本卡屬 FR-114 資安修正(母卡 CM-2019),第 1 批「權限地基」卡 1-2,修 SUMMARY #37 後半(出自 M03-14+M06-7)。中。修法規格來自內化卡,計畫在 docs/features/FR-114-2609-security-fix-dispatch/batches/plan-b1.md「卡 1-2」段。🔴 本卡依賴卡 1-1 先完成(BE 主專案新增的嚴格守門要先存在,套件側才有東西可換)。
弱點檢測套件(jedi-detection)裡八支會改資料的功能,目前呼叫的是太鬆的舊守門,跟卡 1-1 的問題同一個洞——任何登入帳號知道任務編號就能對別家客戶的任務動手。
首腦核對:
套件側:在 /Users/chouraymond/Projects/Jedicogy/module/jedi-python-package/.claude/worktrees/jedi-wt-fix-security/jedi-detection(branch fix/security-b1)改,只動自己那支套件的子目錄、只 git add 該子目錄下的檔。
跨 repo:BE 工作區 pyproject.toml 把 jedi-detection 的 pin 改成 path 形式指向上面那個套件 worktree,poetry update jedi-detection。這個 path 改動不 commit(git add 時跳過 pyproject.toml)。
detection_orchestration_service.py:196 呼叫舊守門,改用卡 1-1 新增的嚴格守門
detection_orchestration_service.py:871 同上
detection_orchestration_service.py:925 同上
detection_orchestration_service.py:1007 同上
detection_orchestration_service.py:1032 同上
detection_orchestration_service.py:1097 同上
detection_orchestration_service.py:1127 同上
detection_orchestration_service.py:1470 同上
detection_orchestration_service.py:1639 自動完成路徑——不動,沒有 request context,本來就不掛守門,設計如此