gnuboard/g6
No critical or high-risk findings. 155 worth a look.
188 warnings in the paths between 296 routes and 1 tables.
Every file was read, but 8 places in them could not be parsed — listed at the end of this report.
- ROUTES
- 296
- TABLES
- 1
- FILES READ
- 302/302
- RULES RUN
- 12/12
188 findings
155 medium33 low
POST /admin/board_copy_update makes calls the check could not follow, so its data access is unknown, not absent: service.is_exist() on BoardFileService; service.copy_board_files() on BoardFileService.
No rule could run on POST /admin/board_copy_update: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.is_exist() on BoardFileService; service.copy_board_files() on BoardFileService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /admin/member_list_delete makes calls the check could not follow, so its data access is unknown, not absent: file_service.update_image_file() on MemberImageService.
No rule could run on POST /admin/member_list_delete: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: file_service.update_image_file() on MemberImageService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /admin/member_form_update makes calls the check could not follow, so its data access is unknown, not absent: file_service.update_image_file() on MemberImageService.
No rule could run on POST /admin/member_form_update: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: file_service.update_image_file() on MemberImageService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /admin/point_update makes calls the check could not follow, so its data access is unknown, not absent: service.save_point() on PointService.
No rule could run on POST /admin/point_update: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.save_point() on PointService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /admin/point_list_delete makes calls the check could not follow, so its data access is unknown, not absent: member_service.update_member_point() on MemberService; service.delete_expire_point() on PointService (+3 more).
No rule could run on POST /admin/point_list_delete: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: member_service.update_member_point() on MemberService; service.delete_expire_point() on PointService; service.delete_use_point() on PointService; service.insert_use_point() on PointService; service.get_total_point() on PointService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /admin/popular/delete makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_populars() on PopularService.
No rule could run on POST /admin/popular/delete: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.fetch_populars() on PopularService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /autosaves makes calls the check could not follow, so its data access is unknown, not absent: service.get_autosave_list() on AJAXService.
No rule could run on GET /autosaves: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.get_autosave_list() on AJAXService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /autosaves/count makes calls the check could not follow, so its data access is unknown, not absent: service.get_autosave_count() on AJAXService.
No rule could run on GET /autosaves/count: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.get_autosave_count() on AJAXService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /autosaves/{as_id} makes calls the check could not follow, so its data access is unknown, not absent: service.get_autosave_content() on AJAXService.
No rule could run on GET /autosaves/{as_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.get_autosave_content() on AJAXService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /autosaves makes calls the check could not follow, so its data access is unknown, not absent: service.autosave_save() on AJAXService; service.get_autosave_count() on AJAXService.
No rule could run on POST /autosaves: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.autosave_save() on AJAXService; service.get_autosave_count() on AJAXService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachDELETE /autosaves/{as_id} makes calls the check could not follow, so its data access is unknown, not absent: service.autosave_delete() on AJAXService.
No rule could run on DELETE /autosaves/{as_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.autosave_delete() on AJAXService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /{bo_table}/writes makes calls the check could not follow, so its data access is unknown, not absent: service.get_board_per_page() on ListPostServiceAPI; service.get_writes() on ListPostServiceAPI (+2 more). It does not declare authentication.
No rule could run on GET /{bo_table}/writes: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.get_board_per_page() on ListPostServiceAPI; service.get_writes() on ListPostServiceAPI; service.get_total_count() on ListPostServiceAPI; service.get_notice_writes() on ListPostServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /{bo_table}/writes/{wr_id} makes calls the check could not follow, so its data access is unknown, not absent: service.get_links() on ReadPostServiceAPI; service.get_comments() on ReadPostServiceAPI (+7 more). It does not declare authentication.
No rule could run on GET /{bo_table}/writes/{wr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.get_links() on ReadPostServiceAPI; service.get_comments() on ReadPostServiceAPI; service.validate_secret() on ReadPostServiceAPI; service.validate_repeat_with_slowapi() on ReadPostServiceAPI; service.block_read_comment() on ReadPostServiceAPI; service.validate_read_level() on ReadPostServiceAPI; service.check_scrap() on ReadPostServiceAPI; service.check_is_good() on ReadPostServiceAPI; ajax_service.get_ajax_good_data() on AJAXService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /{bo_table}/writes/{wr_id} makes calls the check could not follow, so its data access is unknown, not absent: service.get_write_password() on ReadPostServiceAPI; service.validate_read_wr_password() on ReadPostServiceAPI (+7 more). It does not declare authentication.
No rule could run on POST /{bo_table}/writes/{wr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.get_write_password() on ReadPostServiceAPI; service.validate_read_wr_password() on ReadPostServiceAPI; service.get_links() on ReadPostServiceAPI; service.get_comments() on ReadPostServiceAPI; service.validate_repeat_with_slowapi() on ReadPostServiceAPI; service.block_read_comment() on ReadPostServiceAPI; service.check_scrap() on ReadPostServiceAPI; service.check_is_good() on ReadPostServiceAPI; ajax_service.get_ajax_good_data() on AJAXService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /{bo_table}/writes makes calls the check could not follow, so its data access is unknown, not absent: service.validate_secret_board() on CreatePostServiceAPI; service.validate_post_content() on CreatePostServiceAPI (+9 more). It does not declare authentication.
No rule could run on POST /{bo_table}/writes: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.validate_secret_board() on CreatePostServiceAPI; service.validate_post_content() on CreatePostServiceAPI; service.validate_write_level() on CreatePostServiceAPI; service.arrange_data() on CreatePostServiceAPI; service.validate_write_delay_with_slowapi() on CreatePostServiceAPI; service.save_write() on CreatePostServiceAPI; service.add_point() on CreatePostServiceAPI; service.get_parent_post() on CreatePostServiceAPI; service.send_write_mail_() on CreatePostServiceAPI; service.set_notice() on CreatePostServiceAPI; service.delete_cache() on CreatePostServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPUT /{bo_table}/writes/{wr_id} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_restrict_comment_count() on UpdatePostServiceAPI; service.get_write() on UpdatePostServiceAPI (+8 more). It does not declare authentication.
No rule could run on PUT /{bo_table}/writes/{wr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.validate_restrict_comment_count() on UpdatePostServiceAPI; service.get_write() on UpdatePostServiceAPI; service.validate_author() on UpdatePostServiceAPI; service.validate_secret_board() on UpdatePostServiceAPI; service.validate_post_content() on UpdatePostServiceAPI; service.arrange_data() on UpdatePostServiceAPI; service.save_write() on UpdatePostServiceAPI; service.set_notice() on UpdatePostServiceAPI; service.update_children_category() on UpdatePostServiceAPI; service.delete_cache() on UpdatePostServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachDELETE /{bo_table}/writes/{wr_id} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_level() on DeletePostServiceAPI; service.validate_exists_reply() on DeletePostServiceAPI (+2 more). It does not declare authentication.
No rule could run on DELETE /{bo_table}/writes/{wr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.validate_level() on DeletePostServiceAPI; service.validate_exists_reply() on DeletePostServiceAPI; service.validate_exists_comment() on DeletePostServiceAPI; service.delete_write() on DeletePostServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /{bo_table}/writes/delete makes calls the check could not follow, so its data access is unknown, not absent: service.validate_admin_authority() on ListDeleteServiceAPI; service.delete_writes() on ListDeleteServiceAPI. It does not declare authentication.
No rule could run on POST /{bo_table}/writes/delete: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.validate_admin_authority() on ListDeleteServiceAPI; service.delete_writes() on ListDeleteServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /{bo_table}/writes/{wr_id}/delete makes calls the check could not follow, so its data access is unknown, not absent: service.validate_author() on DeletePostServiceAPI; service.validate_exists_reply() on DeletePostServiceAPI (+2 more). It does not declare authentication.
No rule could run on POST /{bo_table}/writes/{wr_id}/delete: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.validate_author() on DeletePostServiceAPI; service.validate_exists_reply() on DeletePostServiceAPI; service.validate_exists_comment() on DeletePostServiceAPI; service.delete_write() on DeletePostServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /{bo_table}/{sw} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_admin_authority() on MoveUpdateServiceAPI; service.get_admin_board_list() on MoveUpdateServiceAPI. It does not declare authentication.
No rule could run on GET /{bo_table}/{sw}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.validate_admin_authority() on MoveUpdateServiceAPI; service.get_admin_board_list() on MoveUpdateServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /{bo_table}/{sw} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_admin_authority() on MoveUpdateServiceAPI; service.get_origin_writes() on MoveUpdateServiceAPI (+1 more). It does not declare authentication.
