این اسکیل چه میکند؟
ممیزی/مقاومسازی authorization در Convex؛ جعل هویت از آرگومان، نبود ownership هر سند، query عمومی افشاگر PII و نوشتن در container دیگران. اسکن قطعی، اصلاح مرجع requireIdentity/requireOwner و بررسی tsc.
Audit and harden Convex authorization: identity-from-arg impersonation, missing per-document ownership checks, PII-leaking public queries, and writes into containers the caller doesn't own. Deterministic scan + canonical requireIdentity/requireOwner fix + tsc verify.
چه زمانی به کار میآید؟
برای 'secure my app'، 'audit auth'، 'who can access this data'؛ نه review عمومی کد.
for 'secure my app' / 'audit auth' / 'who can access this data', not generic code review
کاربردهای مرتبط
برچسبگذاری خودکار بر اساس نام و توضیح؛ ممکن است نیازمند اصلاح باشد.