Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Developer manual: no page on authorization (IDOR, admin-only routes)

未关闭 适合新手
#15,693 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
2/5
预计耗时
1-3 小时
新手友好度
78/100
Issue 类型
文档
描述清晰度
描述清楚
活跃度
活跃
领域
documentation

调研方向

首先阅读 prologue/security.rst,并检查开发者手册如何组织相邻的安全指南。添加一个专门的授权页面,涵盖 IDOR 检查,以及防止通过备用路由或 API 端点执行仅限管理员的操作,并替换或更新过时的句子。完成的标准是手册对所要求的两个授权问题都有清晰的指导。

由索引模型根据 Issue 内容生成。

描述

0. needs triage enhancement manual: developer security

There is no page on authorization in apps: checking that every ID from a request belongs to (or is shared with) the caller (IDOR), and making sure admin-only actions aren't reachable through another route or API endpoint. Today it is one outdated sentence in prologue/security.rst.

主要语言
JavaScript
星标
632
派生
2.5k
平均合并
1 天 51 分钟
30 天内合并 PR
77

环境准备

在 Codespaces 中打开

在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

nextcloud/documentation 的其他 Issue

查看 nextcloud/documentation 的全部 Issue

相似的 Issue

更多 JavaScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。