Repository navigation
[fix][evaluation] add OpenAPI extra_output field and fix two horizontal privilege escalations - #564
Merged
Merged
Conversation
…ponse - Add EvaluatorExtraOutputContent struct to domain_openapi IDL - Regenerate kitex_gen from updated IDL - Add OpenAPIEvaluatorExtraOutputContentDO2DTO convertor - Inject fileProvider into EvalOpenAPIApplication for URI-to-URL signing - Add fillExtraOutputURLs to sign TOS URIs before returning response - Regenerate wire_gen.go - Add unit tests for extra_output conversion
…riment convertor) The ListExperimentResultOApi uses openAPIEvaluatorOutputDataDO2DTO (lowercase, in convertor/experiment/openapi.go) instead of the public OpenAPIEvaluatorOutputDataDO2DTO (in convertor/evaluator/openapi.go). The private method was missing the ExtraOutput and Stdout field mapping.
… tracing Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…rs to reach 90% coverage
…o prevent horizontal privilege escalation
…r BatchGetExptAggrResultByExperimentIDs Add a dedicated table-driven case asserting that experiments whose SpaceID differs from the input spaceID are filtered out (validExptIDs), so all downstream queries (BatchGetExptAggrResultByExperimentIDs / GetEvaluatorRefByExptIDs / batchGetTagInfoByExperimentIDs) only receive the valid exptID and the cross-space exptID is dropped. Verified via mutation: removing the filter makes this case fail. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…rizontal privilege escalation UpdateExperiment used req.WorkspaceID to overwrite the DB space_id without verifying ownership, allowing an attacker to move another workspace's experiment into their own. Validate got.SpaceID == req.GetWorkspaceID() right after Get and before any write, mirroring DeleteExperiment. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Add 'workspace mismatch with experiment space' case asserting the request is rejected before manager.Update is invoked, mirroring the DeleteExperiment test. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
VinCinx
previously approved these changes
Jun 25, 2026
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
xueyizheng
approved these changes
Jun 25, 2026
VinCinx
approved these changes
Jun 25, 2026
Codecov Report❌ Patch coverage is
@@ Coverage Diff @@
## main #564 +/- ##
==========================================
+ Coverage 77.60% 78.12% +0.51%
==========================================
Files 670 670
Lines 75995 76214 +219
==========================================
+ Hits 58979 59543 +564
+ Misses 13565 13238 -327
+ Partials 3451 3433 -18
Flags with carried forward coverage won't be shown. Click here to find out more.
... and 26 files with indirect coverage changes Continue to review full report in Codecov by Harness.
🚀 New features to boost your workflow:
|
Colin4k1024
pushed a commit
to Colin4k1024/coze-loop
that referenced
this pull request
Aug 28, 2026
…al privilege escalations (coze-dev#564) * feat(openapi): add extra_output field to ListExperimentResultOApi response - Add EvaluatorExtraOutputContent struct to domain_openapi IDL - Regenerate kitex_gen from updated IDL - Add OpenAPIEvaluatorExtraOutputContentDO2DTO convertor - Inject fileProvider into EvalOpenAPIApplication for URI-to-URL signing - Add fillExtraOutputURLs to sign TOS URIs before returning response - Regenerate wire_gen.go - Add unit tests for extra_output conversion * fix: add extra_output field in openAPIEvaluatorOutputDataDO2DTO (experiment convertor) The ListExperimentResultOApi uses openAPIEvaluatorOutputDataDO2DTO (lowercase, in convertor/experiment/openapi.go) instead of the public OpenAPIEvaluatorOutputDataDO2DTO (in convertor/evaluator/openapi.go). The private method was missing the ExtraOutput and Stdout field mapping. * debug: add key logs for OpenAPI ListExperimentResultOApi extra_output tracing Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * test(convertor): add unit tests for evaluator and experiment convertors to reach 90% coverage * [fix][evaluation] add spaceID validation for BatchGetExptAggrResult to prevent horizontal privilege escalation * test(evaluation): add cross-space privilege escalation filter case for BatchGetExptAggrResultByExperimentIDs Add a dedicated table-driven case asserting that experiments whose SpaceID differs from the input spaceID are filtered out (validExptIDs), so all downstream queries (BatchGetExptAggrResultByExperimentIDs / GetEvaluatorRefByExptIDs / batchGetTagInfoByExperimentIDs) only receive the valid exptID and the cross-space exptID is dropped. Verified via mutation: removing the filter makes this case fail. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(evaluation): add space_id check in UpdateExperiment to prevent horizontal privilege escalation UpdateExperiment used req.WorkspaceID to overwrite the DB space_id without verifying ownership, allowing an attacker to move another workspace's experiment into their own. Validate got.SpaceID == req.GetWorkspaceID() right after Get and before any write, mirroring DeleteExperiment. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * test(evaluation): cover UpdateExperiment workspace mismatch authz Add 'workspace mismatch with experiment space' case asserting the request is rejected before manager.Update is invoked, mirroring the DeleteExperiment test. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * test(evaluation): cover fillExtraOutputURLs and raise patch coverage Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * style(evaluation): gofumpt format test files to pass lint Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: wangtao.everett <wangtao.everett@bytedance.com> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
本 PR 合并了 evaluation 模块的三项改动(一次发布):
1. feat: ListExperimentResultOApi 响应新增 extra_output 字段
kitex_gen
2. fix: BatchGetExptAggrResult 水平越权校验
validExptIDs,下游聚合/评估器引用/标签查询全部改用过滤后的 ID,防止跨 workspace 读取他人实验聚合结果
3. fix: UpdateExperiment 水平越权校验
既有范式),防止用本 workspace 的 id 覆盖/搬移他人实验的 space_id
Why
#2、#3 是同类水平越权(horizontal privilege escalation)修复:攻击者持有 A workspace
的合法凭证,却能读取/修改属于 B workspace 的实验资源。修复对齐已有 DeleteExperiment 校验范式,复用
errno.CommonBadRequestCode,不新增错误码。
关联 Meego: https://meego.larkoffice.com/fornax/story/detail/7344006097 (水平校验修复)
单元测试(gomock + testify,本地 GOTOOLCHAIN=go1.24.6 go test 全绿):
SpaceID 不匹配的实验,断言报错且不调用 Update(先校验后写库);红→绿变异验证通过
space 实验,断言下游查询只对合法 exptID 发起;移除过滤逻辑后用例如期 FAIL
PPE 泳道端到端验证(ppe_test 泳道,跨 workspace 越权场景):
Scope note
本 PR 仅含 evaluation/openapi 改动(16 文件,其中 3 个为 kitex_gen 生成代码)。仅修水平越权校验,未改 DAO 层
WHERE(纵深防御另议);notification_conf / pool.go 经核查当前代码已一致,不在本次范围。