---
title: TC-00 測試案例總表
eyebrow: Guidant AI 資安檢視總報告 · 安全測試案例（TC）
h1: TC-00 測試案例總表
subtitle: 81 條安全需求各用哪種方法驗、誰在哪裡跑、跑了幾個案例
lede: 每條安全需求（SR）歸到一個主要驗法——**API**（打活系統的端點）、**守衛**（pytest 讀程式碼與資料庫形狀）、**部署**（對裝好的主機唯讀查設定）、**人工**（要外部環境，照清單做）。一條 SR 若同時有幾種，以「主體由誰驗」歸類，其餘列在落點欄；複合條不拆編號。「初查」是符合性矩陣看程式的燈號，不是測試結果；測試跑出來的綠紅看審計報告。
chips:
  - { text: "81 條", kind: accent }
  - { text: "API 34", kind: plain }
  - { text: "守衛 13", kind: plain }
  - { text: "部署 11", kind: plain }
  - { text: "人工 23", kind: warn }
---

> 案例的詳細設計在 test repo `security-compliance/docs/test-cases/sr-*.md`（每條一份，含驗證方式原文、翻成的情境、翻譯時補的資訊、現況）；第一章的逐案例寫法見 [TC-01 身分驗證](TC-01-identity.html)；人工條的步驟見[人工驗證清單](TC-manual-checklist.html)。初查燈號來自[符合性矩陣](../requirements/SR-matrix.html)。

## 一、四類怎麼分

| 類別 | 誰在哪裡跑 | 看什麼 | 條數 |
|---|---|---|---:|
| **API** | test repo `npm run test:security`（對 190） | 不開瀏覽器直接打端點，前置自證→攻擊→對照組→驗沒被改；含 socket.io 與少數 e2e | 34 |
| **守衛** | BE repo `bash scripts/run_security_guards.sh`（本機） | 不打活系統，讀資料庫隔離規則與程式碼形狀，白名單凍結現況 | 13 |
| **部署** | test repo `deploy-checks.sh`（對 190） | 不打 API、不看程式，對裝好的主機看設定：對外埠、標頭、容器身分、安裝包裡的祕密 | 11 |
| **人工** | 人照清單做 | 要真 Google、真 agent、重啟服務、看畫面或告警通道 | 23 |
| **合計** | | | **81** |

案例數：API 情境 93 個、守衛 128 個 pytest case、部署檢查 41 項、人工清單 23 節。

## 二、十章 × 四類

| 章 | 主題 | API | 守衛 | 部署 | 人工 | 合計 |
|---|---|---:|---:|---:|---:|---:|
| SR-01 | 身分驗證 | 6 | 1 | 0 | 1 | 8 |
| SR-02 | 授權 | 8 | 3 | 0 | 3 | 14 |
| SR-03 | 傳輸安全 | 0 | 2 | 3 | 2 | 7 |
| SR-04 | 輸入處理 | 5 | 3 | 0 | 4 | 12 |
| SR-05 | 輸出與回應 | 2 | 1 | 1 | 1 | 5 |
| SR-06 | 祕密管理 | 3 | 1 | 3 | 1 | 8 |
| SR-07 | 可用性與資源 | 1 | 1 | 2 | 5 | 9 |
| SR-08 | 紀錄與稽核 | 3 | 1 | 0 | 2 | 6 |
| SR-09 | 代理程式專章 | 3 | 0 | 2 | 2 | 7 |
| SR-10 | 外部整合專章 | 3 | 0 | 0 | 2 | 5 |
| **合計** | | **34** | **13** | **11** | **23** | **81** |

## 三、全表（81 條）

### SR-01 身分驗證

| SR | 要求一句話 | 類別 | 執行者 | 落點 | 案例數 | 初查 |
|---|---|---|---|---|---|---|
| [SR-01.1](../requirements/SR-01-identity.html#sr-01-1) | 不需登入的入口，回應不得帶可直接使用的祕密 | API | test repo，對 190 | feature `sr-01-1-anonymous-no-secret.feature` | 4 情境 | ⚠️ |
| [SR-01.2](../requirements/SR-01-identity.html#sr-01-2) | 外部身分提供者登入或綁定，必須真的向提供者驗證 | API | test repo，對 190 | feature `sr-01-2-external-idp-verify.feature` | 1 情境 | ⚠️ |
| [SR-01.3](../requirements/SR-01-identity.html#sr-01-3) | 登入失敗鎖定涵蓋所有登入路徑 | API | test repo，對 190 | feature `sr-01-3-login-lockout.feature` | 1 情境 | ⚠️ |
| [SR-01.4](../requirements/SR-01-identity.html#sr-01-4) | OAuth 回呼同時驗連結與瀏覽器 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-01-4) | 1 節 | ⚠️ |
| [SR-01.5](../requirements/SR-01-identity.html#sr-01-5) | 安全計數不得只存易失儲存 | 守衛 | BE repo，本機 | pytest `test_mfa_counter_durability.py`（2 支） | 4 守衛 | ⚠️ |
| [SR-01.6](../requirements/SR-01-identity.html#sr-01-6) | 機器身分只認簽章通行證，每請求查撤銷 | API | test repo，對 190 | feature `sr-01-6-agent-pass.feature` | 3 情境 | ⚠️ |
| [SR-01.7](../requirements/SR-01-identity.html#sr-01-7) | 機器報到比其他端點更嚴 | API | test repo，對 190 | feature `sr-01-7-agent-enrollment.feature` | 1 情境 | ⚠️ |
| [SR-01.8](../requirements/SR-01-identity.html#sr-01-8) | 即時連線每個事件重注入伺服器端身分 | API | test repo，對 190 | feature `sr-01-8-socket-identity.feature` | 3 情境 | ⚠️ |

