本卡屬 FR-114 資安修正(母卡 CM-2019),第 2 批「只驗登入、不檢查歸屬」卡 2-1,修 SUMMARY #3(出自 M02-1/2/3/7)。高。修法規格來自內化卡,計畫在 docs/features/FR-114-2609-security-fix-dispatch/batches/plan-b2.md「卡 2-1」段。🔴 本卡要等第 1 批合回主線+套件發版後才能開工。

問題是什麼(白話)

檔案上傳模組的下載、PDF 預覽、存取權杖核發、刪除功能,目前只檢查「有沒有登入」,不檢查「這個檔案是不是你能碰的」——任何登入帳號知道檔案編號就能下載、預覽、甚至刪除別人上傳的檔案。這是本次掃描裡影響面最大的一個洞,因為附件功能被工作項證據、SSP 文件、意見回饋等好幾個業務模組共用。

首腦核對:

工作區

套件側:在 /Users/chouraymond/Projects/Jedicogy/module/jedi-python-package/.claude/worktrees/jedi-wt-fix-security/jedi-file-upload(branch fix/security-b1)改,只動自己那支套件的子目錄、只 git add 該子目錄下的檔。

跨 repo:BE 工作區 pyproject.toml 把 jedi-file-upload 的 pin 改成 path 形式指向上面那個套件 worktree,poetry update jedi-file-upload。這個 path 改動不 commit(git add 時跳過 pyproject.toml)。BE 側改動(app/、core/plugins/file_upload.py)在 /Users/chouraymond/Projects/Billows/Audit-Manager/compliance-manager-be/.claude/worktrees/wt-fix-security(branch fix/security-b1)做,不要碰主 checkout,跑服務用 PORT=8001。

FE 卡:/Users/chouraymond/Projects/Billows/Audit-Manager/compliance-manager-fe/.claude/worktrees/wt-fix-security(branch fix/security-b1;不存在就 git worktree add .claude/worktrees/wt-fix-security -b fix/security-b1 開),本卡也含 FE 這 10 個呼叫點的確認。

在哪裡

upload_file_route.py:141   下載,補歸屬檢查
upload_file_route.py:173   PDF 預覽,補歸屬檢查
upload_file_route.py:123   存取權杖核發,目前零檢查(:135 完全沒做歸屬比對)
upload_file_route.py:91    刪除,補歸屬檢查
upload_file_service.py:37   get_upload_file,新增「誰能碰這個檔案」檢查掛勾點
upload_file_service.py:47   delete_file,同上
upload_file_service.py:53   delete_files,同上
guards.py:42   file_access_guard,本卡的共用檢查主要邏輯落點
ports.py   定義共用檢查用的介面(port)
contract.py   FileUploadAdapters dataclass,新增 capability_required 欄位(欄位名務必與既有慣例一致,別打錯)
core/plugins/file_upload.py:110-111   BE 主專案掛載點,接上套件新機制
app/flow_control/service/job_evidence_service.py   工作項證據,重用既有 assert_project_participant 作為「答案」實作
app/oscal/service/ssp_control_implementation_service.py   SSP 證據,本卡要接上共用檢查
jedi-issue 套件 issue_upload_file_mapping 對應 service(目前零 BE 呼叫,本卡新增歸屬判斷實作)

怎麼修