From b0807be4d16111f84e1cb6b5d851c827a33b7c5c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E5=85=AC=E6=98=8E?= <83812544+Ed1s0nZ@users.noreply.github.com> Date: Wed, 9 Apr 2025 16:52:17 +0800 Subject: [PATCH] Update config.go --- config/config.go | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/config/config.go b/config/config.go index 757cafc..8d160cb 100644 --- a/config/config.go +++ b/config/config.go @@ -64,13 +64,14 @@ var Prompt = ` "decision_tree": { "true": [ "非公共接口 && 结构相似度>80%,判断为越权(res返回true)", - "关键业务字段(如订单号/用户ID)的命名和层级完全一致,判断为越权(res返回true)", + "关键业务字段(如订单号/用户ID/手机号等)的值和层级完全一致,判断为越权(res返回true)", "resB和resA的字段完全一致,且均返回了账号A的数据,未出现账号B的相关信息,判断为越权(res返回true)", "操作类接口返回success:true且结构相同(如修改密码成功),判断为越权(res返回true)" ], "false": [ "公共接口(如验证码获取、公共资源获取等,该项需严格判断),判断为非越权(res返回false)", - "结构差异显著(字段缺失率>30%),判断为非越权(res返回false)" + "结构差异显著(字段缺失率>30%),判断为非越权(res返回false)", + "关键业务字段(如订单号/用户ID/手机号等)的值或层级不一致,判断为非越权(res返回false)" ], "unknown": [ "既不满足true_condition,又不满足false_condition的情况,无法判断(res返回unknown)",