No rule could run on POST /{bo_table}/{sw}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.validate_admin_authority() on MoveUpdateServiceAPI; service.get_origin_writes() on MoveUpdateServiceAPI; service.move_copy_post() on MoveUpdateServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /{bo_table}/writes/{wr_id}/files makes calls the check could not follow, so its data access is unknown, not absent: service.get_write() on CreatePostServiceAPI; service.upload_files() on CreatePostServiceAPI. It does not declare authentication.
No rule could run on POST /{bo_table}/writes/{wr_id}/files: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.get_write() on CreatePostServiceAPI; service.upload_files() on CreatePostServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /{bo_table}/writes/{wr_id}/files/{bf_no} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_download_level() on DownloadFileServiceAPI; service.get_board_file() on DownloadFileServiceAPI (+1 more). It does not declare authentication.
No rule could run on GET /{bo_table}/writes/{wr_id}/files/{bf_no}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.validate_download_level() on DownloadFileServiceAPI; service.get_board_file() on DownloadFileServiceAPI; service.validate_point() on DownloadFileServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /{bo_table}/writes/{wr_id}/comments makes calls the check could not follow, so its data access is unknown, not absent: service.get_parent_post() on CommentServiceAPI; service.validate_comment_level() on CommentServiceAPI (+7 more). It does not declare authentication.
No rule could run on POST /{bo_table}/writes/{wr_id}/comments: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.get_parent_post() on CommentServiceAPI; service.validate_comment_level() on CommentServiceAPI; service.validate_point() on CommentServiceAPI; service.validate_post_content() on CommentServiceAPI; service.validate_comment_password() on CommentServiceAPI; service.validate_write_delay_with_slowapi() on CommentServiceAPI; service.save_comment() on CommentServiceAPI; service.add_point() on CommentServiceAPI; service.send_write_mail_() on CommentServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPUT /{bo_table}/writes/{wr_id}/comments makes calls the check could not follow, so its data access is unknown, not absent: service.get_parent_post() on CommentServiceAPI; service.validate_author() on CommentServiceAPI (+2 more). It does not declare authentication.
No rule could run on PUT /{bo_table}/writes/{wr_id}/comments: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.get_parent_post() on CommentServiceAPI; service.validate_author() on CommentServiceAPI; service.validate_post_content() on CommentServiceAPI; service.get_cleaned_data() on CommentServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachDELETE /{bo_table}/writes/{wr_id}/comments/{comment_id} makes calls the check could not follow, so its data access is unknown, not absent: service.check_authority() on DeleteCommentServiceAPI; service.delete_comment() on DeleteCommentServiceAPI. It does not declare authentication.
No rule could run on DELETE /{bo_table}/writes/{wr_id}/comments/{comment_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.check_authority() on DeleteCommentServiceAPI; service.delete_comment() on DeleteCommentServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /{bo_table}/writes/{wr_id}/comments/{comment_id}/delete makes calls the check could not follow, so its data access is unknown, not absent: service.validate_author() on DeleteCommentServiceAPI; service.delete_comment() on DeleteCommentServiceAPI. It does not declare authentication.
No rule could run on POST /{bo_table}/writes/{wr_id}/comments/{comment_id}/delete: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.validate_author() on DeleteCommentServiceAPI; service.delete_comment() on DeleteCommentServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /boards/{bo_table}/writes/{wr_id}/{good_type} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_board_good_use() on AJAXService; service.validate_write_owner() on AJAXService (+1 more).
No rule could run on POST /boards/{bo_table}/writes/{wr_id}/{good_type}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.validate_board_good_use() on AJAXService; service.validate_write_owner() on AJAXService; service.get_ajax_good_result() on AJAXService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET / makes calls the check could not follow, so its data access is unknown, not absent: service.get_query() on BoardNewServiceAPI; service.get_offset() on BoardNewServiceAPI (+3 more). It does not declare authentication.
No rule could run on GET /: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.get_query() on BoardNewServiceAPI; service.get_offset() on BoardNewServiceAPI; service.get_board_news() on BoardNewServiceAPI; service.get_total_count() on BoardNewServiceAPI; service.arrange_borad_news_data() on BoardNewServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /writes makes calls the check could not follow, so its data access is unknown, not absent: service.get_latest_posts() on BoardNewServiceAPI. It does not declare authentication.
No rule could run on GET /writes: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.get_latest_posts() on BoardNewServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /writes/{bo_table} makes calls the check could not follow, so its data access is unknown, not absent: service.get_latest_posts() on BoardNewServiceAPI. It does not declare authentication.
No rule could run on GET /writes/{bo_table}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.get_latest_posts() on BoardNewServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /delete makes calls the check could not follow, so its data access is unknown, not absent: service.delete_board_news() on BoardNewServiceAPI.
No rule could run on POST /delete: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.delete_board_news() on BoardNewServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /contents makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_total_records() on ContentServiceAPI; service.read_contents() on ContentServiceAPI. It does not declare authentication.
No rule could run on GET /contents: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.fetch_total_records() on ContentServiceAPI; service.read_contents() on ContentServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /members/current-connect makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_total_records() on CurrentConnectServiceAPI; service.fetch_corrent_connects() on CurrentConnectServiceAPI.
No rule could run on GET /members/current-connect: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.fetch_total_records() on CurrentConnectServiceAPI; service.fetch_corrent_connects() on CurrentConnectServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /faqs makes calls the check could not follow, so its data access is unknown, not absent: service.read_faq_masters() on FaqServiceAPI. It does not declare authentication.
No rule could run on GET /faqs: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.read_faq_masters() on FaqServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /faqs/{fm_id} makes calls the check could not follow, so its data access is unknown, not absent: service.read_faq_master() on FaqServiceAPI; service.read_faqs() on FaqServiceAPI. It does not declare authentication.
No rule could run on GET /faqs/{fm_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.read_faq_master() on FaqServiceAPI; service.read_faqs() on FaqServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /{gr_id}/boards makes calls the check could not follow, so its data access is unknown, not absent: service.check_mobile_only() on GroupBoardListServiceAPI; service.get_boards_in_group() on GroupBoardListServiceAPI. It does not declare authentication.
No rule could run on GET /{gr_id}/boards: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.check_mobile_only() on GroupBoardListServiceAPI; service.get_boards_in_group() on GroupBoardListServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /members makes calls the check could not follow, so its data access is unknown, not absent: service.create_member() on MemberServiceAPI; point_service.save_point() on PointServiceAPI. It does not declare authentication.
No rule could run on POST /members: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.create_member() on MemberServiceAPI; point_service.save_point() on PointServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPUT /members/{mb_id}/email-certification/change makes calls the check could not follow, so its data access is unknown, not absent: member_vaildate.valid_email() on ValidateMemberAPI. It does not declare authentication.
No rule could run on PUT /members/{mb_id}/email-certification/change: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: member_vaildate.valid_email() on ValidateMemberAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPUT /members/{mb_id}/email-certification makes calls the check could not follow, so its data access is unknown, not absent: member_service.read_email_non_certify_member() on MemberServiceAPI. It does not declare authentication.
No rule could run on PUT /members/{mb_id}/email-certification: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: member_service.read_email_non_certify_member() on MemberServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /members/password_certification makes calls the check could not follow, so its data access is unknown, not absent: service.raise_exception() on MemberServiceAPI.
No rule could run on POST /members/password_certification: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.raise_exception() on MemberServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /members/{mb_id} makes calls the check could not follow, so its data access is unknown, not absent: service.get_member_profile() on MemberServiceAPI.
No rule could run on GET /members/{mb_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.get_member_profile() on MemberServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPUT /member makes calls the check could not follow, so its data access is unknown, not absent: service.update_member() on MemberServiceAPI.
No rule could run on PUT /member: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.update_member() on MemberServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachDELETE /member makes calls the check could not follow, so its data access is unknown, not absent: service.leave_member() on MemberServiceAPI.
No rule could run on DELETE /member: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.leave_member() on MemberServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /members/search/id makes calls the check could not follow, so its data access is unknown, not absent: service.find_id() on MemberServiceAPI. It does not declare authentication.
No rule could run on POST /members/search/id: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.find_id() on MemberServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /members/search/password makes calls the check could not follow, so its data access is unknown, not absent: member_service.find_member_from_password_info() on MemberServiceAPI. It does not declare authentication.
No rule could run on POST /members/search/password: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: member_service.find_member_from_password_info() on MemberServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPATCH /members/{mb_id}/password/{token} makes calls the check could not follow, so its data access is unknown, not absent: member_service.reset_password() on MemberServiceAPI. It does not declare authentication.
No rule could run on PATCH /members/{mb_id}/password/{token}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: member_service.reset_password() on MemberServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /memos makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_total_records() on MemoServiceAPI; service.fetch_memos() on MemoServiceAPI.
No rule could run on GET /memos: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.fetch_total_records() on MemoServiceAPI; service.fetch_memos() on MemoServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /memos/{me_id} makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_prev_next_qa() on MemoServiceAPI.
No rule could run on GET /memos/{me_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.fetch_prev_next_qa() on MemoServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPATCH /memos/{me_id}/read makes calls the check could not follow, so its data access is unknown, not absent: service.update_read_datetime() on MemoServiceAPI; service.update_not_read_memos() on MemoServiceAPI.
No rule could run on PATCH /memos/{me_id}/read: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.update_read_datetime() on MemoServiceAPI; service.update_not_read_memos() on MemoServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /memos makes calls the check could not follow, so its data access is unknown, not absent: service.send_memo() on MemoServiceAPI; service.update_memo_call() on MemoServiceAPI (+2 more).
No rule could run on POST /memos: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.send_memo() on MemoServiceAPI; service.update_memo_call() on MemoServiceAPI; point_service.get_config_point() on PointServiceAPI; point_service.save_point() on PointServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachDELETE /memos/{me_id} makes calls the check could not follow, so its data access is unknown, not absent: memo_service.delete_memo_call() on MemoServiceAPI; memo_service.delete_memo() on MemoServiceAPI (+1 more).
No rule could run on DELETE /memos/{me_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: memo_service.delete_memo_call() on MemoServiceAPI; memo_service.delete_memo() on MemoServiceAPI; memo_service.update_not_read_memos() on MemoServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /menus makes calls the check could not follow, so its data access is unknown, not absent: menu_service.fetch_menus() on MenuService. It does not declare authentication.
No rule could run on GET /menus: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: menu_service.fetch_menus() on MenuService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /newwins makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_newwins() on NewwinServiceAPI. It does not declare authentication.
No rule could run on GET /newwins: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.fetch_newwins() on NewwinServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /points makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_total_records() on PointServiceAPI; service.fetch_points() on PointServiceAPI (+1 more).
No rule could run on GET /points: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.fetch_total_records() on PointServiceAPI; service.fetch_points() on PointServiceAPI; service.calculate_sum() on PointServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /polls/latest makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_latest_poll() on PollServiceAPI. It does not declare authentication.
No rule could run on GET /polls/latest: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.fetch_latest_poll() on PollServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /polls/{po_id} makes calls the check could not follow, so its data access is unknown, not absent: service.calculate_poll_result() on PollServiceAPI; service.fetch_other_polls() on PollServiceAPI. It does not declare authentication.
No rule could run on GET /polls/{po_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.calculate_poll_result() on PollServiceAPI; service.fetch_other_polls() on PollServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPATCH /polls/{po_id}/{item} makes calls the check could not follow, so its data access is unknown, not absent: service.update_poll() on PollServiceAPI; point_service.save_point() on PointServiceAPI.
No rule could run on PATCH /polls/{po_id}/{item}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.update_poll() on PollServiceAPI; point_service.save_point() on PointServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /polls/{po_id}/etc makes calls the check could not follow, so its data access is unknown, not absent: service.create_poll_etc() on PollServiceAPI.
No rule could run on POST /polls/{po_id}/etc: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.create_poll_etc() on PollServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachDELETE /polls/{po_id}/etc/{pc_id} makes calls the check could not follow, so its data access is unknown, not absent: poll_service.delete_poll_etc() on PollServiceAPI. It does not declare authentication.
No rule could run on DELETE /polls/{po_id}/etc/{pc_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: poll_service.delete_poll_etc() on PollServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /populars makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_populars() on PopularService. It does not declare authentication.
No rule could run on GET /populars: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.fetch_populars() on PopularService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /populars makes calls the check could not follow, so its data access is unknown, not absent: service.create_popular() on PopularServiceAPI. It does not declare authentication.
No rule could run on POST /populars: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.create_popular() on PopularServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /qas makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_total_records() on QaServiceAPI; service.read_qa_contents() on QaServiceAPI.
No rule could run on GET /qas: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.fetch_total_records() on QaServiceAPI; service.read_qa_contents() on QaServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /qas/{qa_id} makes calls the check could not follow, so its data access is unknown, not absent: service.read_qa_answer() on QaServiceAPI; service.fetch_prev_next_qa() on QaServiceAPI (+1 more).
No rule could run on GET /qas/{qa_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.read_qa_answer() on QaServiceAPI; service.fetch_prev_next_qa() on QaServiceAPI; service.fetch_related_qa_contents() on QaServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /qas makes calls the check could not follow, so its data access is unknown, not absent: service.create_qa_content() on QaServiceAPI.
No rule could run on POST /qas: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.create_qa_content() on QaServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPUT /qas/{qa_id} makes calls the check could not follow, so its data access is unknown, not absent: service.update_qa_content() on QaServiceAPI. It does not declare authentication.
No rule could run on PUT /qas/{qa_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.update_qa_content() on QaServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPUT /qas/{qa_id}/files makes calls the check could not follow, so its data access is unknown, not absent: service.upload_qa_file() on QaFileServiceAPI. It does not declare authentication.
No rule could run on PUT /qas/{qa_id}/files: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.upload_qa_file() on QaFileServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachDELETE /qas/{qa_id} makes calls the check could not follow, so its data access is unknown, not absent: service.delete_qa_content() on QaServiceAPI. It does not declare authentication.
No rule could run on DELETE /qas/{qa_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.delete_qa_content() on QaServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /scraps makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_total_records() on ScrapServiceAPI; service.fetch_scraps() on ScrapServiceAPI (+1 more).
No rule could run on GET /scraps: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.fetch_total_records() on ScrapServiceAPI; service.fetch_scraps() on ScrapServiceAPI; service.set_subjects() on ScrapServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /scraps/{bo_table}/{wr_id} makes calls the check could not follow, so its data access is unknown, not absent: service.create_scrap() on ScrapServiceAPI; service.update_scrap_count() on ScrapServiceAPI (+8 more).
No rule could run on POST /scraps/{bo_table}/{wr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.create_scrap() on ScrapServiceAPI; service.update_scrap_count() on ScrapServiceAPI; comment_service.validate_write_delay() on CommentServiceAPI; comment_service.validate_comment_level() on CommentServiceAPI; comment_service.validate_point() on CommentServiceAPI; comment_service.validate_post_content() on CommentServiceAPI; comment_service.validate_comment_password() on CommentServiceAPI; comment_service.save_comment() on CommentServiceAPI; comment_service.add_point() on CommentServiceAPI; comment_service.send_write_mail_() on CommentServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachDELETE /scraps/{ms_id} makes calls the check could not follow, so its data access is unknown, not absent: service.delete_scrap() on ScrapServiceAPI; service.update_scrap_count() on ScrapServiceAPI.
No rule could run on DELETE /scraps/{ms_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.delete_scrap() on ScrapServiceAPI; service.update_scrap_count() on ScrapServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /search makes calls the check could not follow, so its data access is unknown, not absent: service.get_boards() on SearchServiceAPI; service.search() on SearchServiceAPI. It does not declare authentication.
No rule could run on GET /search: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.get_boards() on SearchServiceAPI; service.search() on SearchServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /visit makes calls the check could not follow, so its data access is unknown, not absent: service.create_visit_record() on VisitServiceAPI. It does not declare authentication.
No rule could run on POST /visit: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.create_visit_record() on VisitServiceAPI.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/ajax/autosave_list makes calls the check could not follow, so its data access is unknown, not absent: service.validate_login() on AJAXService; service.get_autosave_list() on AJAXService.
No rule could run on GET /bbs/ajax/autosave_list: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.validate_login() on AJAXService; service.get_autosave_list() on AJAXService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/ajax/autosave_count makes calls the check could not follow, so its data access is unknown, not absent: service.validate_login() on AJAXService; service.get_autosave_count() on AJAXService.
No rule could run on GET /bbs/ajax/autosave_count: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.validate_login() on AJAXService; service.get_autosave_count() on AJAXService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/ajax/autosave_load/{as_id} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_login() on AJAXService; service.get_autosave_content() on AJAXService.
No rule could run on GET /bbs/ajax/autosave_load/{as_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.validate_login() on AJAXService; service.get_autosave_content() on AJAXService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /bbs/ajax/autosave makes calls the check could not follow, so its data access is unknown, not absent: service.validate_login() on AJAXService; service.autosave_save() on AJAXService (+1 more).
No rule could run on POST /bbs/ajax/autosave: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.validate_login() on AJAXService; service.autosave_save() on AJAXService; service.get_autosave_count() on AJAXService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachDELETE /bbs/ajax/autosave/{as_id} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_login() on AJAXService; service.autosave_delete() on AJAXService.
No rule could run on DELETE /bbs/ajax/autosave/{as_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.validate_login() on AJAXService; service.autosave_delete() on AJAXService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /bbs/ajax/good/{bo_table}/{wr_id}/{type} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_member() on AJAXService; service.validate_token() on AJAXService (+5 more).
No rule could run on POST /bbs/ajax/good/{bo_table}/{wr_id}/{type}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/ajax_good.py:10- Missing
- Evidence of what it touches. Could not follow: service.validate_member() on AJAXService; service.validate_token() on AJAXService; service.get_board() on AJAXService; service.validate_board_good_use() on AJAXService; service.get_write() on AJAXService; service.validate_write_owner() on AJAXService; service.get_ajax_good_result() on AJAXService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /board/group/{gr_id} makes calls the check could not follow, so its data access is unknown, not absent: service.check_mobile_only() on GroupBoardListService; service.get_boards_in_group() on GroupBoardListService.
No rule could run on GET /board/group/{gr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/board.py:48- Missing
- Evidence of what it touches. Could not follow: service.check_mobile_only() on GroupBoardListService; service.get_boards_in_group() on GroupBoardListService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /board/{bo_table} makes calls the check could not follow, so its data access is unknown, not absent: list_post_service.get_total_count() on ListPostService; list_post_service.get_notice_writes() on ListPostService (+3 more).
No rule could run on GET /board/{bo_table}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/board.py:70- Missing
- Evidence of what it touches. Could not follow: list_post_service.get_total_count() on ListPostService; list_post_service.get_notice_writes() on ListPostService; list_post_service.get_writes() on ListPostService; list_post_service.is_write_level() on ListPostService; popular_service.create_popular() on PopularService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /board/list_delete/{bo_table} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_admin_authority() on ListDeleteService; service.delete_writes() on ListDeleteService.
No rule could run on POST /board/list_delete/{bo_table}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/board.py:112- Missing
- Evidence of what it touches. Could not follow: service.validate_admin_authority() on ListDeleteService; service.delete_writes() on ListDeleteService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /board/move/{bo_table} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_admin_authority() on MoveUpdateService; service.get_admin_board_list() on MoveUpdateService.
No rule could run on POST /board/move/{bo_table}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/board.py:129- Missing
- Evidence of what it touches. Could not follow: service.validate_admin_authority() on MoveUpdateService; service.get_admin_board_list() on MoveUpdateService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /board/move_update makes calls the check could not follow, so its data access is unknown, not absent: service.validate_admin_authority() on MoveUpdateService; service.get_origin_writes() on MoveUpdateService (+1 more).
No rule could run on POST /board/move_update: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/board.py:150- Missing
- Evidence of what it touches. Could not follow: service.validate_admin_authority() on MoveUpdateService; service.get_origin_writes() on MoveUpdateService; service.move_copy_post() on MoveUpdateService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /board/write/{bo_table} makes calls the check could not follow, so its data access is unknown, not absent: service.get_parent_post() on CreatePostService; service.validate_write_level() on CreatePostService (+5 more).
No rule could run on GET /board/write/{bo_table}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/board.py:169- Missing
- Evidence of what it touches. Could not follow: service.get_parent_post() on CreatePostService; service.validate_write_level() on CreatePostService; service.get_category_list() on CreatePostService; service.is_html_level() on CreatePostService; service.is_link_level() on CreatePostService; service.is_upload_level() on CreatePostService; file_service.get_board_files_by_form() on BoardFileService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /board/write/{bo_table}/{wr_id} makes calls the check could not follow, so its data access is unknown, not absent: service.get_write() on UpdatePostService; service.validate_write_level() on UpdatePostService (+7 more).
No rule could run on GET /board/write/{bo_table}/{wr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/board.py:221- Missing
- Evidence of what it touches. Could not follow: service.get_write() on UpdatePostService; service.validate_write_level() on UpdatePostService; service.validate_restrict_comment_count() on UpdatePostService; service.get_category_list() on UpdatePostService; service.is_board_notice() on UpdatePostService; service.is_html_level() on UpdatePostService; service.is_link_level() on UpdatePostService; service.is_upload_level() on UpdatePostService; file_service.get_board_files_by_form() on BoardFileService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /board/write_update/{bo_table} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_captcha() on CreatePostService; service.validate_write_delay() on CreatePostService (+15 more).
No rule could run on POST /board/write_update/{bo_table}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/board.py:295- Missing
- Evidence of what it touches. Could not follow: service.validate_captcha() on CreatePostService; service.validate_write_delay() on CreatePostService; service.validate_write_level() on CreatePostService; service.validate_secret_board() on CreatePostService; service.validate_post_content() on CreatePostService; service.is_write_level() on CreatePostService; service.arrange_data() on CreatePostService; service.save_write() on CreatePostService; service.add_point() on CreatePostService; service.get_parent_post() on CreatePostService; service.send_write_mail_() on CreatePostService; service.set_notice() on CreatePostService; service.delete_auto_save() on CreatePostService; service.save_secret_session() on CreatePostService; service.upload_files() on CreatePostService; service.delete_cache() on CreatePostService; service.get_redirect_url() on CreatePostService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /board/write_update/{bo_table}/{wr_id} makes calls the check could not follow, so its data access is unknown, not absent: service.get_write() on UpdatePostService; service.validate_author() on UpdatePostService (+12 more).
No rule could run on POST /board/write_update/{bo_table}/{wr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/board.py:344- Missing
- Evidence of what it touches. Could not follow: service.get_write() on UpdatePostService; service.validate_author() on UpdatePostService; service.validate_restrict_comment_count() on UpdatePostService; service.validate_secret_board() on UpdatePostService; service.validate_post_content() on UpdatePostService; service.arrange_data() on UpdatePostService; service.save_secret_session() on UpdatePostService; service.save_write() on UpdatePostService; service.set_notice() on UpdatePostService; service.delete_auto_save() on UpdatePostService; service.upload_files() on UpdatePostService; service.update_children_category() on UpdatePostService; service.delete_cache() on UpdatePostService; service.get_redirect_url() on UpdatePostService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /board/{bo_table}/{wr_id} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_secret_with_session() on ReadPostService; service.validate_repeat_with_session() on ReadPostService (+10 more).
No rule could run on GET /board/{bo_table}/{wr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/board.py:387- Missing
- Evidence of what it touches. Could not follow: service.validate_secret_with_session() on ReadPostService; service.validate_repeat_with_session() on ReadPostService; service.block_read_comment() on ReadPostService; service.validate_read_level() on ReadPostService; service.check_scrap() on ReadPostService; service.check_is_good() on ReadPostService; service.get_prev_next() on ReadPostService; service.get_links() on ReadPostService; service.get_comments() on ReadPostService; service.is_write_level() on ReadPostService; service.is_reply_level() on ReadPostService; service.is_comment_level() on ReadPostService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /board/delete/{bo_table}/{wr_id} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_level() on DeletePostService; service.validate_exists_reply() on DeletePostService (+2 more).
No rule could run on GET /board/delete/{bo_table}/{wr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/board.py:420- Missing
- Evidence of what it touches. Could not follow: service.validate_level() on DeletePostService; service.validate_exists_reply() on DeletePostService; service.validate_exists_comment() on DeletePostService; service.delete_write() on DeletePostService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /board/{bo_table}/{wr_id}/download/{bf_no} makes calls the check could not follow, so its data access is unknown, not absent: service.validate_download_level() on DownloadFileService; service.get_board_file() on DownloadFileService (+1 more).
No rule could run on GET /board/{bo_table}/{wr_id}/download/{bf_no}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/board.py:437- Missing
- Evidence of what it touches. Could not follow: service.validate_download_level() on DownloadFileService; service.get_board_file() on DownloadFileService; service.validate_point_session() on DownloadFileService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /board/delete_comment/{bo_table}/{comment_id} makes calls the check could not follow, so its data access is unknown, not absent: service.get_comment() on DeleteCommentService; service.check_authority() on DeleteCommentService (+1 more).
