{"id":7060,"date":"2017-09-03T11:12:22","date_gmt":"2017-09-03T03:12:22","guid":{"rendered":"https:\/\/aqzt.com\/7060.html"},"modified":"2017-09-03T11:12:22","modified_gmt":"2017-09-03T03:12:22","slug":"gitlab-%e5%ad%98%e5%9c%a8%e9%ab%98%e5%8d%b1%e6%bc%8f%e6%b4%9e%ef%bc%8c%e7%94%a8%e6%88%b7%e7%a7%81%e6%9c%89%e4%bb%a4%e7%89%8c%e6%88%96%e9%81%ad%e4%bc%9a%e8%af%9d%e5%8a%ab%e6%8c%81","status":"publish","type":"post","link":"https:\/\/aqzt.com\/7060.html","title":{"rendered":"GitLab \u5b58\u5728\u9ad8\u5371\u6f0f\u6d1e\uff0c\u7528\u6237\u79c1\u6709\u4ee4\u724c\u6216\u906d\u4f1a\u8bdd\u52ab\u6301"},"content":{"rendered":"<p><a href=\"https:\/\/www.oschina.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">\u6587\u7ae0\u8f6c\u8f7d\u5f00\u6e90\u4e2d\u56fd<\/a><\/p>\n<p>\u636e\u5916\u5a92\u8fd1\u65e5\u62a5\u9053\uff0c\u6570\u636e\u5b89\u5168\u516c\u53f8&nbsp;<a data-cke-saved-href=\"https:\/\/threatpost.com\/session-hijacking-bug-exposed-gitlab-users-private-tokens\/127747\/\" href=\"https:\/\/threatpost.com\/session-hijacking-bug-exposed-gitlab-users-private-tokens\/127747\/\" target=\"_blank\" rel=\"noopener noreferrer\">Imperva<\/a>&nbsp;\u7814\u7a76\u4eba\u5458\u4e39\u5c3c\u5c14\u00b7\u65af\u74e6\u7279\u66fc\uff08Daniel Svartman\uff09\u4eca\u5e74 5 \u6708\u53d1\u73b0\u5f00\u6e90\u7cfb\u7edf <a href=\"https:\/\/www.incapsula.com\/blog\/blocking-session-hijacking-on-gitlab.html\" target=\"_blank\" rel=\"noopener noreferrer\">GitLab \u5b58\u5728\u4e00\u5904\u9ad8\u5371\u6f0f\u6d1e<\/a>\uff0c\u80fd\u591f\u5141\u8bb8\u653b\u51fb\u8005\u901a\u8fc7\u4f1a\u8bdd\u52ab\u6301\u7a83\u53d6\u7528\u6237\u79c1\u6709\u4ee4\u724c\u3002 \u76f4\u81f3\u672c\u5468\u4e09\uff0cGitLab \u5b98\u65b9\u624d\u786e\u8ba4\u5df2\u5f7b\u5e95\u89e3\u51b3\u8fd9\u4e00\u95ee\u9898\u3002<\/p>\n<p>\u7814\u7a76\u4eba\u5458\u6307\u51fa\uff0c\u5982\u679c\u653b\u51fb\u8005\u901a\u8fc7\u8be5\u6f0f\u6d1e\u6210\u529f\u7834\u89e3\u67d0\u4e00\u5e10\u6237\uff0c\u90a3\u4e48\u4ed6\u4eec\u6781\u6709\u53ef\u80fd\u83b7\u53d6\u8d26\u6237\u7ba1\u7406\u6743\u9650\u3001\u8f6c\u50a8\u6076\u610f\u4ee3\u7801\u5e76\u901a\u8fc7\u4f1a\u8bdd\u52ab\u6301\u7a83\u53d6\u7528\u6237\u654f\u611f\u4fe1\u606f\u7b49\u64cd\u4f5c\u3002\u6b64\u5916\uff0c\u653b\u51fb\u8005\u8fd8\u53ef\u5728\u6267\u884c\u4ee3\u7801\u66f4\u65b0\u65f6\u5c06\u4efb\u4f55\u6076\u610f\u7a0b\u5e8f\u5d4c\u5165\u5176\u4e2d\u3002\u4e0e\u6b64\u540c\u65f6\uff0c\u7531\u4e8e GitLab \u4f7f\u7528\u7684\u6c38\u4e45\u6027\u79c1\u6709\u4f1a\u8bdd\u4ee4\u724c\u6c38\u8fdc\u4e0d\u4f1a\u8fc7\u671f\uff0c\u56e0\u6b64\u5f53\u653b\u51fb\u8005\u83b7\u53d6\u8be5\u4ee4\u724c\u540e\u53d7\u5bb3\u8d26\u6237\u968f\u65f6\u53ef\u80fd\u906d\u53d7\u5165\u4fb5\u3002\u53e6\u5916\uff0c\u503c\u5f97\u6ce8\u610f\u7684\u662f\uff0c\u8be5\u4ee4\u724c\u4ec5\u7531 20 \u4e2a\u5b57\u7b26\u7ec4\u6210\uff0c\u8fd9\u4f7f\u76ee\u6807\u8d26\u6237\u906d\u53d7\u66b4\u529b\u653b\u51fb\u7684\u51e0\u7387\u663e\u8457\u589e\u52a0\u3002<\/p>\n<p>\u7814\u7a76\u4eba\u5458\u8868\u793a\u5c1a\u4e0d\u6e05\u695a\u8be5\u6f0f\u6d1e\u5df2\u51fa\u73b0\u591a\u4e45\uff0c\u800c GitLab \u65b9\u9762\u5219\u6f84\u6e05\u622a\u6b62\u76ee\u524d\u5e76\u6ca1\u6709\u7528\u6237\u906d\u53d7\u6076\u610f\u653b\u51fb\u7684\u6848\u4f8b\u3002GitLab \u5b89\u5168\u4e3b\u7ba1 Brian Neel \u5f3a\u8c03\uff1a\u201c GitLab \u73b0\u4f7f\u7528\u7684\u79c1\u6709\u4ee4\u724c\u53ea\u80fd\u5728\u4e0e\u8de8\u7ad9\u70b9\u811a\u672c\u6216\u5176\u4ed6\u6f0f\u6d1e\u76f8\u7ed3\u5408\u65f6\uff0c\u624d\u4f1a\u5bf9\u7528\u6237\u6784\u6210\u5a01\u80c1\u3002\u5bf9\u6b64\uff0cGitLab \u5b98\u65b9\u6b63\u79ef\u6781\u91c7\u53d6\u66f4\u5b89\u5168\u7684\u63aa\u65bd\u4ee5\u907f\u514d\u8d26\u6237\u4f1a\u8bdd\u6570\u636e\u6cc4\u9732 \u201d\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"71\" data-cke-saved-src=\"https:\/\/aqzt.com\/wp-content\/uploads\/img\/075448_Abix_2896879.png\" src=\"https:\/\/aqzt.com\/wp-content\/uploads\/img\/075448_Abix_2896879.png\" width=\"600\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"113\" data-cke-saved-src=\"https:\/\/aqzt.com\/wp-content\/uploads\/img\/075438_LTGZ_2896879.png\" src=\"https:\/\/aqzt.com\/wp-content\/uploads\/img\/075438_LTGZ_2896879.png\" width=\"600\" \/><\/p>\n<p>\u7a3f\u6e90\uff1a<a data-cke-saved-href=\"http:\/\/hackernews.cc\/archives\/14236\" href=\"http:\/\/hackernews.cc\/archives\/14236\" target=\"_blank\" rel=\"noopener noreferrer\">HackerNews.c<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6587\u7ae0\u8f6c\u8f7d\u5f00\u6e90\u4e2d\u56fd \u636e\u5916\u5a92\u8fd1\u65e5\u62a5\u9053\uff0c\u6570\u636e\u5b89\u5168\u516c\u53f8&nbsp;Imperva&nbsp;\u7814\u7a76\u4eba\u5458\u4e39\u5c3c\u5c14\u00b7\u65af\u74e6\u7279\u66fc\uff08Daniel Svartman\uff09\u4eca\u5e74 5 \u6708\u53d1\u73b0\u5f00\u6e90\u7cfb\u7edf GitLab \u5b58\u5728\u4e00\u5904\u9ad8\u5371\u6f0f\u6d1e\uff0c\u80fd\u591f\u5141\u8bb8\u653b\u51fb\u8005\u901a\u8fc7\u4f1a\u8bdd\u52ab\u6301\u7a83\u53d6\u7528\u6237\u79c1\u6709\u4ee4\u724c\u3002 \u76f4\u81f3\u672c\u5468\u4e09\uff0cGitLab \u5b98\u65b9\u624d\u786e\u8ba4\u5df2\u5f7b\u5e95\u89e3\u51b3\u8fd9\u4e00\u95ee\u9898\u3002 \u7814\u7a76\u4eba\u5458\u6307\u51fa\uff0c\u5982\u679c\u653b\u51fb\u8005\u901a\u8fc7\u8be5\u6f0f\u6d1e\u6210\u529f\u7834\u89e3\u67d0\u4e00\u5e10\u6237\uff0c\u90a3\u4e48\u4ed6\u4eec\u6781\u6709\u53ef\u80fd\u83b7\u53d6\u8d26\u6237\u7ba1\u7406\u6743\u9650\u3001\u8f6c\u50a8\u6076\u610f\u4ee3\u7801\u5e76\u901a\u8fc7\u4f1a\u8bdd\u52ab\u6301\u7a83\u53d6\u7528\u6237\u654f\u611f\u4fe1\u606f\u7b49\u64cd\u4f5c\u3002\u6b64\u5916\uff0c\u653b\u51fb\u8005\u8fd8\u53ef\u5728\u6267\u884c\u4ee3\u7801\u66f4\u65b0\u65f6\u5c06\u4efb\u4f55\u6076\u610f\u7a0b\u5e8f\u5d4c\u5165\u5176\u4e2d\u3002\u4e0e\u6b64\u540c\u65f6\uff0c\u7531\u4e8e GitL<\/p>\n","protected":false},"author":1,"featured_media":6522,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0,"footnotes":""},"categories":[27],"tags":[292,9,345,82,13,71,21,11,20,225],"collection":[],"_links":{"self":[{"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/posts\/7060"}],"collection":[{"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/comments?post=7060"}],"version-history":[{"count":0,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/posts\/7060\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/media\/6522"}],"wp:attachment":[{"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/media?parent=7060"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/categories?post=7060"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/tags?post=7060"},{"taxonomy":"collection","embeddable":true,"href":"https:\/\/aqzt.com\/wp-json\/wp\/v2\/collection?post=7060"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}