本卡屬 FR-114(母卡 CM-2019),CM-2063 驗收時順帶發現,決策者 2026-09-24 裁開。小卡,只改 BE。
儲存設定頁新建一組物件儲存(MinIO/SeaweedFS)設定時,密鑰欄是必填,但只有前端擋。直接打後端 API 建一組沒有密鑰的設定會成功,之後上傳下載全部失敗、錯誤訊息看不出原因。
BE app/system_config/service/guarded_system_config_service.py:675 create_system_config():已有 _reject_hidden/_assert_restricted_group_access/_assert_company_wide_write_allowed/_assert_drive_app_overrides_valid 四道,缺密鑰必填檢查
同檔 :124-125 註解:密鑰鍵名兩種都吃(MinIO 用 minio_secret_key、SeaweedFS 用 secret_key)
⚠️ 本檔 763 行,接近 800 上限——新檢查放新檔或既有 helper 檔,本檔只加一行呼叫
minio_secret_key 與 secret_key 皆空 → BadRequestError。error code 先找既有可用的,沒有才照 GRC_400xxx 新增並補 FE error-code.json 三語。.claude/worktrees/wt-fix-security(branch fix/security-b1),主 checkout 不動;不碰 pyproject/lock。app/system_config/service/storage_secret_guard.py(assert_storage_secret_present),只擋 create_system_config——storage_type 為 minio/seaweedfs 且 secret_key/minio_secret_key 兩個鍵都空時回 400(新增 SYSTEM_CONFIG_STORAGE_SECRET_REQUIRED = SYSTEM_CONFIG_400004)。local/remote_agent 不需密鑰不受影響;update 走既有 CM-2063「沒帶就沿用既有」邏輯不動。guarded_system_config_service.py 已 763 行接近 800 行上限,照規範新檢查放新檔、本檔只加一行呼叫。SYSTEM_CONFIG_400004 錯誤訊息。c2d1657fa(compliance-manager-be,worktree .claude/worktrees/wt-fix-security,branch fix/security-b1);FE 81dcc1b(compliance-manager-fe 同 worktree/branch)。assert_storage_secret_present 確認 minio 無密鑰擋下、有密鑰放行、seaweedfs 用 secret_key 鍵名放行、local 不擋、非 STORAGE_CONFIG group 不擋;並跑既有 test_system_config_secret_mask.py/test_system_config_capability_routing.py/test_system_config_route_precedence.py 共 42 項全過。