No rule could run on GET /board/delete_comment/{bo_table}/{comment_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/board.py:506- Missing
- Evidence of what it touches. Could not follow: service.get_comment() on DeleteCommentService; service.check_authority() on DeleteCommentService; service.delete_comment() on DeleteCommentService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/new makes calls the check could not follow, so its data access is unknown, not absent: service.get_query() on BoardNewService; service.get_offset() on BoardNewService (+3 more).
No rule could run on GET /bbs/new: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/board_new.py:17- Missing
- Evidence of what it touches. Could not follow: service.get_query() on BoardNewService; service.get_offset() on BoardNewService; service.get_board_news() on BoardNewService; service.get_total_count() on BoardNewService; service.arrange_borad_news_data() on BoardNewService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /bbs/new_delete makes calls the check could not follow, so its data access is unknown, not absent: service.delete_board_news() on BoardNewService.
No rule could run on POST /bbs/new_delete: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/board_new.py:44- Missing
- Evidence of what it touches. Could not follow: service.delete_board_news() on BoardNewService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/content/{co_id} makes calls the check could not follow, so its data access is unknown, not absent: content_service.read_content() on ContentService.
No rule could run on GET /bbs/content/{co_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/content.py:14- Missing
- Evidence of what it touches. Could not follow: content_service.read_content() on ContentService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/current_connect makes calls the check could not follow, so its data access is unknown, not absent: service.fetch_corrent_connects() on CurrentConnectService.
No rule could run on GET /bbs/current_connect: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: service.fetch_corrent_connects() on CurrentConnectService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/faq makes calls the check could not follow, so its data access is unknown, not absent: faq_service.read_faq_masters() on FaqService; faq_service.read_faq_master() on FaqService (+1 more).
No rule could run on GET /bbs/faq: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/faq.py:14- Missing
- Evidence of what it touches. Could not follow: faq_service.read_faq_masters() on FaqService; faq_service.read_faq_master() on FaqService; faq_service.read_faqs() on FaqService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/faq/{fm_id} makes calls the check could not follow, so its data access is unknown, not absent: faq_service.read_faq_masters() on FaqService; faq_service.read_faq_master() on FaqService (+1 more).
No rule could run on GET /bbs/faq/{fm_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/faq.py:15- Missing
- Evidence of what it touches. Could not follow: faq_service.read_faq_masters() on FaqService; faq_service.read_faq_master() on FaqService; faq_service.read_faqs() on FaqService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /bbs/login makes calls the check could not follow, so its data access is unknown, not absent: member_service.authenticate_member() on MemberService.
No rule could run on POST /bbs/login: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/login.py:35- Missing
- Evidence of what it touches. Could not follow: member_service.authenticate_member() on MemberService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /bbs/id_lost makes calls the check could not follow, so its data access is unknown, not absent: member_service.find_id() on MemberService.
No rule could run on POST /bbs/id_lost: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: member_service.find_id() on MemberService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /bbs/password_lost makes calls the check could not follow, so its data access is unknown, not absent: member_service.find_member_from_password_info() on MemberService.
No rule could run on POST /bbs/password_lost: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: member_service.find_member_from_password_info() on MemberService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/password_reset/{mb_id}/{token} makes calls the check could not follow, so its data access is unknown, not absent: member_service.read_member_by_lost_certify() on MemberService.
No rule could run on GET /bbs/password_reset/{mb_id}/{token}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: member_service.read_member_by_lost_certify() on MemberService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /bbs/password_reset/{mb_id}/{token} makes calls the check could not follow, so its data access is unknown, not absent: member_service.reset_password() on MemberService.
No rule could run on POST /bbs/password_reset/{mb_id}/{token}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: member_service.reset_password() on MemberService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /bbs/member_leave makes calls the check could not follow, so its data access is unknown, not absent: member_service.read_member() on MemberService; member_service.leave_member() on MemberService.
No rule could run on POST /bbs/member_leave: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: member_service.read_member() on MemberService; member_service.leave_member() on MemberService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/member_profile makes calls the check could not follow, so its data access is unknown, not absent: member_service.read_member() on MemberService; validate.is_open_change_date() on ValidateMember.
No rule could run on GET /bbs/member_profile: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: member_service.read_member() on MemberService; validate.is_open_change_date() on ValidateMember.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /bbs/member_profile makes calls the check could not follow, so its data access is unknown, not absent: member_service.read_member() on MemberService; member_service.update_member() on MemberService (+1 more).
No rule could run on POST /bbs/member_profile: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Missing
- Evidence of what it touches. Could not follow: member_service.read_member() on MemberService; member_service.update_member() on MemberService; file_service.update_image_file() on MemberImageService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/memo makes calls the check could not follow, so its data access is unknown, not absent: memo_service.fetch_total_records() on MemoService; memo_service.fetch_memos() on MemoService.
No rule could run on GET /bbs/memo: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/memo.py:26- Missing
- Evidence of what it touches. Could not follow: memo_service.fetch_total_records() on MemoService; memo_service.fetch_memos() on MemoService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/memo_view/{me_id} makes calls the check could not follow, so its data access is unknown, not absent: member_service.fetch_member_by_id() on MemberService; memo_service.fetch_prev_next_qa() on MemoService (+2 more).
No rule could run on GET /bbs/memo_view/{me_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/memo.py:58- Missing
- Evidence of what it touches. Could not follow: member_service.fetch_member_by_id() on MemberService; memo_service.fetch_prev_next_qa() on MemoService; memo_service.update_read_datetime() on MemoService; memo_service.update_not_read_memos() on MemoService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/memo_form makes calls the check could not follow, so its data access is unknown, not absent: member_service.read_member() on MemberService; member_service.fetch_member_by_id() on MemberService (+1 more).
No rule could run on GET /bbs/memo_form: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/memo.py:91- Missing
- Evidence of what it touches. Could not follow: member_service.read_member() on MemberService; member_service.fetch_member_by_id() on MemberService; memo_service.fetch_memo() on MemoService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /bbs/memo_form_update makes calls the check could not follow, so its data access is unknown, not absent: memo_service.get_receive_members() on MemoService; memo_service.calculate_send_point() on MemoService (+4 more).
No rule could run on POST /bbs/memo_form_update: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/memo.py:118- Missing
- Evidence of what it touches. Could not follow: memo_service.get_receive_members() on MemoService; memo_service.calculate_send_point() on MemoService; memo_service.send_memo() on MemoService; memo_service.update_memo_call() on MemoService; point_service.get_config_point() on PointService; point_service.save_point() on PointService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/memo_delete/{me_id} makes calls the check could not follow, so its data access is unknown, not absent: service.delete_memo_call() on MemoService; service.delete_memo() on MemoService (+1 more).
No rule could run on GET /bbs/memo_delete/{me_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/memo.py:155- Missing
- Evidence of what it touches. Could not follow: service.delete_memo_call() on MemoService; service.delete_memo() on MemoService; service.update_not_read_memos() on MemoService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/point makes calls the check could not follow, so its data access is unknown, not absent: point_service.fetch_total_records() on PointService; point_service.fetch_points() on PointService (+1 more).
No rule could run on GET /bbs/point: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/point.py:17- Missing
- Evidence of what it touches. Could not follow: point_service.fetch_total_records() on PointService; point_service.fetch_points() on PointService; point_service.calculate_sum() on PointService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /bbs/poll_update/{po_id} makes calls the check could not follow, so its data access is unknown, not absent: service.update_poll() on PollService; point_service.save_point() on PointService.
No rule could run on POST /bbs/poll_update/{po_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/poll.py:27- Missing
- Evidence of what it touches. Could not follow: service.update_poll() on PollService; point_service.save_point() on PointService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/poll_result/{po_id} makes calls the check could not follow, so its data access is unknown, not absent: service.calculate_poll_result() on PollService; service.fetch_other_polls() on PollService.
No rule could run on GET /bbs/poll_result/{po_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/poll.py:51- Missing
- Evidence of what it touches. Could not follow: service.calculate_poll_result() on PollService; service.fetch_other_polls() on PollService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /bbs/poll/{po_id}/etc_update makes calls the check could not follow, so its data access is unknown, not absent: service.create_poll_etc() on PollService.
No rule could run on POST /bbs/poll/{po_id}/etc_update: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/poll.py:74- Missing
- Evidence of what it touches. Could not follow: service.create_poll_etc() on PollService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/poll/{po_id}/etc_delete/{pc_id} makes calls the check could not follow, so its data access is unknown, not absent: service.delete_poll_etc() on PollService.
No rule could run on GET /bbs/poll/{po_id}/etc_delete/{pc_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/poll.py:97- Missing
- Evidence of what it touches. Could not follow: service.delete_poll_etc() on PollService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/profile/{mb_id} makes calls the check could not follow, so its data access is unknown, not absent: member_service.get_member_profile() on MemberService.
No rule could run on GET /bbs/profile/{mb_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/profile.py:18- Missing
- Evidence of what it touches. Could not follow: member_service.get_member_profile() on MemberService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/qalist makes calls the check could not follow, so its data access is unknown, not absent: config_service.get_qa_config() on QaConfigService; config_service.get_category_list() on QaConfigService (+2 more).
No rule could run on GET /bbs/qalist: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/qa.py:35- Missing
- Evidence of what it touches. Could not follow: config_service.get_qa_config() on QaConfigService; config_service.get_category_list() on QaConfigService; qa_service.fetch_total_records() on QaService; qa_service.read_qa_contents() on QaService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/qawrite makes calls the check could not follow, so its data access is unknown, not absent: config_service.get_category_list() on QaConfigService; qa_service.init_qa_content() on QaService.
No rule could run on GET /bbs/qawrite: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/qa.py:79- Missing
- Evidence of what it touches. Could not follow: config_service.get_category_list() on QaConfigService; qa_service.init_qa_content() on QaService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/qawrite/{qa_id} makes calls the check could not follow, so its data access is unknown, not absent: config_service.get_category_list() on QaConfigService.
No rule could run on GET /bbs/qawrite/{qa_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/qa.py:103- Missing
- Evidence of what it touches. Could not follow: config_service.get_category_list() on QaConfigService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /bbs/qawrite_update makes calls the check could not follow, so its data access is unknown, not absent: qa_service.read_qa_content() on QaService; qa_service.update_qa_content() on QaService (+2 more).
No rule could run on POST /bbs/qawrite_update: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/qa.py:122- Missing
- Evidence of what it touches. Could not follow: qa_service.read_qa_content() on QaService; qa_service.update_qa_content() on QaService; qa_service.create_qa_content() on QaService; file_service.upload_qa_file() on QaFileService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/qadelete/{qa_id} makes calls the check could not follow, so its data access is unknown, not absent: qa_service.delete_qa_content() on QaService.
No rule could run on GET /bbs/qadelete/{qa_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/qa.py:173- Missing
- Evidence of what it touches. Could not follow: qa_service.delete_qa_content() on QaService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /bbs/qadelete/list makes calls the check could not follow, so its data access is unknown, not absent: qa_service.delete_qa_contents() on QaService.
No rule could run on POST /bbs/qadelete/list: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/qa.py:193- Missing
- Evidence of what it touches. Could not follow: qa_service.delete_qa_contents() on QaService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/qaview/{qa_id} makes calls the check could not follow, so its data access is unknown, not absent: config_service.get_qa_config() on QaConfigService; qa_service.read_qa_answer() on QaService (+2 more).
No rule could run on GET /bbs/qaview/{qa_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/qa.py:210- Missing
- Evidence of what it touches. Could not follow: config_service.get_qa_config() on QaConfigService; qa_service.read_qa_answer() on QaService; qa_service.fetch_prev_next_qa() on QaService; qa_service.fetch_related_qa_contents() on QaService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /bbs/register_form makes calls the check could not follow, so its data access is unknown, not absent: member_service.create_member() on MemberService; file_service.update_image_file() on MemberImageService (+1 more).
No rule could run on POST /bbs/register_form: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/register.py:85- Missing
- Evidence of what it touches. Could not follow: member_service.create_member() on MemberService; file_service.update_image_file() on MemberImageService; point_service.save_point() on PointService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/register_result makes calls the check could not follow, so its data access is unknown, not absent: member_service.fetch_member_by_id() on MemberService.
No rule could run on GET /bbs/register_result: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/register.py:136- Missing
- Evidence of what it touches. Could not follow: member_service.fetch_member_by_id() on MemberService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /bbs/email_certify/update/{mb_id}/{key} makes calls the check could not follow, so its data access is unknown, not absent: member_vaildate.valid_email() on ValidateMember.
No rule could run on POST /bbs/email_certify/update/{mb_id}/{key}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/register.py:173- Missing
- Evidence of what it touches. Could not follow: member_vaildate.valid_email() on ValidateMember.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/email_certify/{mb_id} makes calls the check could not follow, so its data access is unknown, not absent: member_service.read_email_non_certify_member() on MemberService.
No rule could run on GET /bbs/email_certify/{mb_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/register.py:202- Missing
- Evidence of what it touches. Could not follow: member_service.read_email_non_certify_member() on MemberService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/register/validate/{field} makes calls the check could not follow, so its data access is unknown, not absent: validate.valid_id() on ValidateMemberAjax; validate.valid_name() on ValidateMemberAjax (+3 more).
No rule could run on GET /bbs/register/validate/{field}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/register.py:219- Missing
- Evidence of what it touches. Could not follow: validate.valid_id() on ValidateMemberAjax; validate.valid_name() on ValidateMemberAjax; validate.valid_nickname() on ValidateMemberAjax; validate.valid_email() on ValidateMemberAjax; validate.valid_recommend() on ValidateMemberAjax.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /bbs/scrap_popin_update/{bo_table}/{wr_id} makes calls the check could not follow, so its data access is unknown, not absent: scrap_service.create_scrap() on ScrapService; scrap_service.update_scrap_count() on ScrapService.
No rule could run on POST /bbs/scrap_popin_update/{bo_table}/{wr_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/scrap.py:48- Missing
- Evidence of what it touches. Could not follow: scrap_service.create_scrap() on ScrapService; scrap_service.update_scrap_count() on ScrapService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/scrap makes calls the check could not follow, so its data access is unknown, not absent: scrap_service.fetch_total_records() on ScrapService; scrap_service.fetch_scraps() on ScrapService (+1 more).
No rule could run on GET /bbs/scrap: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/scrap.py:90- Missing
- Evidence of what it touches. Could not follow: scrap_service.fetch_total_records() on ScrapService; scrap_service.fetch_scraps() on ScrapService; scrap_service.set_subjects() on ScrapService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/scrap_delete/{ms_id} makes calls the check could not follow, so its data access is unknown, not absent: scrap_service.delete_scrap() on ScrapService; scrap_service.update_scrap_count() on ScrapService.
No rule could run on GET /bbs/scrap_delete/{ms_id}: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/scrap.py:124- Missing
- Evidence of what it touches. Could not follow: scrap_service.delete_scrap() on ScrapService; scrap_service.update_scrap_count() on ScrapService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/search makes calls the check could not follow, so its data access is unknown, not absent: search_service.get_groups() on SearchService; search_service.get_boards() on SearchService (+2 more).
No rule could run on GET /bbs/search: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/search.py:15- Missing
- Evidence of what it touches. Could not follow: search_service.get_groups() on SearchService; search_service.get_boards() on SearchService; search_service.search() on SearchService; popular_service.create_popular() on PopularService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/social/login/callback makes calls the check could not follow, so its data access is unknown, not absent: member_service.get_member() on MemberService.
No rule could run on GET /bbs/social/login/callback: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/social.py:98- Missing
- Evidence of what it touches. Could not follow: member_service.get_member() on MemberService.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachGET /bbs/social/register makes calls the check could not follow, so its data access is unknown, not absent: validate.is_exists_email() on ValidateMember.
No rule could run on GET /bbs/social/register: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/social.py:163- Missing
- Evidence of what it touches. Could not follow: validate.is_exists_email() on ValidateMember.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /bbs/social/register makes calls the check could not follow, so its data access is unknown, not absent: point_service.save_point() on PointService; validate.valid_id() on ValidateMember (+2 more).
No rule could run on POST /bbs/social/register: it calls into code the check could not follow, so whether it reaches data — and whether that is authenticated — is unknown. A route nobody can trace is where a rescue gets hurt.
- Where
bbs/social.py:206- Missing
- Evidence of what it touches. Could not follow: point_service.save_point() on PointService; validate.valid_id() on ValidateMember; validate.valid_email() on ValidateMember; validate.valid_nickname() on ValidateMember.
- Confidence
- The check is certain it could not follow these calls; it is not claiming the route is wrong.
Intended? Trace the chain by hand or log at the data access and hit the route. If it touches no data, record it in the baseline; if it does, that is the path to review first.
unresolved-data-reachPOST /{bo_table}/writes/{wr_id} has no validator or rate limiter attached.
POST /{bo_table}/writes/{wr_id} accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.
- Missing
- Schema validation of the request body, and a rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Prove it
curl -i -X POST 'https://YOUR_API/1/writes/1' \ -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}' # Expect 422. A 2xx or 500 means the body is not validated.Fix
class Body(BaseModel): name: constr(max_length=200) @app.post("/{bo_table}/writes/{wr_id}") def handler(body: Body): ...Regression test
def test_post_rejects_unexpected_body(client): res = client.post("/1/writes/1", json={"unexpected": True}) assert res.status_code == 422Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedDELETE /{bo_table}/writes/{wr_id} has no validator or rate limiter attached.
