略
q***@163.com
- 发布:2025-11-26 15:25
- 更新:2025-11-26 15:25
- 阅读:13
产品分类: uniCloud/App
操作步骤:
预期结果:
略
略
实际结果:
略
略
bug描述:
"bsonType": "object",
"required": ["news_title"],
"permission": {
"read": "'title2' != doc.news_title",
"create": true,
"update": true,
"delete": true
},
"properties": {
"_id": {
"description": "ID,系统自动生成"
},
"title": {
"bsonType": "string",
"title": "标题"
},
"cover": {
"bsonType": "file",
"title": "封面",
"fileMediaType": "image"
},
"content": {
"bsonType": "string",
"title": "内容"
},
"news_title": {
"bsonType": "string",
"title": "标题2"
}
}
}```
前端普通用户居然可以读到 news_title 为排除条件的记录,把 where 设置为 “news_title == 'title2'”,也完全可以读取出来,太令人困惑了。。。
0 个回复