Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Authorization mode leaves generation, indexing, chat, and cache reads unprotected

オープン
#604 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
35/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
python

調査の方向性

Start with api/routers/auth.py, api/routers/wiki.py, api/routers/repo.py, and the existing DELETE /api/wiki_cache authorization check. Trace how WIKI_AUTH_MODE and WIKI_AUTH_CODE are validated, then inspect the routes named in the report and issue #595 for the stated fix. Done means protected routes consistently reject unauthenticated requests while authorized generation, indexing, chat, codemap, and cache access still work.

索引モデルが issue の本文から書いたものです。

説明

Affected versions: confirmed on main at commit d92819a9 (the project publishes no tagged release).

Summary

WIKI_AUTH_MODE's shared authorization code is checked by the frontend's gate screen and by DELETE /api/wiki_cache, but the backend never creates an authenticated session and does not enforce the code on any other route. Wiki generation, repo indexing, chat, codemap, and cache-read endpoints all perform zero authorization check regardless of WIKI_AUTH_MODE.

Details

# api/routers/auth.py
@router.post("/validate")
async def validate_auth_code(request: AuthorizationConfig):
    return {"success": WIKI_AUTH_CODE == request.code}   # no session created
# api/routers/wiki.py
@router.post("/wiki/tasks", response_model=WikiTaskSubmitResult)
async def submit_wiki_task(request: WikiTaskRequest):
    return await registry.submit(...)   # no auth check at all
# api/routers/repo.py
@router.post("/prepare")
async def prepare_repo_index(request: RepoPrepareRequest):
    ...
    task = asyncio.create_task(prepare_index(request))   # no auth check at all

A full grep of api/ confirms WIKI_AUTH_CODE/WIKI_AUTH_MODE are referenced nowhere else in the router layer except the one DELETE /api/wiki_cache check.

POC

(available upon request)

Impact

An operator who enables WIKI_AUTH_MODE specifically to gate access to a deployment gets no actual protection on any route except cache deletion: anyone who bypasses the frontend gate screen (trivial, since it's enforced client-side) can trigger generation/indexing (provider-funded compute cost) and read chat/cache content.

Suggested fix: create a backend authentication dependency and apply it consistently to every protected route. A fix is included in the linked PR.

Fix: #595

主要言語
Python
スター
18.1k
フォーク
2k
PR マージ指標
30日以内にマージされた PR はありません

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

AsyncFuncAI/deepwiki-open のほかの issue

AsyncFuncAI/deepwiki-open の issue をすべて見る

似ている issue

Python の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。