DELETE /{bo_table}/writes/{wr_id} accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.
- Missing
- Schema validation of the request body, and a rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Prove it
curl -i -X DELETE 'https://YOUR_API/1/writes/1' \ -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}' # Expect 422. A 2xx or 500 means the body is not validated.Fix
class Body(BaseModel): name: constr(max_length=200) @app.delete("/{bo_table}/writes/{wr_id}") def handler(body: Body): ...Regression test
def test_delete_rejects_unexpected_body(client): res = client.delete("/1/writes/1", json={"unexpected": True}) assert res.status_code == 422Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedPOST /{bo_table}/writes/delete has no validator or rate limiter attached.
POST /{bo_table}/writes/delete accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.
- Missing
- Schema validation of the request body, and a rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Prove it
curl -i -X POST 'https://YOUR_API/1/writes/delete' \ -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}' # Expect 422. A 2xx or 500 means the body is not validated.Fix
class Body(BaseModel): name: constr(max_length=200) @app.post("/{bo_table}/writes/delete") def handler(body: Body): ...Regression test
def test_post_rejects_unexpected_body(client): res = client.post("/1/writes/delete", json={"unexpected": True}) assert res.status_code == 422Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedPOST /{bo_table}/writes/{wr_id}/delete has no validator or rate limiter attached.
POST /{bo_table}/writes/{wr_id}/delete accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.
- Missing
- Schema validation of the request body, and a rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Prove it
curl -i -X POST 'https://YOUR_API/1/writes/1/delete' \ -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}' # Expect 422. A 2xx or 500 means the body is not validated.Fix
class Body(BaseModel): name: constr(max_length=200) @app.post("/{bo_table}/writes/{wr_id}/delete") def handler(body: Body): ...Regression test
def test_post_rejects_unexpected_body(client): res = client.post("/1/writes/1/delete", json={"unexpected": True}) assert res.status_code == 422Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedPOST /{bo_table}/{sw} has no validator or rate limiter attached.
POST /{bo_table}/{sw} accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.
- Missing
- Schema validation of the request body, and a rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Prove it
curl -i -X POST 'https://YOUR_API/1/1' \ -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}' # Expect 422. A 2xx or 500 means the body is not validated.Fix
class Body(BaseModel): name: constr(max_length=200) @app.post("/{bo_table}/{sw}") def handler(body: Body): ...Regression test
def test_post_rejects_unexpected_body(client): res = client.post("/1/1", json={"unexpected": True}) assert res.status_code == 422Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedPOST /{bo_table}/writes/{wr_id}/files has no validator or rate limiter attached.
POST /{bo_table}/writes/{wr_id}/files accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.
- Missing
- Schema validation of the request body, and a rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Prove it
curl -i -X POST 'https://YOUR_API/1/writes/1/files' \ -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}' # Expect 422. A 2xx or 500 means the body is not validated.Fix
class Body(BaseModel): name: constr(max_length=200) @app.post("/{bo_table}/writes/{wr_id}/files") def handler(body: Body): ...Regression test
def test_post_rejects_unexpected_body(client): res = client.post("/1/writes/1/files", json={"unexpected": True}) assert res.status_code == 422Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedDELETE /{bo_table}/writes/{wr_id}/comments/{comment_id} has no validator or rate limiter attached.
DELETE /{bo_table}/writes/{wr_id}/comments/{comment_id} accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.
- Missing
- Schema validation of the request body, and a rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Prove it
curl -i -X DELETE 'https://YOUR_API/1/writes/1/comments/1' \ -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}' # Expect 422. A 2xx or 500 means the body is not validated.Fix
class Body(BaseModel): name: constr(max_length=200) @app.delete("/{bo_table}/writes/{wr_id}/comments/{comment_id}") def handler(body: Body): ...Regression test
def test_delete_rejects_unexpected_body(client): res = client.delete("/1/writes/1/comments/1", json={"unexpected": True}) assert res.status_code == 422Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedPOST /{bo_table}/writes/{wr_id}/comments/{comment_id}/delete has no validator or rate limiter attached.
POST /{bo_table}/writes/{wr_id}/comments/{comment_id}/delete accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.
- Missing
- Schema validation of the request body, and a rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Prove it
curl -i -X POST 'https://YOUR_API/1/writes/1/comments/1/delete' \ -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}' # Expect 422. A 2xx or 500 means the body is not validated.Fix
class Body(BaseModel): name: constr(max_length=200) @app.post("/{bo_table}/writes/{wr_id}/comments/{comment_id}/delete") def handler(body: Body): ...Regression test
def test_post_rejects_unexpected_body(client): res = client.post("/1/writes/1/comments/1/delete", json={"unexpected": True}) assert res.status_code == 422Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedPOST /captcha/recaptcha/verify has no validator or rate limiter attached.
POST /captcha/recaptcha/verify accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.
- Missing
- Schema validation of the request body, and a rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Prove it
curl -i -X POST 'https://YOUR_API/captcha/recaptcha/verify' \ -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}' # Expect 422. A 2xx or 500 means the body is not validated.Fix
class Body(BaseModel): name: constr(max_length=200) @app.post("/captcha/recaptcha/verify") def handler(body: Body): ...Regression test
def test_post_rejects_unexpected_body(client): res = client.post("/captcha/recaptcha/verify", json={"unexpected": True}) assert res.status_code == 422Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedPOST /members has no validator or rate limiter attached.
POST /members accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.
- Missing
- Schema validation of the request body, and a rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Prove it
curl -i -X POST 'https://YOUR_API/members' \ -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}' # Expect 422. A 2xx or 500 means the body is not validated.Fix
class Body(BaseModel): name: constr(max_length=200) @app.post("/members") def handler(body: Body): ...Regression test
def test_post_rejects_unexpected_body(client): res = client.post("/members", json={"unexpected": True}) assert res.status_code == 422Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedPUT /members/{mb_id}/email-certification/change has no validator or rate limiter attached.
PUT /members/{mb_id}/email-certification/change accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.
- Missing
- Schema validation of the request body, and a rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Prove it
curl -i -X PUT 'https://YOUR_API/members/1/email-certification/change' \ -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}' # Expect 422. A 2xx or 500 means the body is not validated.Fix
class Body(BaseModel): name: constr(max_length=200) @app.put("/members/{mb_id}/email-certification/change") def handler(body: Body): ...Regression test
def test_put_rejects_unexpected_body(client): res = client.put("/members/1/email-certification/change", json={"unexpected": True}) assert res.status_code == 422Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedPUT /members/{mb_id}/email-certification has no validator or rate limiter attached.
PUT /members/{mb_id}/email-certification accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.
- Missing
- Schema validation of the request body, and a rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Prove it
curl -i -X PUT 'https://YOUR_API/members/1/email-certification' \ -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}' # Expect 422. A 2xx or 500 means the body is not validated.Fix
class Body(BaseModel): name: constr(max_length=200) @app.put("/members/{mb_id}/email-certification") def handler(body: Body): ...Regression test
def test_put_rejects_unexpected_body(client): res = client.put("/members/1/email-certification", json={"unexpected": True}) assert res.status_code == 422Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedDELETE /polls/{po_id}/etc/{pc_id} has no validator or rate limiter attached.
DELETE /polls/{po_id}/etc/{pc_id} accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.
- Missing
- Schema validation of the request body, and a rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Prove it
curl -i -X DELETE 'https://YOUR_API/polls/1/etc/1' \ -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}' # Expect 422. A 2xx or 500 means the body is not validated.Fix
class Body(BaseModel): name: constr(max_length=200) @app.delete("/polls/{po_id}/etc/{pc_id}") def handler(body: Body): ...Regression test
def test_delete_rejects_unexpected_body(client): res = client.delete("/polls/1/etc/1", json={"unexpected": True}) assert res.status_code == 422Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedPUT /qas/{qa_id} has no validator or rate limiter attached.
PUT /qas/{qa_id} accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.
- Missing
- Schema validation of the request body, and a rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Prove it
curl -i -X PUT 'https://YOUR_API/qas/1' \ -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}' # Expect 422. A 2xx or 500 means the body is not validated.Fix
class Body(BaseModel): name: constr(max_length=200) @app.put("/qas/{qa_id}") def handler(body: Body): ...Regression test
def test_put_rejects_unexpected_body(client): res = client.put("/qas/1", json={"unexpected": True}) assert res.status_code == 422Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedPUT /qas/{qa_id}/files has no validator or rate limiter attached.
