AOSSIE-Org / AOSSIE-Org/DebateAI

[FEATURE]: /profile Elo update endpoint lets any authenticated client set arbitrary users' ratings

未关闭
#392 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
enhancement
主要语言
TypeScript
星标
84
派生
198
平均合并
2 天 19 小时
30 天内合并 PR
30

描述

### Feature and its Use Cases

## Description
`UpdateEloAfterDebate` in `backend/controllers/profile_controller.go` (lines 352-381) reads `winnerId` and `loserId` straight from the request body and updates both users' ratings with no verification that:
- the caller was a participant in any debate,
- a debate between those users actually happened,
- the caller isn't naming themselves as winner repeatedly.

It is also a plain FindOne → `$set` read-modify-write with no transaction, so concurrent calls lose updates.

### Additional Context

## Impact
Any logged-in user can farm rating (or zero out other players) with a few `curl` calls, making the leaderboard meaningless.

## Suggested Fix
Derive winner/loser server-side from the stored debate result (the websocket/judge flow already knows the outcome) and remove the client-supplied IDs. Use an atomic update (`$inc` or optimistic concurrency on a version field).

### Code of Conduct

- [x] I have joined the [Discord server](https://discord.gg/hjUhu33uAn) and will post updates there
- [x] I have searched existing issues to avoid duplicates

贡献指南

这个仓库没有索引到贡献指南

调研方向

Start in backend/controllers/profile_controller.go at UpdateEloAfterDebate (lines 352-381), then trace the websocket/judge flow and the stored debate result it uses. Review the current FindOne → $set path and verify that completion derives the outcome server-side, prevents unauthorized rating changes, and preserves concurrent updates.

由索引模型根据 Issue 内容生成。

评估

技术栈
go, mongodb
领域
authorization, backend, databases, security
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
冷清
描述清晰度
基本清楚
新手友好度
42/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。