Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

security(permissions): 请求体 permission_mode 可整体替换权限层——运维配置的 deny/interactive 规则被一条 JSON 字段绕过

Đang mở
#87 11 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
58/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
rust
Lĩnh vực
api, authorization, security

Hướng nghiên cứu

Start with the permission construction in src/http/handlers.rs:294-300 and 429-435, then read with_permissions in src/tools/registry.rs:464-468 and the registry setup in crates/recursive-cli/src/cli/builder.rs:259-261. Verify the change with a configured deny rule and a request containing permission_mode:"default"; done means the deny rule still applies.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

场景 gap 单(okguitar 提报)· 优先级 P0 · 依赖:无

基线 HEAD = 9165b9a0。

Summary

运维经 RECURSIVE_TOOL_PERMISSIONS_FILE 或 config.toml [permissions] 配置的权限层在服务启动时挂到 registry(crates/recursive-cli/src/cli/builder.rs:259-261)。但 HTTP 请求体携带 permission_mode 时:

  • src/http/handlers.rs:294-300(run_agent;create_session 同型,handlers.rs:429-435):
tool_registry = tool_registry.with_permissions(LayeredPermissionsConfig {
    mode: perm_mode,
    layers: Vec::new(),   // ← 运维层被置空
});
  • with_permissions 是整体替换而非合并(src/tools/registry.rs:464-468)。

即:客户端把 mode 从 strict 改成 default,运维配置的全部 allow/deny/interactive 层即被空层覆盖;strict→default 的降级再叠加「无规则隐式放行」(见审批配套单)等于全量放行。

影响

企业管理员配好的「禁 Bash/禁外发」策略,任何持 key 员工一条 JSON 字段即可绕过;合规审计时运维以为生效的策略实际从未执行。

建议

服务端策略层与请求级模式分离:客户端只能收紧、不能放宽(strict→default 需运维层允许),layers 永远取运维配置;或运维层作为不可移除的底层、请求层只叠加其上。

验收:配置 deny 规则 + 请求携带 permission_mode:"default",断言 deny 规则仍生效。

Ngôn ngữ chính
Rust
Star
4
Fork
0
Merge trung bình
5 giờ 32 phút
Pull request đã merge (30 ngày)
7

Chuẩn bị môi trường

  • Có Dockerfile hoặc tệp Docker Compose
  • Không có mẫu pull request
  • Không có hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của jeffkit/recursive

Tất cả issue của jeffkit/recursive

Issue tương tự

Thêm issue về Rust

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.