Skip to content

[安全] 全系统缺少认证与授权,存在越权访问(IDOR) #16

Description

@yuezengwu

cc @wyzBelinda

问题

系统所有 HTTP/WebSocket 接口均无认证与授权:

  • api/middleware.py 中仅定义了 AuthenticationError/AuthorizationError 异常类,从未被任何路由使用。
  • 资源接口以路径参数 patient_id 直接取数据,无归属校验,构成越权访问(IDOR):
    • modules/RareSystem/backend/api/cases.py:119 —— GET /api/cases/{patient_id}
    • modules/RareSystem/backend/api/cases.py:253 —— DELETE /api/cases/{patient_id}(会连带删除磁盘上的 VCF 文件)
  • CORS 配置过宽:main.py:58-64 使用 allow_credentials=True 且 allow_methods=["*"]、allow_headers=["*"]。

影响

任何可访问服务的人可枚举 patient_id 读取或删除任意患者的基因组数据与病例。基因组数据属高敏感健康数据,越权访问是合规红线。

解决方案

  1. 在网关引入统一认证(JWT/OAuth 或 API Key + mTLS),下游服务只接受经网关转发的已认证请求。
  2. 为所有资源接口增加基于用户身份的授权校验,消除 IDOR(校验请求者是否有权访问该 patient_id)。
  3. 收紧 CORS:allow_origins 用明确白名单,allow_methods/allow_headers 按需列举。

优先级

高。对外/生产部署前必须解决。

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions