gnuboard/g6

0 errors, 188 warningsmaster

No critical or high-risk findings. 155 worth a look.

188 warnings in the paths between 296 routes and 1 tables.

Every file was read, but 8 places in them could not be parsed — listed at the end of this report.

ROUTE FINDINGS154 of 296 · 12/12 rules
ROUTES
296
TABLES
1
FILES READ
302/302
RULES RUN
12/12

188 findings

155 medium33 low

  • Mediumhigh confidencePOST /admin/board_copy_update makes calls the check could not follow, so its data access is unknown, not absent: service.is_exist() on BoardFileService; service.copy_board_files() on BoardFileService.

    No rule could run on POST /admin/board_copy_update: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.is_exist() on BoardFileService; service.copy_board_files() on BoardFileService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /admin/member_list_delete makes calls the check could not follow, so its data access is unknown, not absent: file_service.update_image_file() on MemberImageService.

    No rule could run on POST /admin/member_list_delete: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: file_service.update_image_file() on MemberImageService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /admin/member_form_update makes calls the check could not follow, so its data access is unknown, not absent: file_service.update_image_file() on MemberImageService.

    No rule could run on POST /admin/member_form_update: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: file_service.update_image_file() on MemberImageService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /admin/point_update makes calls the check could not follow, so its data access is unknown, not absent: service.save_point() on PointService.

    No rule could run on POST /admin/point_update: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.save_point() on PointService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /admin/point_list_delete makes calls the check could not follow, so its data access is unknown, not absent: member_service.update_member_point() on MemberService; service.delete_expire_point() on PointService (+3 more).

    No rule could run on POST /admin/point_list_delete: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_service.update_member_point() on MemberService; service.delete_expire_point() on PointService; service.delete_use_point() on PointService; service.insert_use_point() on PointService; service.get_total_point() on PointService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /admin/popular/delete makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_populars() on PopularService.

    No rule could run on POST /admin/popular/delete: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.fetch_populars() on PopularService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /autosaves makes calls the check could not follow, so its data access is unknown, not absent: service.get_autosave_list() on AJAXService.

    No rule could run on GET /autosaves: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.get_autosave_list() on AJAXService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /autosaves/count makes calls the check could not follow, so its data access is unknown, not absent: service.get_autosave_count() on AJAXService.

    No rule could run on GET /autosaves/count: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.get_autosave_count() on AJAXService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /autosaves/{as_id} makes calls the check could not follow, so its data access is unknown, not absent: service.get_autosave_content() on AJAXService.

    No rule could run on GET /autosaves/{as_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.get_autosave_content() on AJAXService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /autosaves makes calls the check could not follow, so its data access is unknown, not absent: service.autosave_save() on AJAXService; service.get_autosave_count() on AJAXService.

    No rule could run on POST /autosaves: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.autosave_save() on AJAXService; service.get_autosave_count() on AJAXService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceDELETE /autosaves/{as_id} makes calls the check could not follow, so its data access is unknown, not absent: service.autosave_delete() on AJAXService.

    No rule could run on DELETE /autosaves/{as_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.autosave_delete() on AJAXService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /{bo_table}/writes makes calls the check could not follow, so its data access is unknown, not absent: service.get_board_per_page() on ListPostServiceAPI; service.get_writes() on ListPostServiceAPI (+2 more). It does not declare authentication.

    No rule could run on GET /{bo_table}/writes: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.get_board_per_page() on ListPostServiceAPI; service.get_writes() on ListPostServiceAPI; service.get_total_count() on ListPostServiceAPI; service.get_notice_writes() on ListPostServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /{bo_table}/writes/{wr_id} makes calls the check could not follow, so its data access is unknown, not absent: service.get_links() on ReadPostServiceAPI; service.get_comments() on ReadPostServiceAPI (+7 more). It does not declare authentication.

    No rule could run on GET /{bo_table}/writes/{wr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.get_links() on ReadPostServiceAPI; service.get_comments() on ReadPostServiceAPI; service.validate_secret() on ReadPostServiceAPI; service.validate_repeat_with_slowapi() on ReadPostServiceAPI; service.block_read_comment() on ReadPostServiceAPI; service.validate_read_level() on ReadPostServiceAPI; service.check_scrap() on ReadPostServiceAPI; service.check_is_good() on ReadPostServiceAPI; ajax_service.get_ajax_good_data() on AJAXService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /{bo_table}/writes/{wr_id} makes calls the check could not follow, so its data access is unknown, not absent: service.get_write_password() on ReadPostServiceAPI; service.validate_read_wr_password() on ReadPostServiceAPI (+7 more). It does not declare authentication.

    No rule could run on POST /{bo_table}/writes/{wr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.get_write_password() on ReadPostServiceAPI; service.validate_read_wr_password() on ReadPostServiceAPI; service.get_links() on ReadPostServiceAPI; service.get_comments() on ReadPostServiceAPI; service.validate_repeat_with_slowapi() on ReadPostServiceAPI; service.block_read_comment() on ReadPostServiceAPI; service.check_scrap() on ReadPostServiceAPI; service.check_is_good() on ReadPostServiceAPI; ajax_service.get_ajax_good_data() on AJAXService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /{bo_table}/writes makes calls the check could not follow, so its data access is unknown, not absent: service.validate_secret_board() on CreatePostServiceAPI; service.validate_post_content() on CreatePostServiceAPI (+9 more). It does not declare authentication.

    No rule could run on POST /{bo_table}/writes: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_secret_board() on CreatePostServiceAPI; service.validate_post_content() on CreatePostServiceAPI; service.validate_write_level() on CreatePostServiceAPI; service.arrange_data() on CreatePostServiceAPI; service.validate_write_delay_with_slowapi() on CreatePostServiceAPI; service.save_write() on CreatePostServiceAPI; service.add_point() on CreatePostServiceAPI; service.get_parent_post() on CreatePostServiceAPI; service.send_write_mail_() on CreatePostServiceAPI; service.set_notice() on CreatePostServiceAPI; service.delete_cache() on CreatePostServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePUT /{bo_table}/writes/{wr_id} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_restrict_comment_count() on UpdatePostServiceAPI; service.get_write() on UpdatePostServiceAPI (+8 more). It does not declare authentication.

    No rule could run on PUT /{bo_table}/writes/{wr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_restrict_comment_count() on UpdatePostServiceAPI; service.get_write() on UpdatePostServiceAPI; service.validate_author() on UpdatePostServiceAPI; service.validate_secret_board() on UpdatePostServiceAPI; service.validate_post_content() on UpdatePostServiceAPI; service.arrange_data() on UpdatePostServiceAPI; service.save_write() on UpdatePostServiceAPI; service.set_notice() on UpdatePostServiceAPI; service.update_children_category() on UpdatePostServiceAPI; service.delete_cache() on UpdatePostServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceDELETE /{bo_table}/writes/{wr_id} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_level() on DeletePostServiceAPI; service.validate_exists_reply() on DeletePostServiceAPI (+2 more). It does not declare authentication.

    No rule could run on DELETE /{bo_table}/writes/{wr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_level() on DeletePostServiceAPI; service.validate_exists_reply() on DeletePostServiceAPI; service.validate_exists_comment() on DeletePostServiceAPI; service.delete_write() on DeletePostServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /{bo_table}/writes/delete makes calls the check could not follow, so its data access is unknown, not absent: service.validate_admin_authority() on ListDeleteServiceAPI; service.delete_writes() on ListDeleteServiceAPI. It does not declare authentication.

    No rule could run on POST /{bo_table}/writes/delete: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_admin_authority() on ListDeleteServiceAPI; service.delete_writes() on ListDeleteServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /{bo_table}/writes/{wr_id}/delete makes calls the check could not follow, so its data access is unknown, not absent: service.validate_author() on DeletePostServiceAPI; service.validate_exists_reply() on DeletePostServiceAPI (+2 more). It does not declare authentication.

    No rule could run on POST /{bo_table}/writes/{wr_id}/delete: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_author() on DeletePostServiceAPI; service.validate_exists_reply() on DeletePostServiceAPI; service.validate_exists_comment() on DeletePostServiceAPI; service.delete_write() on DeletePostServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /{bo_table}/{sw} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_admin_authority() on MoveUpdateServiceAPI; service.get_admin_board_list() on MoveUpdateServiceAPI. It does not declare authentication.

    No rule could run on GET /{bo_table}/{sw}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_admin_authority() on MoveUpdateServiceAPI; service.get_admin_board_list() on MoveUpdateServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /{bo_table}/{sw} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_admin_authority() on MoveUpdateServiceAPI; service.get_origin_writes() on MoveUpdateServiceAPI (+1 more). It does not declare authentication.

    No rule could run on POST /{bo_table}/{sw}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_admin_authority() on MoveUpdateServiceAPI; service.get_origin_writes() on MoveUpdateServiceAPI; service.move_copy_post() on MoveUpdateServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /{bo_table}/writes/{wr_id}/files makes calls the check could not follow, so its data access is unknown, not absent: service.get_write() on CreatePostServiceAPI; service.upload_files() on CreatePostServiceAPI. It does not declare authentication.

    No rule could run on POST /{bo_table}/writes/{wr_id}/files: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.get_write() on CreatePostServiceAPI; service.upload_files() on CreatePostServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /{bo_table}/writes/{wr_id}/files/{bf_no} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_download_level() on DownloadFileServiceAPI; service.get_board_file() on DownloadFileServiceAPI (+1 more). It does not declare authentication.

    No rule could run on GET /{bo_table}/writes/{wr_id}/files/{bf_no}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_download_level() on DownloadFileServiceAPI; service.get_board_file() on DownloadFileServiceAPI; service.validate_point() on DownloadFileServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /{bo_table}/writes/{wr_id}/comments makes calls the check could not follow, so its data access is unknown, not absent: service.get_parent_post() on CommentServiceAPI; service.validate_comment_level() on CommentServiceAPI (+7 more). It does not declare authentication.

    No rule could run on POST /{bo_table}/writes/{wr_id}/comments: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.get_parent_post() on CommentServiceAPI; service.validate_comment_level() on CommentServiceAPI; service.validate_point() on CommentServiceAPI; service.validate_post_content() on CommentServiceAPI; service.validate_comment_password() on CommentServiceAPI; service.validate_write_delay_with_slowapi() on CommentServiceAPI; service.save_comment() on CommentServiceAPI; service.add_point() on CommentServiceAPI; service.send_write_mail_() on CommentServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePUT /{bo_table}/writes/{wr_id}/comments makes calls the check could not follow, so its data access is unknown, not absent: service.get_parent_post() on CommentServiceAPI; service.validate_author() on CommentServiceAPI (+2 more). It does not declare authentication.

    No rule could run on PUT /{bo_table}/writes/{wr_id}/comments: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.get_parent_post() on CommentServiceAPI; service.validate_author() on CommentServiceAPI; service.validate_post_content() on CommentServiceAPI; service.get_cleaned_data() on CommentServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceDELETE /{bo_table}/writes/{wr_id}/comments/{comment_id} makes calls the check could not follow, so its data access is unknown, not absent: service.check_authority() on DeleteCommentServiceAPI; service.delete_comment() on DeleteCommentServiceAPI. It does not declare authentication.

    No rule could run on DELETE /{bo_table}/writes/{wr_id}/comments/{comment_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.check_authority() on DeleteCommentServiceAPI; service.delete_comment() on DeleteCommentServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /{bo_table}/writes/{wr_id}/comments/{comment_id}/delete makes calls the check could not follow, so its data access is unknown, not absent: service.validate_author() on DeleteCommentServiceAPI; service.delete_comment() on DeleteCommentServiceAPI. It does not declare authentication.

    No rule could run on POST /{bo_table}/writes/{wr_id}/comments/{comment_id}/delete: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_author() on DeleteCommentServiceAPI; service.delete_comment() on DeleteCommentServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /boards/{bo_table}/writes/{wr_id}/{good_type} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_board_good_use() on AJAXService; service.validate_write_owner() on AJAXService (+1 more).

    No rule could run on POST /boards/{bo_table}/writes/{wr_id}/{good_type}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_board_good_use() on AJAXService; service.validate_write_owner() on AJAXService; service.get_ajax_good_result() on AJAXService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET / makes calls the check could not follow, so its data access is unknown, not absent: service.get_query() on BoardNewServiceAPI; service.get_offset() on BoardNewServiceAPI (+3 more). It does not declare authentication.

    No rule could run on GET /: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.get_query() on BoardNewServiceAPI; service.get_offset() on BoardNewServiceAPI; service.get_board_news() on BoardNewServiceAPI; service.get_total_count() on BoardNewServiceAPI; service.arrange_borad_news_data() on BoardNewServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /writes makes calls the check could not follow, so its data access is unknown, not absent: service.get_latest_posts() on BoardNewServiceAPI. It does not declare authentication.

    No rule could run on GET /writes: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.get_latest_posts() on BoardNewServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /writes/{bo_table} makes calls the check could not follow, so its data access is unknown, not absent: service.get_latest_posts() on BoardNewServiceAPI. It does not declare authentication.

    No rule could run on GET /writes/{bo_table}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.get_latest_posts() on BoardNewServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /delete makes calls the check could not follow, so its data access is unknown, not absent: service.delete_board_news() on BoardNewServiceAPI.

    No rule could run on POST /delete: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.delete_board_news() on BoardNewServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /contents makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_total_records() on ContentServiceAPI; service.read_contents() on ContentServiceAPI. It does not declare authentication.

    No rule could run on GET /contents: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.fetch_total_records() on ContentServiceAPI; service.read_contents() on ContentServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /members/current-connect makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_total_records() on CurrentConnectServiceAPI; service.fetch_corrent_connects() on CurrentConnectServiceAPI.

    No rule could run on GET /members/current-connect: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.fetch_total_records() on CurrentConnectServiceAPI; service.fetch_corrent_connects() on CurrentConnectServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /faqs makes calls the check could not follow, so its data access is unknown, not absent: service.read_faq_masters() on FaqServiceAPI. It does not declare authentication.

    No rule could run on GET /faqs: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.read_faq_masters() on FaqServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /faqs/{fm_id} makes calls the check could not follow, so its data access is unknown, not absent: service.read_faq_master() on FaqServiceAPI; service.read_faqs() on FaqServiceAPI. It does not declare authentication.

    No rule could run on GET /faqs/{fm_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.read_faq_master() on FaqServiceAPI; service.read_faqs() on FaqServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /{gr_id}/boards makes calls the check could not follow, so its data access is unknown, not absent: service.check_mobile_only() on GroupBoardListServiceAPI; service.get_boards_in_group() on GroupBoardListServiceAPI. It does not declare authentication.

    No rule could run on GET /{gr_id}/boards: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.check_mobile_only() on GroupBoardListServiceAPI; service.get_boards_in_group() on GroupBoardListServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /members makes calls the check could not follow, so its data access is unknown, not absent: service.create_member() on MemberServiceAPI; point_service.save_point() on PointServiceAPI. It does not declare authentication.

    No rule could run on POST /members: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.create_member() on MemberServiceAPI; point_service.save_point() on PointServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePUT /members/{mb_id}/email-certification/change makes calls the check could not follow, so its data access is unknown, not absent: member_vaildate.valid_email() on ValidateMemberAPI. It does not declare authentication.

    No rule could run on PUT /members/{mb_id}/email-certification/change: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_vaildate.valid_email() on ValidateMemberAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePUT /members/{mb_id}/email-certification makes calls the check could not follow, so its data access is unknown, not absent: member_service.read_email_non_certify_member() on MemberServiceAPI. It does not declare authentication.

    No rule could run on PUT /members/{mb_id}/email-certification: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_service.read_email_non_certify_member() on MemberServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /members/password_certification makes calls the check could not follow, so its data access is unknown, not absent: service.raise_exception() on MemberServiceAPI.

    No rule could run on POST /members/password_certification: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.raise_exception() on MemberServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /members/{mb_id} makes calls the check could not follow, so its data access is unknown, not absent: service.get_member_profile() on MemberServiceAPI.

    No rule could run on GET /members/{mb_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.get_member_profile() on MemberServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePUT /member makes calls the check could not follow, so its data access is unknown, not absent: service.update_member() on MemberServiceAPI.

    No rule could run on PUT /member: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.update_member() on MemberServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceDELETE /member makes calls the check could not follow, so its data access is unknown, not absent: service.leave_member() on MemberServiceAPI.

    No rule could run on DELETE /member: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.leave_member() on MemberServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /members/search/id makes calls the check could not follow, so its data access is unknown, not absent: service.find_id() on MemberServiceAPI. It does not declare authentication.

    No rule could run on POST /members/search/id: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.find_id() on MemberServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /members/search/password makes calls the check could not follow, so its data access is unknown, not absent: member_service.find_member_from_password_info() on MemberServiceAPI. It does not declare authentication.

    No rule could run on POST /members/search/password: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_service.find_member_from_password_info() on MemberServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePATCH /members/{mb_id}/password/{token} makes calls the check could not follow, so its data access is unknown, not absent: member_service.reset_password() on MemberServiceAPI. It does not declare authentication.

    No rule could run on PATCH /members/{mb_id}/password/{token}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_service.reset_password() on MemberServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /memos makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_total_records() on MemoServiceAPI; service.fetch_memos() on MemoServiceAPI.

    No rule could run on GET /memos: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.fetch_total_records() on MemoServiceAPI; service.fetch_memos() on MemoServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /memos/{me_id} makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_prev_next_qa() on MemoServiceAPI.

    No rule could run on GET /memos/{me_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.fetch_prev_next_qa() on MemoServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePATCH /memos/{me_id}/read makes calls the check could not follow, so its data access is unknown, not absent: service.update_read_datetime() on MemoServiceAPI; service.update_not_read_memos() on MemoServiceAPI.

    No rule could run on PATCH /memos/{me_id}/read: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.update_read_datetime() on MemoServiceAPI; service.update_not_read_memos() on MemoServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /memos makes calls the check could not follow, so its data access is unknown, not absent: service.send_memo() on MemoServiceAPI; service.update_memo_call() on MemoServiceAPI (+2 more).

    No rule could run on POST /memos: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.send_memo() on MemoServiceAPI; service.update_memo_call() on MemoServiceAPI; point_service.get_config_point() on PointServiceAPI; point_service.save_point() on PointServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceDELETE /memos/{me_id} makes calls the check could not follow, so its data access is unknown, not absent: memo_service.delete_memo_call() on MemoServiceAPI; memo_service.delete_memo() on MemoServiceAPI (+1 more).

    No rule could run on DELETE /memos/{me_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: memo_service.delete_memo_call() on MemoServiceAPI; memo_service.delete_memo() on MemoServiceAPI; memo_service.update_not_read_memos() on MemoServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /menus makes calls the check could not follow, so its data access is unknown, not absent: menu_service.fetch_menus() on MenuService. It does not declare authentication.

    No rule could run on GET /menus: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: menu_service.fetch_menus() on MenuService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /newwins makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_newwins() on NewwinServiceAPI. It does not declare authentication.

    No rule could run on GET /newwins: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.fetch_newwins() on NewwinServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /points makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_total_records() on PointServiceAPI; service.fetch_points() on PointServiceAPI (+1 more).

    No rule could run on GET /points: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.fetch_total_records() on PointServiceAPI; service.fetch_points() on PointServiceAPI; service.calculate_sum() on PointServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /polls/latest makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_latest_poll() on PollServiceAPI. It does not declare authentication.

    No rule could run on GET /polls/latest: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.fetch_latest_poll() on PollServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /polls/{po_id} makes calls the check could not follow, so its data access is unknown, not absent: service.calculate_poll_result() on PollServiceAPI; service.fetch_other_polls() on PollServiceAPI. It does not declare authentication.

    No rule could run on GET /polls/{po_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.calculate_poll_result() on PollServiceAPI; service.fetch_other_polls() on PollServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePATCH /polls/{po_id}/{item} makes calls the check could not follow, so its data access is unknown, not absent: service.update_poll() on PollServiceAPI; point_service.save_point() on PointServiceAPI.

    No rule could run on PATCH /polls/{po_id}/{item}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.update_poll() on PollServiceAPI; point_service.save_point() on PointServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /polls/{po_id}/etc makes calls the check could not follow, so its data access is unknown, not absent: service.create_poll_etc() on PollServiceAPI.

    No rule could run on POST /polls/{po_id}/etc: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.create_poll_etc() on PollServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceDELETE /polls/{po_id}/etc/{pc_id} makes calls the check could not follow, so its data access is unknown, not absent: poll_service.delete_poll_etc() on PollServiceAPI. It does not declare authentication.

    No rule could run on DELETE /polls/{po_id}/etc/{pc_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: poll_service.delete_poll_etc() on PollServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /populars makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_populars() on PopularService. It does not declare authentication.

    No rule could run on GET /populars: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.fetch_populars() on PopularService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /populars makes calls the check could not follow, so its data access is unknown, not absent: service.create_popular() on PopularServiceAPI. It does not declare authentication.

    No rule could run on POST /populars: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.create_popular() on PopularServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /qas makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_total_records() on QaServiceAPI; service.read_qa_contents() on QaServiceAPI.

    No rule could run on GET /qas: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.fetch_total_records() on QaServiceAPI; service.read_qa_contents() on QaServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /qas/{qa_id} makes calls the check could not follow, so its data access is unknown, not absent: service.read_qa_answer() on QaServiceAPI; service.fetch_prev_next_qa() on QaServiceAPI (+1 more).

    No rule could run on GET /qas/{qa_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.read_qa_answer() on QaServiceAPI; service.fetch_prev_next_qa() on QaServiceAPI; service.fetch_related_qa_contents() on QaServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /qas makes calls the check could not follow, so its data access is unknown, not absent: service.create_qa_content() on QaServiceAPI.

    No rule could run on POST /qas: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.create_qa_content() on QaServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePUT /qas/{qa_id} makes calls the check could not follow, so its data access is unknown, not absent: service.update_qa_content() on QaServiceAPI. It does not declare authentication.

    No rule could run on PUT /qas/{qa_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.update_qa_content() on QaServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePUT /qas/{qa_id}/files makes calls the check could not follow, so its data access is unknown, not absent: service.upload_qa_file() on QaFileServiceAPI. It does not declare authentication.

    No rule could run on PUT /qas/{qa_id}/files: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.upload_qa_file() on QaFileServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceDELETE /qas/{qa_id} makes calls the check could not follow, so its data access is unknown, not absent: service.delete_qa_content() on QaServiceAPI. It does not declare authentication.

    No rule could run on DELETE /qas/{qa_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.delete_qa_content() on QaServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /scraps makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_total_records() on ScrapServiceAPI; service.fetch_scraps() on ScrapServiceAPI (+1 more).

    No rule could run on GET /scraps: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.fetch_total_records() on ScrapServiceAPI; service.fetch_scraps() on ScrapServiceAPI; service.set_subjects() on ScrapServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /scraps/{bo_table}/{wr_id} makes calls the check could not follow, so its data access is unknown, not absent: service.create_scrap() on ScrapServiceAPI; service.update_scrap_count() on ScrapServiceAPI (+8 more).

    No rule could run on POST /scraps/{bo_table}/{wr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.create_scrap() on ScrapServiceAPI; service.update_scrap_count() on ScrapServiceAPI; comment_service.validate_write_delay() on CommentServiceAPI; comment_service.validate_comment_level() on CommentServiceAPI; comment_service.validate_point() on CommentServiceAPI; comment_service.validate_post_content() on CommentServiceAPI; comment_service.validate_comment_password() on CommentServiceAPI; comment_service.save_comment() on CommentServiceAPI; comment_service.add_point() on CommentServiceAPI; comment_service.send_write_mail_() on CommentServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceDELETE /scraps/{ms_id} makes calls the check could not follow, so its data access is unknown, not absent: service.delete_scrap() on ScrapServiceAPI; service.update_scrap_count() on ScrapServiceAPI.

    No rule could run on DELETE /scraps/{ms_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.delete_scrap() on ScrapServiceAPI; service.update_scrap_count() on ScrapServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /search makes calls the check could not follow, so its data access is unknown, not absent: service.get_boards() on SearchServiceAPI; service.search() on SearchServiceAPI. It does not declare authentication.

    No rule could run on GET /search: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.get_boards() on SearchServiceAPI; service.search() on SearchServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /visit makes calls the check could not follow, so its data access is unknown, not absent: service.create_visit_record() on VisitServiceAPI. It does not declare authentication.

    No rule could run on POST /visit: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.create_visit_record() on VisitServiceAPI.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/ajax/autosave_list makes calls the check could not follow, so its data access is unknown, not absent: service.validate_login() on AJAXService; service.get_autosave_list() on AJAXService.

    No rule could run on GET /bbs/ajax/autosave_list: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_login() on AJAXService; service.get_autosave_list() on AJAXService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/ajax/autosave_count makes calls the check could not follow, so its data access is unknown, not absent: service.validate_login() on AJAXService; service.get_autosave_count() on AJAXService.

    No rule could run on GET /bbs/ajax/autosave_count: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_login() on AJAXService; service.get_autosave_count() on AJAXService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/ajax/autosave_load/{as_id} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_login() on AJAXService; service.get_autosave_content() on AJAXService.

    No rule could run on GET /bbs/ajax/autosave_load/{as_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_login() on AJAXService; service.get_autosave_content() on AJAXService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /bbs/ajax/autosave makes calls the check could not follow, so its data access is unknown, not absent: service.validate_login() on AJAXService; service.autosave_save() on AJAXService (+1 more).

    No rule could run on POST /bbs/ajax/autosave: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_login() on AJAXService; service.autosave_save() on AJAXService; service.get_autosave_count() on AJAXService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceDELETE /bbs/ajax/autosave/{as_id} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_login() on AJAXService; service.autosave_delete() on AJAXService.

    No rule could run on DELETE /bbs/ajax/autosave/{as_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_login() on AJAXService; service.autosave_delete() on AJAXService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /bbs/ajax/good/{bo_table}/{wr_id}/{type} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_member() on AJAXService; service.validate_token() on AJAXService (+5 more).

    No rule could run on POST /bbs/ajax/good/{bo_table}/{wr_id}/{type}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_member() on AJAXService; service.validate_token() on AJAXService; service.get_board() on AJAXService; service.validate_board_good_use() on AJAXService; service.get_write() on AJAXService; service.validate_write_owner() on AJAXService; service.get_ajax_good_result() on AJAXService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /board/group/{gr_id} makes calls the check could not follow, so its data access is unknown, not absent: service.check_mobile_only() on GroupBoardListService; service.get_boards_in_group() on GroupBoardListService.

    No rule could run on GET /board/group/{gr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.check_mobile_only() on GroupBoardListService; service.get_boards_in_group() on GroupBoardListService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /board/{bo_table} makes calls the check could not follow, so its data access is unknown, not absent: list_post_service.get_total_count() on ListPostService; list_post_service.get_notice_writes() on ListPostService (+3 more).

    No rule could run on GET /board/{bo_table}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: list_post_service.get_total_count() on ListPostService; list_post_service.get_notice_writes() on ListPostService; list_post_service.get_writes() on ListPostService; list_post_service.is_write_level() on ListPostService; popular_service.create_popular() on PopularService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /board/list_delete/{bo_table} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_admin_authority() on ListDeleteService; service.delete_writes() on ListDeleteService.

    No rule could run on POST /board/list_delete/{bo_table}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_admin_authority() on ListDeleteService; service.delete_writes() on ListDeleteService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /board/move/{bo_table} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_admin_authority() on MoveUpdateService; service.get_admin_board_list() on MoveUpdateService.

    No rule could run on POST /board/move/{bo_table}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_admin_authority() on MoveUpdateService; service.get_admin_board_list() on MoveUpdateService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /board/move_update makes calls the check could not follow, so its data access is unknown, not absent: service.validate_admin_authority() on MoveUpdateService; service.get_origin_writes() on MoveUpdateService (+1 more).

    No rule could run on POST /board/move_update: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_admin_authority() on MoveUpdateService; service.get_origin_writes() on MoveUpdateService; service.move_copy_post() on MoveUpdateService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /board/write/{bo_table} makes calls the check could not follow, so its data access is unknown, not absent: service.get_parent_post() on CreatePostService; service.validate_write_level() on CreatePostService (+5 more).

    No rule could run on GET /board/write/{bo_table}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.get_parent_post() on CreatePostService; service.validate_write_level() on CreatePostService; service.get_category_list() on CreatePostService; service.is_html_level() on CreatePostService; service.is_link_level() on CreatePostService; service.is_upload_level() on CreatePostService; file_service.get_board_files_by_form() on BoardFileService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /board/write/{bo_table}/{wr_id} makes calls the check could not follow, so its data access is unknown, not absent: service.get_write() on UpdatePostService; service.validate_write_level() on UpdatePostService (+7 more).

    No rule could run on GET /board/write/{bo_table}/{wr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.get_write() on UpdatePostService; service.validate_write_level() on UpdatePostService; service.validate_restrict_comment_count() on UpdatePostService; service.get_category_list() on UpdatePostService; service.is_board_notice() on UpdatePostService; service.is_html_level() on UpdatePostService; service.is_link_level() on UpdatePostService; service.is_upload_level() on UpdatePostService; file_service.get_board_files_by_form() on BoardFileService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /board/write_update/{bo_table} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_captcha() on CreatePostService; service.validate_write_delay() on CreatePostService (+15 more).

    No rule could run on POST /board/write_update/{bo_table}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_captcha() on CreatePostService; service.validate_write_delay() on CreatePostService; service.validate_write_level() on CreatePostService; service.validate_secret_board() on CreatePostService; service.validate_post_content() on CreatePostService; service.is_write_level() on CreatePostService; service.arrange_data() on CreatePostService; service.save_write() on CreatePostService; service.add_point() on CreatePostService; service.get_parent_post() on CreatePostService; service.send_write_mail_() on CreatePostService; service.set_notice() on CreatePostService; service.delete_auto_save() on CreatePostService; service.save_secret_session() on CreatePostService; service.upload_files() on CreatePostService; service.delete_cache() on CreatePostService; service.get_redirect_url() on CreatePostService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /board/write_update/{bo_table}/{wr_id} makes calls the check could not follow, so its data access is unknown, not absent: service.get_write() on UpdatePostService; service.validate_author() on UpdatePostService (+12 more).

    No rule could run on POST /board/write_update/{bo_table}/{wr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.get_write() on UpdatePostService; service.validate_author() on UpdatePostService; service.validate_restrict_comment_count() on UpdatePostService; service.validate_secret_board() on UpdatePostService; service.validate_post_content() on UpdatePostService; service.arrange_data() on UpdatePostService; service.save_secret_session() on UpdatePostService; service.save_write() on UpdatePostService; service.set_notice() on UpdatePostService; service.delete_auto_save() on UpdatePostService; service.upload_files() on UpdatePostService; service.update_children_category() on UpdatePostService; service.delete_cache() on UpdatePostService; service.get_redirect_url() on UpdatePostService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /board/{bo_table}/{wr_id} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_secret_with_session() on ReadPostService; service.validate_repeat_with_session() on ReadPostService (+10 more).

    No rule could run on GET /board/{bo_table}/{wr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_secret_with_session() on ReadPostService; service.validate_repeat_with_session() on ReadPostService; service.block_read_comment() on ReadPostService; service.validate_read_level() on ReadPostService; service.check_scrap() on ReadPostService; service.check_is_good() on ReadPostService; service.get_prev_next() on ReadPostService; service.get_links() on ReadPostService; service.get_comments() on ReadPostService; service.is_write_level() on ReadPostService; service.is_reply_level() on ReadPostService; service.is_comment_level() on ReadPostService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /board/delete/{bo_table}/{wr_id} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_level() on DeletePostService; service.validate_exists_reply() on DeletePostService (+2 more).

    No rule could run on GET /board/delete/{bo_table}/{wr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_level() on DeletePostService; service.validate_exists_reply() on DeletePostService; service.validate_exists_comment() on DeletePostService; service.delete_write() on DeletePostService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /board/{bo_table}/{wr_id}/download/{bf_no} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_download_level() on DownloadFileService; service.get_board_file() on DownloadFileService (+1 more).

    No rule could run on GET /board/{bo_table}/{wr_id}/download/{bf_no}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.validate_download_level() on DownloadFileService; service.get_board_file() on DownloadFileService; service.validate_point_session() on DownloadFileService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /board/delete_comment/{bo_table}/{comment_id} makes calls the check could not follow, so its data access is unknown, not absent: service.get_comment() on DeleteCommentService; service.check_authority() on DeleteCommentService (+1 more).

    No rule could run on GET /board/delete_comment/{bo_table}/{comment_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.get_comment() on DeleteCommentService; service.check_authority() on DeleteCommentService; service.delete_comment() on DeleteCommentService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/new makes calls the check could not follow, so its data access is unknown, not absent: service.get_query() on BoardNewService; service.get_offset() on BoardNewService (+3 more).

    No rule could run on GET /bbs/new: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.get_query() on BoardNewService; service.get_offset() on BoardNewService; service.get_board_news() on BoardNewService; service.get_total_count() on BoardNewService; service.arrange_borad_news_data() on BoardNewService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /bbs/new_delete makes calls the check could not follow, so its data access is unknown, not absent: service.delete_board_news() on BoardNewService.

    No rule could run on POST /bbs/new_delete: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.delete_board_news() on BoardNewService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/content/{co_id} makes calls the check could not follow, so its data access is unknown, not absent: content_service.read_content() on ContentService.

    No rule could run on GET /bbs/content/{co_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: content_service.read_content() on ContentService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/current_connect makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_corrent_connects() on CurrentConnectService.

    No rule could run on GET /bbs/current_connect: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.fetch_corrent_connects() on CurrentConnectService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/faq makes calls the check could not follow, so its data access is unknown, not absent: faq_service.read_faq_masters() on FaqService; faq_service.read_faq_master() on FaqService (+1 more).

    No rule could run on GET /bbs/faq: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: faq_service.read_faq_masters() on FaqService; faq_service.read_faq_master() on FaqService; faq_service.read_faqs() on FaqService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/faq/{fm_id} makes calls the check could not follow, so its data access is unknown, not absent: faq_service.read_faq_masters() on FaqService; faq_service.read_faq_master() on FaqService (+1 more).

    No rule could run on GET /bbs/faq/{fm_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: faq_service.read_faq_masters() on FaqService; faq_service.read_faq_master() on FaqService; faq_service.read_faqs() on FaqService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /bbs/login makes calls the check could not follow, so its data access is unknown, not absent: member_service.authenticate_member() on MemberService.

    No rule could run on POST /bbs/login: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_service.authenticate_member() on MemberService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /bbs/id_lost makes calls the check could not follow, so its data access is unknown, not absent: member_service.find_id() on MemberService.

    No rule could run on POST /bbs/id_lost: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_service.find_id() on MemberService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /bbs/password_lost makes calls the check could not follow, so its data access is unknown, not absent: member_service.find_member_from_password_info() on MemberService.

    No rule could run on POST /bbs/password_lost: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_service.find_member_from_password_info() on MemberService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/password_reset/{mb_id}/{token} makes calls the check could not follow, so its data access is unknown, not absent: member_service.read_member_by_lost_certify() on MemberService.

    No rule could run on GET /bbs/password_reset/{mb_id}/{token}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_service.read_member_by_lost_certify() on MemberService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /bbs/password_reset/{mb_id}/{token} makes calls the check could not follow, so its data access is unknown, not absent: member_service.reset_password() on MemberService.

    No rule could run on POST /bbs/password_reset/{mb_id}/{token}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_service.reset_password() on MemberService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /bbs/member_leave makes calls the check could not follow, so its data access is unknown, not absent: member_service.read_member() on MemberService; member_service.leave_member() on MemberService.

    No rule could run on POST /bbs/member_leave: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_service.read_member() on MemberService; member_service.leave_member() on MemberService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/member_profile makes calls the check could not follow, so its data access is unknown, not absent: member_service.read_member() on MemberService; validate.is_open_change_date() on ValidateMember.

    No rule could run on GET /bbs/member_profile: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_service.read_member() on MemberService; validate.is_open_change_date() on ValidateMember.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /bbs/member_profile makes calls the check could not follow, so its data access is unknown, not absent: member_service.read_member() on MemberService; member_service.update_member() on MemberService (+1 more).

    No rule could run on POST /bbs/member_profile: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_service.read_member() on MemberService; member_service.update_member() on MemberService; file_service.update_image_file() on MemberImageService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/memo makes calls the check could not follow, so its data access is unknown, not absent: memo_service.fetch_total_records() on MemoService; memo_service.fetch_memos() on MemoService.

    No rule could run on GET /bbs/memo: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: memo_service.fetch_total_records() on MemoService; memo_service.fetch_memos() on MemoService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/memo_view/{me_id} makes calls the check could not follow, so its data access is unknown, not absent: member_service.fetch_member_by_id() on MemberService; memo_service.fetch_prev_next_qa() on MemoService (+2 more).

    No rule could run on GET /bbs/memo_view/{me_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_service.fetch_member_by_id() on MemberService; memo_service.fetch_prev_next_qa() on MemoService; memo_service.update_read_datetime() on MemoService; memo_service.update_not_read_memos() on MemoService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/memo_form makes calls the check could not follow, so its data access is unknown, not absent: member_service.read_member() on MemberService; member_service.fetch_member_by_id() on MemberService (+1 more).

    No rule could run on GET /bbs/memo_form: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_service.read_member() on MemberService; member_service.fetch_member_by_id() on MemberService; memo_service.fetch_memo() on MemoService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /bbs/memo_form_update makes calls the check could not follow, so its data access is unknown, not absent: memo_service.get_receive_members() on MemoService; memo_service.calculate_send_point() on MemoService (+4 more).

    No rule could run on POST /bbs/memo_form_update: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: memo_service.get_receive_members() on MemoService; memo_service.calculate_send_point() on MemoService; memo_service.send_memo() on MemoService; memo_service.update_memo_call() on MemoService; point_service.get_config_point() on PointService; point_service.save_point() on PointService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/memo_delete/{me_id} makes calls the check could not follow, so its data access is unknown, not absent: service.delete_memo_call() on MemoService; service.delete_memo() on MemoService (+1 more).

    No rule could run on GET /bbs/memo_delete/{me_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.delete_memo_call() on MemoService; service.delete_memo() on MemoService; service.update_not_read_memos() on MemoService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/point makes calls the check could not follow, so its data access is unknown, not absent: point_service.fetch_total_records() on PointService; point_service.fetch_points() on PointService (+1 more).

    No rule could run on GET /bbs/point: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: point_service.fetch_total_records() on PointService; point_service.fetch_points() on PointService; point_service.calculate_sum() on PointService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /bbs/poll_update/{po_id} makes calls the check could not follow, so its data access is unknown, not absent: service.update_poll() on PollService; point_service.save_point() on PointService.

    No rule could run on POST /bbs/poll_update/{po_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.update_poll() on PollService; point_service.save_point() on PointService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/poll_result/{po_id} makes calls the check could not follow, so its data access is unknown, not absent: service.calculate_poll_result() on PollService; service.fetch_other_polls() on PollService.

    No rule could run on GET /bbs/poll_result/{po_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.calculate_poll_result() on PollService; service.fetch_other_polls() on PollService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /bbs/poll/{po_id}/etc_update makes calls the check could not follow, so its data access is unknown, not absent: service.create_poll_etc() on PollService.

    No rule could run on POST /bbs/poll/{po_id}/etc_update: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.create_poll_etc() on PollService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/poll/{po_id}/etc_delete/{pc_id} makes calls the check could not follow, so its data access is unknown, not absent: service.delete_poll_etc() on PollService.

    No rule could run on GET /bbs/poll/{po_id}/etc_delete/{pc_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: service.delete_poll_etc() on PollService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/profile/{mb_id} makes calls the check could not follow, so its data access is unknown, not absent: member_service.get_member_profile() on MemberService.

    No rule could run on GET /bbs/profile/{mb_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_service.get_member_profile() on MemberService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/qalist makes calls the check could not follow, so its data access is unknown, not absent: config_service.get_qa_config() on QaConfigService; config_service.get_category_list() on QaConfigService (+2 more).

    No rule could run on GET /bbs/qalist: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: config_service.get_qa_config() on QaConfigService; config_service.get_category_list() on QaConfigService; qa_service.fetch_total_records() on QaService; qa_service.read_qa_contents() on QaService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/qawrite makes calls the check could not follow, so its data access is unknown, not absent: config_service.get_category_list() on QaConfigService; qa_service.init_qa_content() on QaService.

