Skip to content

Improve API export signed URL evidence#1969

Open
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/api-export-signed-url-fixtures-1750
Open

Improve API export signed URL evidence#1969
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/api-export-signed-url-fixtures-1750

Conversation

@DENGXUELIN

Copy link
Copy Markdown

Closes #1750.

Summary

  • add bulk export and signed download URL evidence gates to api-security
  • cover create/status/download/cleanup authorization, signed URL lifecycle, storage isolation, export limits, retention, and auditability
  • add vulnerable and benign fixtures for cross-tenant export signed URL abuse versus scoped export controls

Validation

  • git diff --check origin/main...HEAD
  • Markdown fence balance check
  • added-line ASCII check
  • content marker check for API-EXPORT-* findings and fixtures
  • git merge-tree --write-tree origin/main HEAD

Bounty

Requested tier: Improver Moderate, USD 100 if accepted.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] api-security: add bulk export and signed download URL evidence gates

1 participant