From 0ea58f719280c56bc7389f1f41673a7b8fd3cab7 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E5=85=AC=E6=98=8E?= <83812544+Ed1s0nZ@users.noreply.github.com> Date: Sat, 1 Mar 2025 19:30:06 +0800 Subject: [PATCH] Update scan.go --- scan.go | 13 ++++++------- 1 file changed, 6 insertions(+), 7 deletions(-) diff --git a/scan.go b/scan.go index 579ca85..7c8162a 100644 --- a/scan.go +++ b/scan.go @@ -107,7 +107,6 @@ func scan() { } } - func sendHTTPAndKimi(r *RequestResponseLog) (result string, respA string, respB string, err error) { jsonDataReq, err := json.Marshal(r.Request) if err != nil { @@ -165,7 +164,7 @@ func sendHTTPAndKimi(r *RequestResponseLog) (result string, respA string, respB var detectErr error maxRetries := 5 for i := 0; i < maxRetries; i++ { - resultDetect, detectErr = detectPrivilegeEscalation(config.GetConfig().AI, fullURL.String(), resp1, resp2) + resultDetect, detectErr = detectPrivilegeEscalation(config.GetConfig().AI, req1, resp1, resp2, resp.Status) if detectErr == nil { break // 成功退出循环 } @@ -188,19 +187,19 @@ func sendHTTPAndKimi(r *RequestResponseLog) (result string, respA string, respB return `{"res": "white", "reason": "白名单后缀或白名单Content-Type接口"}`, resp1, "", nil } -func detectPrivilegeEscalation(AI string, url, resp1, resp2 string) (string, error) { +func detectPrivilegeEscalation(AI string, reqA, resp1, resp2, statusB string) (string, error) { var result string var err error switch AI { case "kimi": - result, err = aiapis.Kimi(url, resp1, resp2) // 调用 kimi 检测是否越权 + result, err = aiapis.Kimi(reqA, resp1, resp2, statusB) // 调用 kimi 检测是否越权 case "deepseek": - result, err = aiapis.DeepSeek(url, resp1, resp2) // 调用 deepSeek 检测是否越权 + result, err = aiapis.DeepSeek(reqA, resp1, resp2, statusB) // 调用 deepSeek 检测是否越权 case "qianwen": - result, err = aiapis.Qianwen(url, resp1, resp2) // 调用 qianwen 检测是否越权 + result, err = aiapis.Qianwen(reqA, resp1, resp2, statusB) // 调用 qianwen 检测是否越权 default: - result, err = aiapis.Kimi(url, resp1, resp2) // 默认调用 kimi 检测是否越权 + result, err = aiapis.Kimi(reqA, resp1, resp2, statusB) // 默认调用 kimi 检测是否越权 } if err != nil {