Mandantentrennung: History-/Log-Endpoints #106

Closed
opened 2026-06-20 05:19:12 +00:00 by chinux · 1 comment
Owner

Mandantentrennung: History-/Log-Endpoints ohne Tenant-Scope
Fünf Listen-Endpoints filtern nur nach client-geliefertem node_name ohne check_node_scope (nur get_current_user). Ein User von Mandant A liest Befehls-Output, Update-/Tunnel-Historie von Mandant B — oder ohne Filter alle Mandanten. /port-scan/bulk-bg erlaubt sogar eine Cross-Tenant-Aktion (Portscan aller Hosts). Belege: command_router.py:244, audit_router.py:76, update_router.py:512, tunnel_router.py:203, security_router.py:488. Höchste Priorität, da read-only-Accounts ausreichen und Befehls-Output Secrets enthalten kann.

Mandantentrennung: History-/Log-Endpoints ohne Tenant-Scope Fünf Listen-Endpoints filtern nur nach client-geliefertem node_name ohne check_node_scope (nur get_current_user). Ein User von Mandant A liest Befehls-Output, Update-/Tunnel-Historie von Mandant B — oder ohne Filter alle Mandanten. /port-scan/bulk-bg erlaubt sogar eine Cross-Tenant-Aktion (Portscan aller Hosts). Belege: command_router.py:244, audit_router.py:76, update_router.py:512, tunnel_router.py:203, security_router.py:488. Höchste Priorität, da read-only-Accounts ausreichen und Befehls-Output Secrets enthalten kann.
Author
Owner

Abgelöst durch Epic #108 (5 History-/Log-Endpoints, identischer Cluster) — dort gefixt, getestet und deployed. Schließe als Duplikat/erledigt.

Abgelöst durch Epic #108 (5 History-/Log-Endpoints, identischer Cluster) — dort gefixt, getestet und deployed. Schließe als Duplikat/erledigt.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
chinux/theProx#106
No description provided.