From 11b6017171dbbe6c5276eb90ebeb55b03deac35d Mon Sep 17 00:00:00 2001 From: Cheri Wen Date: Tue, 2 Jun 2026 00:46:50 +0800 Subject: [PATCH] fix: return 404 instead of 403 for unauthorized key access to prevent ID oracle (CWE-204) GET /api/v1/keys/:id previously returned distinct HTTP status codes for 'key not found' (404) vs 'key exists but belongs to another user' (403). This oracle allowed attackers to enumerate valid API key IDs by observing response differences. Now returns 404 in both cases so the response is identical regardless of whether a key exists. Fixes: CWE-204 (Information Disclosure via ID Oracle) --- backend/internal/handler/api_key_handler.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/backend/internal/handler/api_key_handler.go b/backend/internal/handler/api_key_handler.go index 9d6c6c1523..e0d73b390d 100644 --- a/backend/internal/handler/api_key_handler.go +++ b/backend/internal/handler/api_key_handler.go @@ -131,7 +131,7 @@ func (h *APIKeyHandler) GetByID(c *gin.Context) { // 验证所有权 if key.UserID != subject.UserID { - response.Forbidden(c, "Not authorized to access this key") + response.NotFound(c, "API key not found") return }