本卡屬 FR-114 資安修正(母卡 CM-2019),第 2 批「只驗登入、不檢查歸屬」卡 2-10,修 SUMMARY #4/#47/#113(出自 M03-2/M03-12/M03-8)。中。修法規格來自內化卡,計畫在 docs/features/FR-114-2609-security-fix-dispatch/batches/plan-b2.md「卡 2-10」段。🔴 本卡要等第 1 批合回主線+套件發版後才能開工。

問題是什麼(白話)

#4:弱點檢測工具的「測試連線」端點沒有能力檢查,任何登入帳號都能拿去試探內部設定的檢測工具連線資訊。#47:查詢執行紀錄列表的方法沒有檢查是不是該專案成員,找不到資料時還回傳空清單,讓人分不清是「沒資料」還是「沒權限」。#113(嚴重度已從中下修為低):掃描設定相關的 8 支讀取端點都沒有掛守門。

首腦核對:

工作區

套件側:在 /Users/chouraymond/Projects/Jedicogy/module/jedi-python-package/.claude/worktrees/jedi-wt-fix-security/jedi-detection(branch fix/security-b1)改,只動自己那支套件的子目錄、只 git add 該子目錄下的檔。

跨 repo:BE 工作區 pyproject.toml 把 jedi-detection 的 pin 改成 path 形式指向上面那個套件 worktree,poetry update jedi-detection。這個 path 改動不 commit。

在哪裡

detection_tool_route.py:126   TenantDetectionToolConfigTestConnectionRoute.post,缺 @capability_required,複製 :67/:88/:105 既有寫法
detection_tool_route.py:143   確認不用動
detection_orchestration_service.py:1649   list_executions,缺 assert_project_participant,複製同檔 8 個既有呼叫點寫法;找不到資料要回「找不到」不是空清單
detection_profile_route.py:135   缺守門
detection_profile_route.py:163   缺守門
detection_profile_route.py:211   缺守門
detection_profile_route.py:274   缺守門
detection_profile_route.py:303   缺守門
detection_profile_route.py:328   缺守門
detection_profile_route.py:507   缺守門
detection_profile_route.py:527   缺守門
detection_profile_route.py:54-56   既有裝飾器寫法(含 lambda 延遲求值),原封不動複製
detection_profile_route.py:290   註解內容誤導,順手更新
detection_profile_route.py:540   註解內容誤導,順手更新

怎麼修