki/tasks", response_model=WikiTaskSubmitResult)
async def submit_wiki_task(request: WikiTaskRequest):
    return await registry.submit(...)   # no auth check at all
# api/routers/repo.py
@router.post("/prepare")
async def prepare_repo_index(request: RepoPrepareRequest):
    ...
    task = asyncio.create_task(prepare_index(request))   # no auth check at all

A full grep of api/ confirms WIKI_AUTH_CODE/WIKI_AUTH_MODE are referenced nowhere else in the router layer except the one DELETE /api/wiki_cache check.

POC

(available upon request)

Impact

An operator who enables WIKI_AUTH_MODE specifically to gate access to a deployment gets no actual protection on any route except cache deletion: anyone who bypasses the frontend gate screen (trivial, since it's enforced client-side) can trigger generation/indexing (provider-funded compute cost) and read chat/cache content.

Suggested fix: create a backend authentication dependency and apply it consistently to every protected route. A fix is included in the linked PR.

Fix: #595

Lingua principale
Python
Stelle
18.1k
Fork
2k
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Preparare l'ambiente

Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di AsyncFuncAI/deepwiki-open

Tutte le issue di AsyncFuncAI/deepwiki-open

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.