Authorization mode leaves generation, indexing, chat, and cache reads unprotected
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 35/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- python
調査の方向性
Start with api/routers/auth.py, api/routers/wiki.py, api/routers/repo.py, and the existing DELETE /api/wiki_cache authorization check. Trace how WIKI_AUTH_MODE and WIKI_AUTH_CODE are validated, then inspect the routes named in the report and issue #595 for the stated fix. Done means protected routes consistently reject unauthenticated requests while authorized generation, indexing, chat, codemap, and cache access still work.
索引モデルが issue の本文から書いたものです。
説明
Affected versions: confirmed on main at commit d92819a9 (the project publishes no tagged release).
Summary
WIKI_AUTH_MODE's shared authorization code is checked by the frontend's gate screen and by DELETE /api/wiki_cache, but the backend never creates an authenticated session and does not enforce the code on any other route. Wiki generation, repo indexing, chat, codemap, and cache-read endpoints all perform zero authorization check regardless of WIKI_AUTH_MODE.
Details
# api/routers/auth.py
@router.post("/validate")
async def validate_auth_code(request: AuthorizationConfig):
return {"success": WIKI_AUTH_CODE == request.code} # no session created
# api/routers/wiki.py
@router.post("/wiki/tasks", response_model=WikiTaskSubmitResult)
async def submit_wiki_task(request: WikiTaskRequest):
return await registry.submit(...) # no auth check at all
# api/routers/repo.py
@router.post("/prepare")
async def prepare_repo_index(request: RepoPrepareRequest):
...
task = asyncio.create_task(prepare_index(request)) # no auth check at all
A full grep of api/ confirms WIKI_AUTH_CODE/WIKI_AUTH_MODE are referenced nowhere else in the router layer except the one DELETE /api/wiki_cache check.
POC
(available upon request)
Impact
An operator who enables WIKI_AUTH_MODE specifically to gate access to a deployment gets no actual protection on any route except cache deletion: anyone who bypasses the frontend gate screen (trivial, since it's enforced client-side) can trigger generation/indexing (provider-funded compute cost) and read chat/cache content.
Suggested fix: create a backend authentication dependency and apply it consistently to every protected route. A fix is included in the linked PR.
Fix: #595
- 主要言語
- Python
- スター
- 18.1k
- フォーク
- 2k
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
AsyncFuncAI/deepwiki-open のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
AsyncFuncAI/deepwiki-open#608 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
AsyncFuncAI/deepwiki-open#602 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
AsyncFuncAI/deepwiki-open#589 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
AsyncFuncAI/deepwiki-open#539 · コメント 1 件 ·
-
難易度 3/5 1〜2日 初心者へのやさしさ 45/100
AsyncFuncAI/deepwiki-open#610 ·
AsyncFuncAI/deepwiki-open の issue をすべて見る
似ている issue
-
Harmony OPeNDAP SubSetter (HOSS) Geographic LARC_CLOUD PREFIRE_SAT2_AUX-SAT R01 production
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
nasa/harmony-autotester#245 ·
-
feature
難易度 2/5 1〜3時間 初心者へのやさしさ 66/100
-
L: github:actions L: php:composer
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
dependabot/dependabot-core#16493 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 92/100
DataTalksClub/machine-learning-zoomcamp#730 ·
メンテナーはふだん 2 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
メンテナーはふだん 4 日以内に返信