    No rule could run on GET /bbs/qawrite: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: config_service.get_category_list() on QaConfigService; qa_service.init_qa_content() on QaService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/qawrite/{qa_id} makes calls the check could not follow, so its data access is unknown, not absent: config_service.get_category_list() on QaConfigService.

    No rule could run on GET /bbs/qawrite/{qa_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: config_service.get_category_list() on QaConfigService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /bbs/qawrite_update makes calls the check could not follow, so its data access is unknown, not absent: qa_service.read_qa_content() on QaService; qa_service.update_qa_content() on QaService (+2 more).

    No rule could run on POST /bbs/qawrite_update: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: qa_service.read_qa_content() on QaService; qa_service.update_qa_content() on QaService; qa_service.create_qa_content() on QaService; file_service.upload_qa_file() on QaFileService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/qadelete/{qa_id} makes calls the check could not follow, so its data access is unknown, not absent: qa_service.delete_qa_content() on QaService.

    No rule could run on GET /bbs/qadelete/{qa_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: qa_service.delete_qa_content() on QaService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /bbs/qadelete/list makes calls the check could not follow, so its data access is unknown, not absent: qa_service.delete_qa_contents() on QaService.

    No rule could run on POST /bbs/qadelete/list: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: qa_service.delete_qa_contents() on QaService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/qaview/{qa_id} makes calls the check could not follow, so its data access is unknown, not absent: config_service.get_qa_config() on QaConfigService; qa_service.read_qa_answer() on QaService (+2 more).

    No rule could run on GET /bbs/qaview/{qa_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: config_service.get_qa_config() on QaConfigService; qa_service.read_qa_answer() on QaService; qa_service.fetch_prev_next_qa() on QaService; qa_service.fetch_related_qa_contents() on QaService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /bbs/register_form makes calls the check could not follow, so its data access is unknown, not absent: member_service.create_member() on MemberService; file_service.update_image_file() on MemberImageService (+1 more).

    No rule could run on POST /bbs/register_form: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_service.create_member() on MemberService; file_service.update_image_file() on MemberImageService; point_service.save_point() on PointService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/register_result makes calls the check could not follow, so its data access is unknown, not absent: member_service.fetch_member_by_id() on MemberService.

    No rule could run on GET /bbs/register_result: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_service.fetch_member_by_id() on MemberService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /bbs/email_certify/update/{mb_id}/{key} makes calls the check could not follow, so its data access is unknown, not absent: member_vaildate.valid_email() on ValidateMember.

    No rule could run on POST /bbs/email_certify/update/{mb_id}/{key}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_vaildate.valid_email() on ValidateMember.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/email_certify/{mb_id} makes calls the check could not follow, so its data access is unknown, not absent: member_service.read_email_non_certify_member() on MemberService.

    No rule could run on GET /bbs/email_certify/{mb_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_service.read_email_non_certify_member() on MemberService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/register/validate/{field} makes calls the check could not follow, so its data access is unknown, not absent: validate.valid_id() on ValidateMemberAjax; validate.valid_name() on ValidateMemberAjax (+3 more).

    No rule could run on GET /bbs/register/validate/{field}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: validate.valid_id() on ValidateMemberAjax; validate.valid_name() on ValidateMemberAjax; validate.valid_nickname() on ValidateMemberAjax; validate.valid_email() on ValidateMemberAjax; validate.valid_recommend() on ValidateMemberAjax.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /bbs/scrap_popin_update/{bo_table}/{wr_id} makes calls the check could not follow, so its data access is unknown, not absent: scrap_service.create_scrap() on ScrapService; scrap_service.update_scrap_count() on ScrapService.

    No rule could run on POST /bbs/scrap_popin_update/{bo_table}/{wr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: scrap_service.create_scrap() on ScrapService; scrap_service.update_scrap_count() on ScrapService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/scrap makes calls the check could not follow, so its data access is unknown, not absent: scrap_service.fetch_total_records() on ScrapService; scrap_service.fetch_scraps() on ScrapService (+1 more).

    No rule could run on GET /bbs/scrap: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: scrap_service.fetch_total_records() on ScrapService; scrap_service.fetch_scraps() on ScrapService; scrap_service.set_subjects() on ScrapService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/scrap_delete/{ms_id} makes calls the check could not follow, so its data access is unknown, not absent: scrap_service.delete_scrap() on ScrapService; scrap_service.update_scrap_count() on ScrapService.

    No rule could run on GET /bbs/scrap_delete/{ms_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: scrap_service.delete_scrap() on ScrapService; scrap_service.update_scrap_count() on ScrapService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/search makes calls the check could not follow, so its data access is unknown, not absent: search_service.get_groups() on SearchService; search_service.get_boards() on SearchService (+2 more).

    No rule could run on GET /bbs/search: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: search_service.get_groups() on SearchService; search_service.get_boards() on SearchService; search_service.search() on SearchService; popular_service.create_popular() on PopularService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/social/login/callback makes calls the check could not follow, so its data access is unknown, not absent: member_service.get_member() on MemberService.

    No rule could run on GET /bbs/social/login/callback: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: member_service.get_member() on MemberService.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidenceGET /bbs/social/register makes calls the check could not follow, so its data access is unknown, not absent: validate.is_exists_email() on ValidateMember.

    No rule could run on GET /bbs/social/register: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: validate.is_exists_email() on ValidateMember.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumhigh confidencePOST /bbs/social/register makes calls the check could not follow, so its data access is unknown, not absent: point_service.save_point() on PointService; validate.valid_id() on ValidateMember (+2 more).

    No rule could run on POST /bbs/social/register: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.

    Missing
    Evidence of what it touches. Could not follow: point_service.save_point() on PointService; validate.valid_id() on ValidateMember; validate.valid_email() on ValidateMember; validate.valid_nickname() on ValidateMember.
    Confidence
    The check is certain it could not follow these calls; it is not claiming the route is wrong.

    Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.

    unresolved-data-reach

  • Mediumlow confidencePOST /{bo_table}/writes/{wr_id} has no validator or rate limiter attached.

    POST /{bo_table}/writes/{wr_id} accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.

    Missing
    Schema validation of the request body, and a rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Prove it

    curl -i -X POST 'https://YOUR_API/1/writes/1' \
      -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}'
    # Expect 422. A 2xx or 500 means the body is not validated.

    Fix

    class Body(BaseModel):
        name: constr(max_length=200)
    
    @app.post("/{bo_table}/writes/{wr_id}")
    def handler(body: Body): ...

    Regression test

    def test_post_rejects_unexpected_body(client):
        res = client.post("/1/writes/1", json={"unexpected": True})
        assert res.status_code == 422

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceDELETE /{bo_table}/writes/{wr_id} has no validator or rate limiter attached.

    DELETE /{bo_table}/writes/{wr_id} accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.

    Missing
    Schema validation of the request body, and a rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Prove it

    curl -i -X DELETE 'https://YOUR_API/1/writes/1' \
      -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}'
    # Expect 422. A 2xx or 500 means the body is not validated.

    Fix

    class Body(BaseModel):
        name: constr(max_length=200)
    
    @app.delete("/{bo_table}/writes/{wr_id}")
    def handler(body: Body): ...

    Regression test

    def test_delete_rejects_unexpected_body(client):
        res = client.delete("/1/writes/1", json={"unexpected": True})
        assert res.status_code == 422

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidencePOST /{bo_table}/writes/delete has no validator or rate limiter attached.

    POST /{bo_table}/writes/delete accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.

    Missing
    Schema validation of the request body, and a rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Prove it

    curl -i -X POST 'https://YOUR_API/1/writes/delete' \
      -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}'
    # Expect 422. A 2xx or 500 means the body is not validated.

    Fix

    class Body(BaseModel):
        name: constr(max_length=200)
    
    @app.post("/{bo_table}/writes/delete")
    def handler(body: Body): ...

    Regression test

    def test_post_rejects_unexpected_body(client):
        res = client.post("/1/writes/delete", json={"unexpected": True})
        assert res.status_code == 422

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidencePOST /{bo_table}/writes/{wr_id}/delete has no validator or rate limiter attached.

    POST /{bo_table}/writes/{wr_id}/delete accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.

