Hardening: cap the invite_user list size in UpdateQuestionInviteUser to bound notification fan-out
还没有人认领这个 Issue。
评估
调研方向
从 internal/schema/question_schema.go:206 开始,跟踪 PUT /answer/api/v1/question/invite 使用的 invite_user 数组的验证逻辑。找到 UI 中现有的邀请上限,然后确认超出上限的请求会如何处理;如果仓库中有针对该 schema 或 endpoint 的测试,请添加相应的覆盖。完成标准是服务器强制执行最大值,并防止通知无限 fan-out。
由索引模型根据 Issue 内容生成。
描述
Background
PUT /answer/api/v1/question/invite accepts an uncapped invite_user array (internal/schema/question_schema.go:206), so a single request can trigger a large number of "invited you to answer" notifications.
I reported this privately to the ASF security team. They confirmed the endpoint's rank-gated, site-wide behaviour is by design (not a boundary crossing), but noted the missing maximum on invite_user reads as hardening. Filing here per that suggestion.
Suggested hardening
- Add a sane server-side maximum on
invite_user(e.g. matching the UI's limit) to bound the notification fan-out.
Happy to send a PR.
- 主要语言
- Go
- 星标
- 15.7k
- 派生
- 1.4k
- 平均合并
- 1 天 20 小时
- 30 天内合并 PR
- 6
贡献指南
这个仓库没有索引到贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
apache/answer 的其他 Issue
-
bug
难度 2/5 1-3 小时 新手友好度 65/100
-
难度 2/5 1-3 小时 新手友好度 84/100
-
难度 2/5 1-3 小时 新手友好度 88/100
-
Gravatar hash is computed from the un-lowercased email, so mixed-case accounts render an identicon 未关闭
难度 2/5 1-3 小时 新手友好度 85/100
-
bug
难度 2/5 1-3 小时 新手友好度 75/100
相似的 Issue
-
bug github_actions
难度 2/5 1-3 小时 新手友好度 75/100
registrystack/registry-stack#1393 ·
-
难度 2/5 1-3 小时 新手友好度 75/100
JakeChampion/lang#10213 ·
-
难度 2/5 1-3 小时 新手友好度 70/100
oasisprotocol/oasis-sdk#2523 ·
-
难度 2/5 1-3 小时 新手友好度 75/100
-
难度 2/5 1-3 小时 新手友好度 70/100