T09 · Insecure Skill Coding Practices
- Location
generate-function.js:104- Finding
Unrestricted Caller-Controlled Database Operations
- Content
View full analysis
{ const { action, collection, data, id, where } = event switch (action) { case 'create': return await db.collection(collection).add({ data }) case 'read': if (id) { return await db.collection(collection).doc(id).get() } return await db.collection(collection).where(where || {}).get() case 'update': return await db.collection(collection).doc(id).update({ data }) case 'delete': return await db.collection(collection).doc(id).remove() default: return { error: 'Invalid action' } } } ``` ### Technical Analysis The generated cloud function accepts the database collection, operation, record identifier, query, and record data directly from the invoking client. It does not authenticate the caller, derive identity through `cloud.getWXContext()`, restrict accessible collections, enforce ownership, or validate the supplied data. Cloud functions commonly execute with permissions exceeding those granted to the Mini Program client. Consequently, database security rules applicable to direct client access may not prevent abuse through this function. ### Attack Path 1. A developer generates and deploys the `crud` cloud function. 2. An attacker invokes the function through the Mini Program cloud API. 3. The attacker sets `collection` to a sensitive collection such as `users` or `orders`. 4. The attacker uses `action: "read"` with an empty filter to retrieve records. 5. The attacker can subsequently submit `update` or `delete` with selected record identifiers. ### Impact Assessment An unauthenticated or ordinary application user may gain read and write access to arbitrary application collections. Depending on deployed database ...[truncated 135 chars]- Remediation
View remediation
