Mandantentrennung: History-/Log-Endpoints #106
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Mandantentrennung: History-/Log-Endpoints ohne Tenant-Scope
Fünf Listen-Endpoints filtern nur nach client-geliefertem node_name ohne check_node_scope (nur get_current_user). Ein User von Mandant A liest Befehls-Output, Update-/Tunnel-Historie von Mandant B — oder ohne Filter alle Mandanten. /port-scan/bulk-bg erlaubt sogar eine Cross-Tenant-Aktion (Portscan aller Hosts). Belege: command_router.py:244, audit_router.py:76, update_router.py:512, tunnel_router.py:203, security_router.py:488. Höchste Priorität, da read-only-Accounts ausreichen und Befehls-Output Secrets enthalten kann.
Abgelöst durch Epic #108 (5 History-/Log-Endpoints, identischer Cluster) — dort gefixt, getestet und deployed. Schließe als Duplikat/erledigt.