fix: 全APIの変更系ルート権限監査(require_write 付与の残り) #39
Labels
No labels
h1-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
joe/o2#39
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
概要
src/o2/api/__init__.pyで_auth_deps = [Depends(require_read)]が多数のルーターに付与されており、変更系(POST/PUT/PATCH/DELETE)ルートにrequire_writeが設定されていません。#38 で Web UI 露出分(masters/write/accounts の25ルート)は修正済みですが、残りのモジュールは未対応です。現状(変更系ルート数の目安)
accounting(8) /ai(9) /automation(10) /bank_reconciliation(13) /billing_api(10) /billing_pricing(9) /fixed_assets(5) /iot(6) /masters(対応済) /multi_currency(4) /notes(5) /payroll(15) /purchase_invoices(5) /purchase_orders(8) /quotations(6) /sales_orders(6) /security(6) /set_products(5) /stocktaking(4) /sync(3) /tax(8) /tenants(2) /write(対応済) ほか影響
Role.VIEWERのトークンで、販売/購買/在庫/給与/税務などの変更系 API を直接叩いてデータを変更できる対応方針(要検討)
dependencies=[Depends(require_write)]を付与(#38 と同じ方式。明示的で安全)_auth_depsに適用。ただし POST を計算用途に使うエンドポイント(例:/api/ai/suggest,/api/chat)は read 権限のままにしたい場合があり、除外リスト設計が必要tenants/admin/securityは既にrequire_platform_manage/require_manageで保護済みか確認受け入れ条件
Role.VIEWERで変更系が 403、GET は 200test_api_schema.py/test_api_contract.py緑関連
対応完了: 全変更系ルートの権限監査
アプリ全体の変更系(POST/PUT/PATCH/DELETE)ルートに
require_writeを付与しました。mainb52ed93にマージ・push 済み。付与結果(独立検証済み)
dependencies=[Depends(require_write)](GET は対象外)read のままにした例外(データを変更しない用途)
ai:/suggest/audit/{y}/{m}/forecast/*/analysis/financial/accountant/suggestchat POST ""currencies POST /convertbilling_pricing POST /prices/getdocument_chain POST /verify/verify-seal/{year}bank_reconciliation POST /parse/zengin/transfer/exportmulti_currency POST /gain-lossmcp POST /mcpauth.py(公開)/adminsecuritytenantsapi_key(manage/platform_manage で既存保護)テスト
tests/test_write_permissions.py46 passed(VIEWER 変更系 403 / ACCOUNTANT 200-201 / VIEWER GET 200 を横断検証)成果物
b96c27f(167ルート付与)、d8e572d(計算系を read に精緻化)→ mainb52ed93残課題(別Issue)
MCP の
POST /mcpは read 権限のままですが、src/o2/mcp/tools.pyのdispatch_toolがロール検証を行わず、VIEWER トークンでもcreate_journal等の更新系ツールを実行可能です(tenant scope 検証のみ)。→ #40 として起票。本 Issue のスコープ(REST 変更系ルートの権限)は完了につきクローズします。