    Missing
    Schema validation of the request body, and a rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Prove it

    curl -i -X POST 'https://YOUR_API/1/writes/1/delete' \
      -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}'
    # Expect 422. A 2xx or 500 means the body is not validated.

    Fix

    class Body(BaseModel):
        name: constr(max_length=200)
    
    @app.post("/{bo_table}/writes/{wr_id}/delete")
    def handler(body: Body): ...

    Regression test

    def test_post_rejects_unexpected_body(client):
        res = client.post("/1/writes/1/delete", json={"unexpected": True})
        assert res.status_code == 422

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidencePOST /{bo_table}/{sw} has no validator or rate limiter attached.

    POST /{bo_table}/{sw} accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.

    Missing
    Schema validation of the request body, and a rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Prove it

    curl -i -X POST 'https://YOUR_API/1/1' \
      -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}'
    # Expect 422. A 2xx or 500 means the body is not validated.

    Fix

    class Body(BaseModel):
        name: constr(max_length=200)
    
    @app.post("/{bo_table}/{sw}")
    def handler(body: Body): ...

    Regression test

    def test_post_rejects_unexpected_body(client):
        res = client.post("/1/1", json={"unexpected": True})
        assert res.status_code == 422

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidencePOST /{bo_table}/writes/{wr_id}/files has no validator or rate limiter attached.

    POST /{bo_table}/writes/{wr_id}/files accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.

    Missing
    Schema validation of the request body, and a rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Prove it

    curl -i -X POST 'https://YOUR_API/1/writes/1/files' \
      -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}'
    # Expect 422. A 2xx or 500 means the body is not validated.

    Fix

    class Body(BaseModel):
        name: constr(max_length=200)
    
    @app.post("/{bo_table}/writes/{wr_id}/files")
    def handler(body: Body): ...

    Regression test

    def test_post_rejects_unexpected_body(client):
        res = client.post("/1/writes/1/files", json={"unexpected": True})
        assert res.status_code == 422

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceDELETE /{bo_table}/writes/{wr_id}/comments/{comment_id} has no validator or rate limiter attached.

    DELETE /{bo_table}/writes/{wr_id}/comments/{comment_id} accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.

    Missing
    Schema validation of the request body, and a rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Prove it

    curl -i -X DELETE 'https://YOUR_API/1/writes/1/comments/1' \
      -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}'
    # Expect 422. A 2xx or 500 means the body is not validated.

    Fix

    class Body(BaseModel):
        name: constr(max_length=200)
    
    @app.delete("/{bo_table}/writes/{wr_id}/comments/{comment_id}")
    def handler(body: Body): ...

    Regression test

    def test_delete_rejects_unexpected_body(client):
        res = client.delete("/1/writes/1/comments/1", json={"unexpected": True})
        assert res.status_code == 422

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidencePOST /{bo_table}/writes/{wr_id}/comments/{comment_id}/delete has no validator or rate limiter attached.

    POST /{bo_table}/writes/{wr_id}/comments/{comment_id}/delete accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.

    Missing
    Schema validation of the request body, and a rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Prove it

    curl -i -X POST 'https://YOUR_API/1/writes/1/comments/1/delete' \
      -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}'
    # Expect 422. A 2xx or 500 means the body is not validated.

    Fix

    class Body(BaseModel):
        name: constr(max_length=200)
    
    @app.post("/{bo_table}/writes/{wr_id}/comments/{comment_id}/delete")
    def handler(body: Body): ...

    Regression test

    def test_post_rejects_unexpected_body(client):
        res = client.post("/1/writes/1/comments/1/delete", json={"unexpected": True})
        assert res.status_code == 422

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidencePOST /captcha/recaptcha/verify has no validator or rate limiter attached.

    POST /captcha/recaptcha/verify accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.

    Missing
    Schema validation of the request body, and a rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Prove it

    curl -i -X POST 'https://YOUR_API/captcha/recaptcha/verify' \
      -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}'
    # Expect 422. A 2xx or 500 means the body is not validated.

    Fix

    class Body(BaseModel):
        name: constr(max_length=200)
    
    @app.post("/captcha/recaptcha/verify")
    def handler(body: Body): ...

    Regression test

    def test_post_rejects_unexpected_body(client):
        res = client.post("/captcha/recaptcha/verify", json={"unexpected": True})
        assert res.status_code == 422

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidencePOST /members has no validator or rate limiter attached.

    POST /members accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.

    Missing
    Schema validation of the request body, and a rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Prove it

    curl -i -X POST 'https://YOUR_API/members' \
      -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}'
    # Expect 422. A 2xx or 500 means the body is not validated.

    Fix

    class Body(BaseModel):
        name: constr(max_length=200)
    
    @app.post("/members")
    def handler(body: Body): ...

    Regression test

    def test_post_rejects_unexpected_body(client):
        res = client.post("/members", json={"unexpected": True})
        assert res.status_code == 422

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidencePUT /members/{mb_id}/email-certification/change has no validator or rate limiter attached.

    PUT /members/{mb_id}/email-certification/change accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.

    Missing
    Schema validation of the request body, and a rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Prove it

    curl -i -X PUT 'https://YOUR_API/members/1/email-certification/change' \
      -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}'
    # Expect 422. A 2xx or 500 means the body is not validated.

    Fix

    class Body(BaseModel):
        name: constr(max_length=200)
    
    @app.put("/members/{mb_id}/email-certification/change")
    def handler(body: Body): ...

    Regression test

    def test_put_rejects_unexpected_body(client):
        res = client.put("/members/1/email-certification/change", json={"unexpected": True})
        assert res.status_code == 422

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidencePUT /members/{mb_id}/email-certification has no validator or rate limiter attached.

    PUT /members/{mb_id}/email-certification accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.

    Missing
    Schema validation of the request body, and a rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Prove it

    curl -i -X PUT 'https://YOUR_API/members/1/email-certification' \
      -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}'
    # Expect 422. A 2xx or 500 means the body is not validated.

    Fix

    class Body(BaseModel):
        name: constr(max_length=200)
    
    @app.put("/members/{mb_id}/email-certification")
    def handler(body: Body): ...

    Regression test

    def test_put_rejects_unexpected_body(client):
        res = client.put("/members/1/email-certification", json={"unexpected": True})
        assert res.status_code == 422

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceDELETE /polls/{po_id}/etc/{pc_id} has no validator or rate limiter attached.

    DELETE /polls/{po_id}/etc/{pc_id} accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.

    Missing
    Schema validation of the request body, and a rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Prove it

    curl -i -X DELETE 'https://YOUR_API/polls/1/etc/1' \
      -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}'
    # Expect 422. A 2xx or 500 means the body is not validated.

    Fix

    class Body(BaseModel):
        name: constr(max_length=200)
    
    @app.delete("/polls/{po_id}/etc/{pc_id}")
    def handler(body: Body): ...

    Regression test

    def test_delete_rejects_unexpected_body(client):
        res = client.delete("/polls/1/etc/1", json={"unexpected": True})
        assert res.status_code == 422

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidencePUT /qas/{qa_id} has no validator or rate limiter attached.

    PUT /qas/{qa_id} accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.

    Missing
    Schema validation of the request body, and a rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Prove it

    curl -i -X PUT 'https://YOUR_API/qas/1' \
      -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}'
    # Expect 422. A 2xx or 500 means the body is not validated.

    Fix

    class Body(BaseModel):
        name: constr(max_length=200)
    
    @app.put("/qas/{qa_id}")
    def handler(body: Body): ...

    Regression test

    def test_put_rejects_unexpected_body(client):
        res = client.put("/qas/1", json={"unexpected": True})
        assert res.status_code == 422

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidencePUT /qas/{qa_id}/files has no validator or rate limiter attached.

    PUT /qas/{qa_id}/files accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.

    Missing
    Schema validation of the request body, and a rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Prove it

    curl -i -X PUT 'https://YOUR_API/qas/1/files' \
      -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}'
    # Expect 422. A 2xx or 500 means the body is not validated.

    Fix

    class Body(BaseModel):
        name: constr(max_length=200)
    
    @app.put("/qas/{qa_id}/files")
    def handler(body: Body): ...

