本卡屬 FR-114 資安修正(母卡 CM-2019),第 1 批「權限地基」卡 1-2,修 SUMMARY #37 後半(出自 M03-14+M06-7)。中。修法規格來自內化卡,計畫在 docs/features/FR-114-2609-security-fix-dispatch/batches/plan-b1.md「卡 1-2」段。🔴 本卡依賴卡 1-1 先完成(BE 主專案新增的嚴格守門要先存在,套件側才有東西可換)。

問題是什麼(白話)

弱點檢測套件(jedi-detection)裡八支會改資料的功能,目前呼叫的是太鬆的舊守門,跟卡 1-1 的問題同一個洞——任何登入帳號知道任務編號就能對別家客戶的任務動手。

首腦核對:

工作區

套件側:在 /Users/chouraymond/Projects/Jedicogy/module/jedi-python-package/.claude/worktrees/jedi-wt-fix-security/jedi-detection(branch fix/security-b1)改,只動自己那支套件的子目錄、只 git add 該子目錄下的檔。

跨 repo:BE 工作區 pyproject.toml 把 jedi-detection 的 pin 改成 path 形式指向上面那個套件 worktree,poetry update jedi-detection。這個 path 改動不 commit(git add 時跳過 pyproject.toml)。

在哪裡

detection_orchestration_service.py:196   呼叫舊守門,改用卡 1-1 新增的嚴格守門
detection_orchestration_service.py:871   同上
detection_orchestration_service.py:925   同上
detection_orchestration_service.py:1007  同上
detection_orchestration_service.py:1032  同上
detection_orchestration_service.py:1097  同上
detection_orchestration_service.py:1127  同上
detection_orchestration_service.py:1470  同上
detection_orchestration_service.py:1639  自動完成路徑——不動,沒有 request context,本來就不掛守門,設計如此

怎麼修

手測

做完要回寫報告