github / github/codeql

False positive: "Missing function level access control" where public endpoint name contains "Edit"

未關閉
#21,042 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
C# false-positive
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

**Description of the false positive**

We have a .NET 8 Api.

We have a controller method that has the characters 'Edit' in it, but the whole word is not Edit. This causes the method to be marked with the rule cs/web/missing-function-level-access-control. The method even has the 'AllowAnonymous' attribute on it.

**Code samples or links to source code**

```
[AllowAnonymous]
public async Task TestEditionAsync(){

}
```

Is there a way to get this alert resolved?

貢獻指南

開啟貢獻指南

研究方向

Start with the CodeQL rule cs/web/missing-function-level-access-control and reproduce the report using the provided .NET 8 controller example. The issue is resolved when a public method named TestEditionAsync with AllowAnonymous is no longer flagged solely because its name contains Edit.

由索引模型根據 Issue 內容生成。

評估

技術堆疊
csharp
領域
security
Issue 類型
缺陷
難度
3/5
預估耗時
1-2 天
活躍度
停滯
描述清晰度
基本清楚
新手友好度
45/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。