T09 · Insecure Skill Coding Practices
- Location
scripts/game_simulator.py:217- Finding
Unvalidated move input causes denial of service and game-state corruption
- Content
View full analysis
Tuple[str, List[Card], int]: """ 解析出牌字符串 返回: (牌型, 牌列表, 强度) """ move_str = move_str.strip() # 解析炸弹 if '炸弹' in move_str or '炸' in move_str: # 提取点数 rank = None for r in ['大王', '小王', '2', 'A', 'K', 'Q', 'J', '10', '9', '8', '7', '6', '5', '4', '3']: if r in move_str: rank = r break if '大王' in move_str or '小王' in move_str: return ('天王炸弹', [], 1000) elif rank: count = 4 # 默认四炸 for c in ['七', '六', '五', '四']: if c in move_str: count = {'七': 7, '六': 6, '五': 5, '四': 4}[c] break return ('炸弹', [], 500 + count * 10) # 解析天王炸弹 if '王炸' in move_str or '王炸' in move_str: return ('天王炸弹', [], 1000) # 解析牌型 if '单张' in move_str or move_str[0] in '♠♥♣♦': return ('单张', [], 14) # 简化处理 if '对' in move_str: return ('对子', [], 14) if '顺' in move_str: return ('顺子', [], 10) return ('单张', [], 3) def execute_move(self, seat: int, move_str: str) -> bool: """执行出牌""" if seat != self.current_player: return False player = self.players[seat] pattern, cards, strength = self.parse_move(move_str) # 验证出牌是否合法(简化版) # 实际实现需要更复杂的牌型验证 # 记录出牌 if self.current_round is None: self.current_round = GameRound(leader=seat) self.round_number += 1 self.current_round.plays[seat] = move_str self.current_round.pattern = pattern self.current_round.strength = max(self.current_round.strength, strength) # 更新当前玩家 self.current_player = (seat % 4) + 1 # 检查 ...[truncated 2517 chars]- Remediation
View remediation