PUT /qas/{qa_id}/files accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.
- Missing
- Schema validation of the request body, and a rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Prove it
curl -i -X PUT 'https://YOUR_API/qas/1/files' \ -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}' # Expect 422. A 2xx or 500 means the body is not validated.Fix
class Body(BaseModel): name: constr(max_length=200) @app.put("/qas/{qa_id}/files") def handler(body: Body): ...Regression test
def test_put_rejects_unexpected_body(client): res = client.put("/qas/1/files", json={"unexpected": True}) assert res.status_code == 422Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedDELETE /qas/{qa_id} has no validator or rate limiter attached.
DELETE /qas/{qa_id} accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.
- Missing
- Schema validation of the request body, and a rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Prove it
curl -i -X DELETE 'https://YOUR_API/qas/1' \ -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}' # Expect 422. A 2xx or 500 means the body is not validated.Fix
class Body(BaseModel): name: constr(max_length=200) @app.delete("/qas/{qa_id}") def handler(body: Body): ...Regression test
def test_delete_rejects_unexpected_body(client): res = client.delete("/qas/1", json={"unexpected": True}) assert res.status_code == 422Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedPOST /visit has no validator or rate limiter attached.
POST /visit accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.
- Missing
- Schema validation of the request body, and a rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Prove it
curl -i -X POST 'https://YOUR_API/visit' \ -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}' # Expect 422. A 2xx or 500 means the body is not validated.Fix
class Body(BaseModel): name: constr(max_length=200) @app.post("/visit") def handler(body: Body): ...Regression test
def test_post_rejects_unexpected_body(client): res = client.post("/visit", json={"unexpected": True}) assert res.status_code == 422Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedPOST /install/form has no validator or rate limiter attached.
POST /install/form accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.
- Where
install/router.py:84- Missing
- Schema validation of the request body, and a rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Prove it
curl -i -X POST 'https://YOUR_API/install/form' \ -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}' # Expect 422. A 2xx or 500 means the body is not validated.Fix
class Body(BaseModel): name: constr(max_length=200) @app.post("/install/form") def handler(body: Body): ...Regression test
def test_post_rejects_unexpected_body(client): res = client.post("/install/form", json={"unexpected": True}) assert res.status_code == 422Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedPOST /generate_token has no validator or rate limiter attached.
POST /generate_token accepts any body at any rate. Malformed input reaches your handler, and nothing stops a script calling it in a loop.
- Where
main.py:235- Missing
- Schema validation of the request body, and a rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Prove it
curl -i -X POST 'https://YOUR_API/generate_token' \ -H 'content-type: application/json' -d '{"unexpected": {"nested": [1,2,3]}}' # Expect 422. A 2xx or 500 means the body is not validated.Fix
class Body(BaseModel): name: constr(max_length=200) @app.post("/generate_token") def handler(body: Body): ...Regression test
def test_post_rejects_unexpected_body(client): res = client.post("/generate_token", json={"unexpected": True}) assert res.status_code == 422Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedcommentservice is not connected to anything.
commentservice is connected to nothing: dead weight, or a route that was meant to use it and does not.
- Missing
- A route that uses it, or its removal.
- Confidence
- Nothing is wired to it in the design.
Intended? If it is used by a job or another service, accept it as known debt: run
wyro-check --update-baselineand commit the ledger. It stays visible and CI fails only on new findings.no-orphan-datastoreGET /{bo_table}/writes has no validator or rate limiter attached.
GET /{bo_table}/writes can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/{bo_table}/writes") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /{bo_table}/writes/{wr_id} has no validator or rate limiter attached.
GET /{bo_table}/writes/{wr_id} can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/{bo_table}/writes/{wr_id}") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /{bo_table}/{sw} has no validator or rate limiter attached.
GET /{bo_table}/{sw} can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/{bo_table}/{sw}") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /{bo_table}/writes/{wr_id}/files/{bf_no} has no validator or rate limiter attached.
GET /{bo_table}/writes/{wr_id}/files/{bf_no} can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/{bo_table}/writes/{wr_id}/files/{bf_no}") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET / has no validator or rate limiter attached.
GET / can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /writes has no validator or rate limiter attached.
GET /writes can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/writes") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /writes/{bo_table} has no validator or rate limiter attached.
GET /writes/{bo_table} can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/writes/{bo_table}") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /config/html has no validator or rate limiter attached.
GET /config/html can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/config/html") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /config/policy has no validator or rate limiter attached.
GET /config/policy can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/config/policy") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /config/member has no validator or rate limiter attached.
GET /config/member can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/config/member") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /config/memo has no validator or rate limiter attached.
GET /config/memo can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/config/memo") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /config/board has no validator or rate limiter attached.
GET /config/board can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/config/board") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /contents has no validator or rate limiter attached.
GET /contents can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/contents") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /contents/{co_id} has no validator or rate limiter attached.
GET /contents/{co_id} can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/contents/{co_id}") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /faqs has no validator or rate limiter attached.
GET /faqs can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/faqs") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /faqs/{fm_id} has no validator or rate limiter attached.
GET /faqs/{fm_id} can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/faqs/{fm_id}") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /{gr_id}/boards has no validator or rate limiter attached.
GET /{gr_id}/boards can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/{gr_id}/boards") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /menus has no validator or rate limiter attached.
GET /menus can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/menus") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /newwins has no validator or rate limiter attached.
GET /newwins can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/newwins") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /polls/latest has no validator or rate limiter attached.
GET /polls/latest can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/polls/latest") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /polls/{po_id} has no validator or rate limiter attached.
GET /polls/{po_id} can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/polls/{po_id}") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /populars has no validator or rate limiter attached.
GET /populars can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/populars") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /qa/config has no validator or rate limiter attached.
GET /qa/config can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/qa/config") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /qas/{qa_id}/files/{file_index} has no validator or rate limiter attached.
GET /qas/{qa_id}/files/{file_index} can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/qas/{qa_id}/files/{file_index}") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /search has no validator or rate limiter attached.
GET /search can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/search") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /visit has no validator or rate limiter attached.
GET /visit can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/visit") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /install has no validator or rate limiter attached.
GET /install can be called at any rate. Cheap to fix, rarely urgent on a read.
- Where
install/router.py:48- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/install") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /install/license has no validator or rate limiter attached.
GET /install/license can be called at any rate. Cheap to fix, rarely urgent on a read.
- Where
install/router.py:65- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/install/license") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /install/form has no validator or rate limiter attached.
GET /install/form can be called at any rate. Cheap to fix, rarely urgent on a read.
- Where
install/router.py:77- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/install/form") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /device/change/{device} has no validator or rate limiter attached.
GET /device/change/{device} can be called at any rate. Cheap to fix, rarely urgent on a read.
- Where
main.py:251- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/device/change/{device}") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /show has no validator or rate limiter attached.
GET /show can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/show") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /show_template has no validator or rate limiter attached.
GET /show_template can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
from slowapi import Limiter from slowapi.util import get_remote_address limiter = Limiter(key_func=get_remote_address) @app.get("/show_template") @limiter.limit("60/minute") def handler(request: Request): ...Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guarded
8 places could not be parsed, so any route or table declared there is missing from this report:
api/v1/models/__init__.py— class MemberRefreshToken looks like a model but declares no __tablename__core/models.py— class Config looks like a model but declares no __tablename__core/models.py— class Member looks like a model but declares no __tablename__core/models.py— class Group looks like a model but declares no __tablename__core/models.py— class GroupMember looks like a model but declares no __tablename__core/models.py— class Board looks like a model but declares no __tablename__core/models.py— class WriteBaseModel looks like a model but declares no __tablename__core/models.py— class Content looks like a model but declares no __tablename__
Free account, no card. The repository opens as an editable graph.
Add this check to the README
[](https://wyro.in/scan/gnuboard/g6)It updates itself whenever the repository changes and links back to this report.
What this is
Wyro reads the repository’s routes and data models and checks the paths between them: whether a route can reach a table without passing a guard, whether a datastore holding personal data is exposed to a public read, whether an endpoint that issues credentials requires the credentials it issues.
It is rule-based, not a model. The same commit produces the same result every time, and it does not guess at business rules it cannot see. A rule with nothing to look at is reported as not having run — never as a pass.
This check runs on public source through GitHub’s own API and needs no account. A free account adds the editable architecture canvas, private repositories on paid plans, and a CI gate. No card required.
Maintain this repository? You can have this report removed, and a real vulnerability is disclosed to you privately before it is published. How public reports are handled.