    Regression test

    def test_put_rejects_unexpected_body(client):
        res = client.put("/qas/1/files", json={"unexpected": True})
        assert res.status_code == 422

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidenceDELETE /qas/{qa_id} has no validator or rate limiter attached.

    DELETE /qas/{qa_id} accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.

    Missing
    Schema validation of the request body, and a rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Prove it

    curl -i -X DELETE 'https://YOUR_API/qas/1' \
      -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}'
    # Expect 422. A 2xx or 500 means the body is not validated.

    Fix

    class Body(BaseModel):
        name: constr(max_length=200)
    
    @app.delete("/qas/{qa_id}")
    def handler(body: Body): ...

    Regression test

    def test_delete_rejects_unexpected_body(client):
        res = client.delete("/qas/1", json={"unexpected": True})
        assert res.status_code == 422

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidencePOST /visit has no validator or rate limiter attached.

    POST /visit accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.

    Missing
    Schema validation of the request body, and a rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Prove it

    curl -i -X POST 'https://YOUR_API/visit' \
      -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}'
    # Expect 422. A 2xx or 500 means the body is not validated.

    Fix

    class Body(BaseModel):
        name: constr(max_length=200)
    
    @app.post("/visit")
    def handler(body: Body): ...

    Regression test

    def test_post_rejects_unexpected_body(client):
        res = client.post("/visit", json={"unexpected": True})
        assert res.status_code == 422

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidencePOST /install/form has no validator or rate limiter attached.

    POST /install/form accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.

    Missing
    Schema validation of the request body, and a rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Prove it

    curl -i -X POST 'https://YOUR_API/install/form' \
      -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}'
    # Expect 422. A 2xx or 500 means the body is not validated.

    Fix

    class Body(BaseModel):
        name: constr(max_length=200)
    
    @app.post("/install/form")
    def handler(body: Body): ...

    Regression test

    def test_post_rejects_unexpected_body(client):
        res = client.post("/install/form", json={"unexpected": True})
        assert res.status_code == 422

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Mediumlow confidencePOST /generate_token has no validator or rate limiter attached.

    POST /generate_token accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.

    Missing
    Schema validation of the request body, and a rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Prove it

    curl -i -X POST 'https://YOUR_API/generate_token' \
      -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}'
    # Expect 422. A 2xx or 500 means the body is not validated.

    Fix

    class Body(BaseModel):
        name: constr(max_length=200)
    
    @app.post("/generate_token")
    def handler(body: Body): ...

    Regression test

    def test_post_rejects_unexpected_body(client):
        res = client.post("/generate_token", json={"unexpected": True})
        assert res.status_code == 422

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowhigh confidencecommentservice is not connected to anything.

    commentservice is connected to nothing: dead weight, or a route that was meant to use it and does not.

    Missing
    A route that uses it, or its removal.
    Confidence
    Nothing is wired to it in the design.

    Intended? If it is used by a job or another service, accept it as known debt: run wyro-check --update-baseline and commit the ledger. It stays visible and CI fails only on new findings.

    no-orphan-datastore

  • Lowlow confidenceGET /{bo_table}/writes has no validator or rate limiter attached.

    GET /{bo_table}/writes can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/{bo_table}/writes")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /{bo_table}/writes/{wr_id} has no validator or rate limiter attached.

    GET /{bo_table}/writes/{wr_id} can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/{bo_table}/writes/{wr_id}")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /{bo_table}/{sw} has no validator or rate limiter attached.

    GET /{bo_table}/{sw} can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/{bo_table}/{sw}")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /{bo_table}/writes/{wr_id}/files/{bf_no} has no validator or rate limiter attached.

    GET /{bo_table}/writes/{wr_id}/files/{bf_no} can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/{bo_table}/writes/{wr_id}/files/{bf_no}")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET / has no validator or rate limiter attached.

    GET / can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /writes has no validator or rate limiter attached.

    GET /writes can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/writes")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /writes/{bo_table} has no validator or rate limiter attached.

    GET /writes/{bo_table} can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/writes/{bo_table}")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /config/html has no validator or rate limiter attached.

    GET /config/html can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/config/html")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /config/policy has no validator or rate limiter attached.

    GET /config/policy can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/config/policy")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /config/member has no validator or rate limiter attached.

    GET /config/member can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/config/member")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /config/memo has no validator or rate limiter attached.

    GET /config/memo can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/config/memo")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /config/board has no validator or rate limiter attached.

    GET /config/board can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/config/board")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /contents has no validator or rate limiter attached.

    GET /contents can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/contents")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /contents/{co_id} has no validator or rate limiter attached.

    GET /contents/{co_id} can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/contents/{co_id}")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /faqs has no validator or rate limiter attached.

    GET /faqs can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/faqs")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /faqs/{fm_id} has no validator or rate limiter attached.

    GET /faqs/{fm_id} can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/faqs/{fm_id}")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /{gr_id}/boards has no validator or rate limiter attached.

    GET /{gr_id}/boards can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/{gr_id}/boards")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /menus has no validator or rate limiter attached.

    GET /menus can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/menus")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /newwins has no validator or rate limiter attached.

    GET /newwins can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/newwins")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /polls/latest has no validator or rate limiter attached.

    GET /polls/latest can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/polls/latest")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /polls/{po_id} has no validator or rate limiter attached.

    GET /polls/{po_id} can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/polls/{po_id}")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /populars has no validator or rate limiter attached.

    GET /populars can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/populars")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /qa/config has no validator or rate limiter attached.

    GET /qa/config can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/qa/config")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /qas/{qa_id}/files/{file_index} has no validator or rate limiter attached.

    GET /qas/{qa_id}/files/{file_index} can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/qas/{qa_id}/files/{file_index}")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /search has no validator or rate limiter attached.

    GET /search can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/search")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /visit has no validator or rate limiter attached.

    GET /visit can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/visit")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /install has no validator or rate limiter attached.

    GET /install can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/install")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /install/license has no validator or rate limiter attached.

    GET /install/license can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/install/license")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /install/form has no validator or rate limiter attached.

    GET /install/form can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/install/form")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /device/change/{device} has no validator or rate limiter attached.

    GET /device/change/{device} can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/device/change/{device}")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /show has no validator or rate limiter attached.

    GET /show can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/show")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

  • Lowlow confidenceGET /show_template has no validator or rate limiter attached.

    GET /show_template can be called at any rate. Cheap to fix, rarely urgent on a read.

    Missing
    A rate limit.
    Confidence
    Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.

    Fix

    from slowapi import Limiter
    from slowapi.util import get_remote_address
    
    limiter = Limiter(key_func=get_remote_address)
    
    @app.get("/show_template")
    @limiter.limit("60/minute")
    def handler(request: Request): ...

    Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo: { "policy": { "rules": { "public-entry-guarded": "off" } } } in wyro.json.

    public-entry-guarded

8 places could not be parsed, so any route or table declared there is missing from this report:

  • api/v1/models/__init__.py — class MemberRefreshToken looks like a model but declares no __tablename__
  • core/models.py — class Config looks like a model but declares no __tablename__
  • core/models.py — class Member looks like a model but declares no __tablename__
  • core/models.py — class Group looks like a model but declares no __tablename__
  • core/models.py — class GroupMember looks like a model but declares no __tablename__
  • core/models.py — class Board looks like a model but declares no __tablename__
  • core/models.py — class WriteBaseModel looks like a model but declares no __tablename__
  • core/models.py — class Content looks like a model but declares no __tablename__

Free account, no card. The repository opens as an editable graph.

Add this check to the README

wyro architecture badge
[![wyro architecture](https://wyro.in/api/badge/gnuboard/g6)](https://wyro.in/scan/gnuboard/g6)

It updates itself whenever the repository changes and links back to this report.

What this is

Wyro reads the repository’s routes and data models and checks the paths between them: whether a route can reach a table without passing a guard, whether a datastore holding personal data is exposed to a public read, whether an endpoint that issues credentials requires the credentials it issues.

It is rule-based, not a model. The same commit produces the same result every time, and it does not guess at business rules it cannot see. A rule with nothing to look at is reported as not having run — never as a pass.

This check runs on public source through GitHub’s own API and needs no account. A free account adds the editable architecture canvas, private repositories on paid plans, and a CI gate. No card required.

Maintain this repository? You can have this report removed, and a real vulnerability is disclosed to you privately before it is published. How public reports are handled.