Skip to content

[Bug] API调用时,api key跨智能体越权 #4854

@ggh-zyy

Description

@ggh-zyy

Contact Information

1966236926@qq.com

MaxKB Version

2.6.0

Problem Description

进行调用http://ip:端口/chat/api/019cac56-1271-75b1-9f80-70326ed22443/chat/completions接口时,使用任意应用的apikey可以成功调用对话

Steps to Reproduce

Image Image 如图我使用图2的apikey调用图一的应用id Image Image 发现调用成功了。

The expected correct result

No response

Related log output

Additional Information

No response

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions