Incorrect expiration date validation for `_perishable_token_expires_at`
维护者通常 1 天内回复
评估
- 难度
- 2/5
- 预计耗时
- 1-3 小时
- 新手友好度
- 72/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 冷清
- 技术栈
- javascript, nodejs
调研方向
从 src/Routers/UsersRouter.js 第 454-471 行附近开始,将 token 查找与 email 路径进行比较。根据 issue 描述验证过期条件和查询选项。完成的标准是:使用维护上下文,通过单结果查找找到有效且未过期的 token。
由索引模型根据 Issue 内容生成。
描述
New Issue Checklist
- Report security issues confidentially.
- Any contribution is under this license.
- Before posting search existing issues.
Issue Description
⚠️ Potential issue | 🔴 Critical
Token lookup uses inverted expiry comparator and lacks Auth.maintenance/limit.
- _perishable_token_expires_at should be greater than “now” for a valid token.
- Use Auth.maintenance like the email path for consistency.
- Limit results to 1.
Apply:
- userResults = await req.config.database.find('_User', {
- _perishable_token: token,
- _perishable_token_expires_at: { $lt: Parse._encode(new Date()) },
- });
+ userResults = await req.config.database.find(
+ '_User',
+ {
+ _perishable_token: token,
+ _perishable_token_expires_at: { $gt: Parse._encode(new Date()) },
+ },
+ { limit: 1 },
+ Auth.maintenance(req.config)
+ );
🤖 Prompt for AI Agents
In src/Routers/UsersRouter.js around lines 454 to 471, the token lookup query
uses the wrong expiry comparator and is missing the same options as the email
path; change the _perishable_token_expires_at check to $gt Parse._encode(new
Date()) so only unexpired tokens match, and call req.config.database.find with
the same options as the email branch: pass { limit: 1 } and
Auth.maintenance(req.config) as the query options so the lookup is limited to
one result and runs under maintenance context.
Reported by @coderabbitai
- 主要语言
- JavaScript
- 星标
- 21.4k
- 派生
- 4.8k
- 平均合并
- 7 小时 36 分钟
- 30 天内合并 PR
- 67
环境准备
- 提供 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
parse-community/parse-server 的其他 Issue
-
Add MongoDB 9 support可能已有人在做 @ga262 于 5 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 75/100
parse-community/parse-server#10750 · 1 条评论 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 84/100
parse-community/parse-server#10720 · 1 条评论 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 78/100
parse-community/parse-server#10710 · 1 条评论 ·
维护者通常 1 天内回复
-
Node.js version in `.nvmrc` does not satisfy `engines.node`可能已有人在做 @kokokoXUY 于 13 天前认领。 未关闭
难度 1/5 1 小时以内 新手友好度 92/100
parse-community/parse-server#10699 · 1 条评论 ·
维护者通常 1 天内回复
-
RedisCacheAdapter put, del and clear reject on a Redis outage, producing unhandled rejections可能已有人在做 @AdrianCurtin 于 57 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 78/100
parse-community/parse-server#10634 · 1 条评论 ·
维护者通常 1 天内回复
查看 parse-community/parse-server 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 62/100
维护者通常 1 天内回复
-
factory-active factory-automatic harness/claude-code task-identify-harness-labels-done task-identify-issue-type-done
难度 2/5 1-3 小时 新手友好度 62/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 62/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 82/100
维护者通常 1 天内回复
-
documentation good first issue help wanted
难度 1/5 1-3 小时 新手友好度 85/100
zmo2s/agent-toolbox#23 ·