[危急] JWT签名验证可被绕过 #70
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
问题描述
backend/app/core/behavior_middleware.py 第56-65行,JWT验证逻辑存在两处严重缺陷:
涉及文件
修复建议
严重程度
危急 - 认证绕过风险