Snyk, разработчик инструментов для безопасности приложений, объяснила в руководстве, как ИИ-агент может пропустить проверку прав на данные при запросе счёта. В примере из руководства обработчик проверяет, вошёл ли пользователь в систему, но выдаёт чужой счёт при подмене идентификатора счёта в адресе.

При поиске счёта добавляют проверку организации, к которой принадлежит пользователь. Автор подчёркивает, что правила доступа зависят от продукта: в некоторых системах читать данные разных организаций разрешено аудиторам или головным учётным записям.

Snyk рекомендует описать, кому принадлежат данные и кто имеет к ним доступ, и отдельно проверять права доступа в коде ИИ-агентов. Для каждого типа данных автор предлагает тест: пользователь одной организации должен получить ошибку 404 при запросе данных другой.

Проверка утверждений:

  • Snyk разобрала на примере запроса счёта, как ИИ-агент может пропустить проверку прав на данные. (подтверждено самой публикацией: доказательство; «Because the authorization requirement was never stated, and the agent is not wrong about the task it was given. Consider a developer asking a coding agent to add an endpoint that returns an invoice by ID. The agent produces a route that verifies the caller is logged in, looks up the invoice using the identifier from the URL, returns a 404 when nothing matches, and sends the record back to the client. Every one of those decisions is correct for the task as written. The endpoint authenticates, it handles the missing-record case, and it reads cleanly in review. It also lets any authenticated user read any invoice in the system by changing one value in the URL. The correction is one additional condition on the lookup: match the invoice by its identifier, and by the organization the caller belongs to. Nothing else about the endpoint changes.»)
  • В примере из руководства обработчик проверяет, вошёл ли пользователь в систему, но выдаёт чужой счёт при подмене идентификатора счёта в адресе. (подтверждено самой публикацией: доказательство; «Every one of those decisions is correct for the task as written. The endpoint authenticates, it handles the missing-record case, and it reads cleanly in review. It also lets any authenticated user read any invoice in the system by changing one value in the URL.»)
  • При поиске счёта добавляют проверку организации, к которой принадлежит пользователь. (подтверждено самой публикацией: доказательство; «The correction is one additional condition on the lookup: match the invoice by its identifier, and by the organization the caller belongs to. Nothing else about the endpoint changes.»)
  • Автор подчёркивает, что правила доступа зависят от продукта: в некоторых системах читать данные разных организаций разрешено аудиторам или головным учётным записям. (подтверждено самой публикацией: доказательство; «In a different product, the third fact could be false, since some platforms let auditors, resellers, or parent accounts read across tenant boundaries by design. The rule is a property of the product, not of the language or the framework.»)
  • Snyk рекомендует описать, кому принадлежат данные и кто имеет к ним доступ, и отдельно проверять права доступа в коде ИИ-агентов. (подтверждено самой публикацией: доказательство; «Write down the ownership rules. For each resource type, record what it belongs to and who may read or modify it. Authorization flaws survive review because this information has never been written anywhere that a reviewer or an analyst can check. Make authorization an explicit review item on agent-authored pull requests. Not a general instruction to review carefully, but a specific question: does this endpoint verify that the caller is entitled to the object, and against which field?»)
  • Для каждого типа данных автор предлагает тест: пользователь одной организации должен получить ошибку 404 при запросе данных другой. (подтверждено самой публикацией: доказательство; «One test per resource, asserting that a valid session from one tenant gets a 404 on another tenant’s object, turns the rule you wrote down in step two into one that stays enforced.»)

Публикации:

Первоисточники:

оценка 49,4 из 100 · тип: руководство