本卡屬 FR-114 資安修正(母卡 CM-2019),第 4 批「憑證殘留」卡 4-3,修 SUMMARY #70(出自模組報告,jedi-detection)。中。修法規格來自本批查證,計畫在 docs/features/FR-114-2609-security-fix-dispatch/batches/plan-b4.md「卡 4-3」段。

問題是什麼(白話)

掃描弱點時,程式在把「這次要掃什麼」的工作單(派工表 agent_tasks)寫進資料庫時,多此一舉地把解密後的明文帳密也一起塞進去存了一份。這份多存的明文完全沒有任何程式在讀它——代理程式(agent)實際拿到帳密走的是另一條、心跳時才重新解密組裝的正確路徑,這行是舊的殘留,刪掉不會影響任何功能。

首腦核對:

工作區

在哪裡

jedi_detection/app/service/detection_orchestration_service.py:480       params["_credentials"] = creds 這一行,整支刪除
jedi_detection/app/service/detection_orchestration_service.py:438-517   _dispatch_one(),刪除那行所在的函式(只刪那一行,函式其他部分不動)
jedi_detection/app/service/detection_orchestration_service.py:942-947   start_assignment_now()(第二條呼叫路徑,:980 呼叫 _dispatch_one,不需改這裡,因為只刪一行就兩條路都修好)
jedi-remote-agent/jedi_remote_agent/infra/agent_task/model/agent_task.py:45   agent_tasks 的 params JSONB 欄位 model(參考用,不改)
infra/remote_agent/adapter/detection_task_payload_provider.py:68,109-125     正確的心跳重新解密路徑(參考用,確認不受影響,不改)

怎麼修

手測