- Name
- lúc 10:17 25 tháng 9, 2026 UTC
- Tác giả
- Kamo
- Cam kết
- b826b5a
POST /api/session stored any JSON under any KS= key, with a caller-chosen TTL and no authentication, through a Redis client pair of its own. The session Redis runs maxmemory 2gb with allkeys-lru, so a flood of those keys evicts every *** and OTK and signs the whole platform out; the Redis ACL cannot stop it because the route writes as kamo_app. Nothing read a KS= key and nothing called the route (the page uses /api/session/select), so it is deleted, and app/lib/redis.ts is now the only Redis client. Sign-out logged the whole session key twice, and on a Redis failure it printed the ioredis error, which carries the failed command's arguments (the key again). It now logs neither. tests/session-redis.test.mjs (node --test tests/*.test.mjs) pins both: only app/lib/redis.ts opens Redis, no route writes to it except sign-out deleting the caller's own session, and no sign-out log line carries the id, on success or on a Redis failure. KamoAI SP00 final review I-2 and P3.
