From e69f719b8217bee16ff2b21178033056658e41d6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E5=85=AC=E6=98=8E?= <83812544+Ed1s0nZ@users.noreply.github.com> Date: Wed, 9 Apr 2025 16:51:32 +0800 Subject: [PATCH] Update README.md --- README.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index f2bff00..94c4531 100644 --- a/README.md +++ b/README.md @@ -60,13 +60,14 @@ "decision_tree": { "true": [ "非公共接口 && 结构相似度>80%,判断为越权(res返回true)", - "关键业务字段(如订单号/用户ID)的命名和层级完全一致,判断为越权(res返回true)", + "关键业务字段(如订单号/用户ID/手机号等)的值和层级完全一致,判断为越权(res返回true)", "resB和resA的字段完全一致,且均返回了账号A的数据,未出现账号B的相关信息,判断为越权(res返回true)", "操作类接口返回success:true且结构相同(如修改密码成功),判断为越权(res返回true)" ], "false": [ "公共接口(如验证码获取、公共资源获取等,该项需严格判断),判断为非越权(res返回false)", - "结构差异显著(字段缺失率>30%),判断为非越权(res返回false)" + "结构差异显著(字段缺失率>30%),判断为非越权(res返回false)", + "关键业务字段(如订单号/用户ID/手机号等)的值或层级不一致,判断为非越权(res返回false)" ], "unknown": [ "既不满足true_condition,又不满足false_condition的情况,无法判断(res返回unknown)",