[GH-ISSUE #696] [BUG]加强PASSWORDS认证 #263

Closed
opened 2026-02-26 20:36:23 +03:00 by kerem · 1 comment
Owner

Originally created by @x-Ai on GitHub (Jul 27, 2025).
Original GitHub issue: https://github.com/dreamhunter2333/cloudflare_temp_email/issues/696

复现步骤

PASSWORDS已配置时,且DISABLE_ADMIN_PASSWORD_CHECK 为true的情况下,可通过F12删除前端DIV遮罩完全控制站点

预期行为

PASSWORDS配置时,所有API都应该强校验

部署方式

  • cli 部署
  • 用户界面部署

浏览器环境

  • Firefox 141.0
  • Edge 138.0.0.0
Originally created by @x-Ai on GitHub (Jul 27, 2025). Original GitHub issue: https://github.com/dreamhunter2333/cloudflare_temp_email/issues/696 ## 复现步骤 `PASSWORDS`已配置时,且`DISABLE_ADMIN_PASSWORD_CHECK `为true的情况下,可通过F12删除前端DIV遮罩完全控制站点 ## 预期行为 `PASSWORDS`配置时,所有API都应该强校验 ## 部署方式 - [ ] cli 部署 - [x] 用户界面部署 ## 浏览器环境 - Firefox 141.0 - Edge 138.0.0.0
kerem 2026-02-26 20:36:23 +03:00
  • closed this issue
  • added the
    bug
    label
Author
Owner

@dreamhunter2333 commented on GitHub (Jul 27, 2025):

感谢反馈,DISABLE_ADMIN_PASSWORD_CHECK,就是站点不受任何控制,需要配合cf zero trust 使用

公网使用请不要打开 DISABLE_ADMIN_PASSWORD_CHECK

<!-- gh-comment-id:3124272824 --> @dreamhunter2333 commented on GitHub (Jul 27, 2025): 感谢反馈,DISABLE_ADMIN_PASSWORD_CHECK,就是站点不受任何控制,需要配合cf zero trust 使用 公网使用请不要打开 DISABLE_ADMIN_PASSWORD_CHECK
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/cloudflare_temp_email#263
No description provided.