T09 · Insecure Skill Coding Practices
- Location
SKILL.md:918- Finding
Anti-Addiction Compliance Handling Fails Open for Unknown Result Codes
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 918–935
Vulnerability Type: Fail-open authorization and compliance logic
Risk Level: HighVulnerable Code:
gdscript func _on_anti_addiction_callback(code: String, message: String) -> void: match code: "500": # LOGIN_SUCCESS - can play _try_restore_cloud_save() _enter_bookshelf() "1000", "1001": # Need re-login ToastManager.show_toast(tr("请重新登录")) "1030": # Time restricted ToastManager.show_toast(tr("当前时间无法游戏")) "1050": # Time used up ToastManager.show_toast(tr("今日游戏时长已用完")) "1100": # Age restricted ToastManager.show_toast(tr("年龄限制,无法进入游戏")) "1200": # Network error ToastManager.show_toast(tr("网络错误,请检查网络")) _: _try_restore_cloud_save() _enter_bookshelf()Technical Analysis
The wildcard branch treats every undocumented, malformed, empty, or newly introduced compliance result code as authorization to enter the game. This is a fail-open implementation: access is granted unless the result happens to match one of a small number of explicitly denied codes.
Compliance and authorization decisions should instead fail closed. Only an explicitly recognized success response should call
_enter_bookshelf(). Unknown responses can occur because of SDK API changes, integration defects, callback corruption, server-side errors, or incomplete code mappings. None of these conditions establishes that the user passed age and playtime checks.Attack Path
- The TapTap compliance callback returns a code that is not included in the local
matchstatement. - This may result from an SDK update, a new restriction code, an unexpected server response, or a malformed callback value.
- Execution reaches the
_wildcard branch. - The application invokes `enter ...[truncated 510 chars]
- The TapTap compliance callback returns a code that is not included in the local
- Remediation
View remediation
Remediation Suggestions
- Permit entry only when the callback contains the explicitly documented success code.
- Replace the wildcard branch with a denial state, retry flow, or recoverable error screen.
- Confirm all result-code meanings against the exact TapSDK version in use.
- Record unknown codes in privacy-safe diagnostic logs so mappings can be updated without granting access.
- Ensure network failures, parsing failures, empty codes, and SDK exceptions cannot reach the game-entry path.
- Add automated tests for every documented restriction code and for unknown, empty, malformed, and future result codes.
A safer pattern is:
gdscript func _on_anti_addiction_callback(code: String, message: String) -> void: match code: "500": _try_restore_cloud_save() _enter_bookshelf() "1000", "1001": _show_compliance_error("Authentication is required.") "1030", "1050", "1100": _show_compliance_error("Game access is currently restricted.") "1200": _show_compliance_error("Compliance verification failed due to a network error.") _: push_warning("Unknown compliance result code: " + code) _show_compliance_error("Unable to verify eligibility. Please try again.")
