Skip to content

[Bug] maxkb interface vertically oversteps #3343

Open
@zhainanshidai

Description

@zhainanshidai

Contact Information

No response

MaxKB Version

1.10.8

Problem Description

put /api/function_lib/538cf118-4106-11f0-8885-0242ac140002
接口存在垂直越权问题。

Steps to Reproduce

1.使用函数库编辑函数,权限设为尽自己可见

Image

2.模拟请求

Image

Image

3.切换一个账号(没有该函数的权限)
获取到authorization,把body的函数改成return2
结果:succeed

Image
成功修改。
Image

The expected correct result

No response

Related log output

Additional Information

No response

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions