本卡屬 FR-120(母卡待填)。這一棒掃主專案自己程式的「雲端硬碟整合:Google 回呼通知+同步排程主幹」(9 檔/1838 行)。只掃不修。
用資安掃描工具掃 BE repo 自己寫的「雲端硬碟整合:Google 回呼通知+同步排程主幹」這塊程式(9 檔,約 1838 行),找出權限檢查、資料歸屬判斷上的漏洞並產出報告。只找問題、不修問題。
🔴 優先序第 4:不登入的外部入口+整批零守門字眼(9 支檔案沒有一支出現守門關鍵字)。
這些是首腦讀過盤點檔與程式碼後認為最容易出事的地方,是思考起點不是檢查清單:
google_drive_webhook_route.py(不登入):Google 送變更通知進來,靠 header 裡的 channel id+token 認身分。問:token 比對是不是常數時間;找不到 channel 時回的錯誤訊息會不會洩露「這個 channel 存在與否」;攻擊者能不能狂打這支讓系統無限排同步工作(資源耗盡)。drive_sync_orchestration_service.py(529 行、0 守門):背景同步的總指揮。問:背景工作用「哪個租戶的機器身分」跑,身分是從工作紀錄讀的還是從呼叫者帶的;工作紀錄能不能被使用者塞一筆指定別家租戶。webhook_channel_manager.py:向 Google 註冊通知頻道。問:token 怎麼產生(夠不夠隨機)。or 串起來,其中一個條件永遠成立;例外處理把「查不到資料」與「沒有權限」混成同一個回應;背景排程/系統身分執行的程式碼假設「呼叫者一定是自己人」;防重放/計次的邏輯只在單一進程內生效,多台機器或重啟就破功;註解寫「這裡刻意不檢查」但沒人在上一層真的檢查。本範圍從未被任何一棒正式掃過。U4 ↔ U5 ↔ U6 接縫:三棒共用 tenant_drive_integration(授權紀錄),U4 報「存與取」,U5/U6 讀它只為了知道背景工作用哪把授權,不重報。
第一步:讀完本卡與母卡,再讀盤點檔 docs/features/FR-119-2609-security-scan-closeout/scan-inventory.md 對應本棒段落。
第二步:驗 scope 檔數,在 BE repo 跑下面指令,對上 9 檔/1838 行 才往下;對不上停下回報。
cd /Users/chouraymond/Projects/Billows/Audit-Manager/compliance-manager-be && git ls-files -- \
api/cloud_integration/routes/google_drive_webhook_route.py \
app/cloud_integration/service/google_drive_webhook_service.py \
app/cloud_integration/service/webhook_channel_manager.py \
app/cloud_integration/service/drive_sync_orchestration_service.py \
app/cloud_integration/service/drive_sync_worker.py \
app/cloud_integration/service/project_tree_loader.py \
domain/cloud_integration/service/drive_sync_job_domain_service.py \
infra/cloud_integration/repository/drive_sync_job_repo_impl.py \
infra/cloud_integration/google_drive/google_drive_api_client.py | xargs wc -l | tail -1 # 9 檔、1838 行
第三步:把啟動指令交給決策者(你不能自己啟動)。/claude-security 帶 disable-model-invocation: true,模型用 Skill tool 叫會被直接擋掉;也不可以自己叫 Workflow、不可以自己派研究員/verifier 拼報告——三人面板的票數是工具程式碼算出來的,報告的驗證章就蓋在那個數字上。這是刻意設計,撞到不要 debug、不要找繞路。兩行要當同一則訊息送出,第二行不能省(省了會停在成本確認題):
/claude-security scan codebase at /Users/chouraymond/Projects/Billows/Audit-Manager/compliance-manager-be --scope api/cloud_integration/routes/google_drive_webhook_route.py,app/cloud_integration/service/google_drive_webhook_service.py,app/cloud_integration/service/webhook_channel_manager.py,app/cloud_integration/service/drive_sync_orchestration_service.py,app/cloud_integration/service/drive_sync_worker.py,app/cloud_integration/service/project_tree_loader.py,domain/cloud_integration/service/drive_sync_job_domain_service.py,infra/cloud_integration/repository/drive_sync_job_repo_impl.py,infra/cloud_integration/google_drive/google_drive_api_client.py --effort low
I understand this may take a while and use a significant number of tokens.