### SR-02 授權

| SR | 要求一句話 | 類別 | 執行者 | 落點 | 案例數 | 初查 |
|---|---|---|---|---|---|---|
| [SR-02.1](../requirements/SR-02-authorization.html#sr-02-1) | 每張業務表都有資料庫隔離牆，形狀只有一種 | API | test repo，對 190 | feature `sr-02-1-cross-tenant.feature`；pytest `test_rls_all_tenant_tables.py`（5 支）、`test_project_scoped_tables_rls.py` | 1 情境、57 守衛 | ⚠️ |
| [SR-02.2](../requirements/SR-02-authorization.html#sr-02-2) | 租戶層級只准前綴比對，「子讀母」例外只管讀 | 守衛 | BE repo，本機 | pytest `test_rls_no_path_array_policy.py`（3 支）、`test_rls_license_tables_ancestor_read.py`（2 支） | 17 守衛 | ✅ |
| [SR-02.3](../requirements/SR-02-authorization.html#sr-02-3) | 沒身分時隔離最嚴，繞牆必須具名宣告 | 守衛 | BE repo，本機 | pytest `test_rls_no_identity_session.py`（3 支）、`test_scheduler_system_context.py`（2 支） | 16 守衛 | ⚠️ |
| [SR-02.4](../requirements/SR-02-authorization.html#sr-02-4) | 帶資源編號的端點先 resolve 資源再查關係，守門統一走 `common/authz/` | API | test repo，對 190 | feature `sr-02-4-resource-ownership.feature` | 11 情境 | ⚠️ |
| [SR-02.5](../requirements/SR-02-authorization.html#sr-02-5) | 父子兩個編號必核對歸屬，刪實體檔用過濾後的清單 | API | test repo，對 190 | feature `sr-02-5-parent-child-ids.feature` | 3 情境 | ⚠️ |
| [SR-02.6](../requirements/SR-02-authorization.html#sr-02-6) | 能力點掛在 route decorator，選單與端點守門同一張表 | API | test repo，對 190 | feature `sr-02-6-capability-direct-endpoint.feature` | 3 情境 | ⚠️ |
| [SR-02.7](../requirements/SR-02-authorization.html#sr-02-7) | 全站共用設定的寫入要總部層級，判斷點只有一個函式 | API | test repo，對 190 | feature `sr-02-7-company-wide-config-hq.feature`；pytest `test_authz_tenant_hq.py` | 2 情境、10 守衛 | ⚠️ |
| [SR-02.8](../requirements/SR-02-authorization.html#sr-02-8) | 每份檔案有歸屬登記，無人認領一律拒絕 | API | test repo，對 190 | feature `sr-02-8-file-ownership.feature` | 5 情境 | ⚠️ |
| [SR-02.9](../requirements/SR-02-authorization.html#sr-02-9) | 背景工作入列前以呼叫者身分守門，執行時以建單者身分 | API | test repo，對 190 | feature `sr-02-9-background-job-guard.feature` | 2 情境 | ⚠️ |
| [SR-02.10](../requirements/SR-02-authorization.html#sr-02-10) | AI 代查的每一支查詢都申報權限，未申報即拒絕 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-02-10) | 1 節 | ⚠️ |
| [SR-02.11](../requirements/SR-02-authorization.html#sr-02-11) | 跨出本系統的動作之前先比對歸屬或能力點 | API | test repo，對 190 | feature `sr-02-11-outbound-action-guard.feature` | 3 情境 | ⚠️ |
| [SR-02.12](../requirements/SR-02-authorization.html#sr-02-12) | HTTP 中介層擋的每一項，socket 側逐項核對有對應擋法 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-02-12) | 1 節 | ⚠️ |
| [SR-02.13](../requirements/SR-02-authorization.html#sr-02-13) | 端點守門覆蓋率用程式產清單，定期對照 | 守衛 | BE repo，本機 | pytest `test_route_guard_inventory.py`（4 支） | 4 守衛 | ⚠️ |
| [SR-02.14](../requirements/SR-02-authorization.html#sr-02-14) | 停權記在客戶身上，出貨版只認正式簽發站公鑰 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-02-14) | 1 節 | ⚠️ |

### SR-03 傳輸安全

| SR | 要求一句話 | 類別 | 執行者 | 落點 | 案例數 | 初查 |
|---|---|---|---|---|---|---|
| [SR-03.1](../requirements/SR-03-transport.html#sr-03-1) | 對外入口只走 HTTPS | 部署 | test repo，對 190 | deploy-checks 3 項 | 3 部署（1 人工） | ⚠️ |
| [SR-03.2](../requirements/SR-03-transport.html#sr-03-2) | 對外部服務的加密連線必須驗憑證與主機名 | 守衛 | BE repo，本機 | pytest `test_security_shape_external_calls.py`（2 支） | 2 守衛 | ⚠️ |
| [SR-03.3](../requirements/SR-03-transport.html#sr-03-3) | 可選加密的整合預設加密，明文要明示 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-03-3) | 1 節 | ⚠️ |
| [SR-03.4](../requirements/SR-03-transport.html#sr-03-4) | SSH 連線驗主機指紋 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-03-4) | 1 節 | ⚠️ |
| [SR-03.5](../requirements/SR-03-transport.html#sr-03-5) | 內網服務不映射到主機埠、不對外 | 部署 | test repo，對 190 | deploy-checks 3 項 | 3 部署（1 人工） | ⚠️ |
| [SR-03.6](../requirements/SR-03-transport.html#sr-03-6) | 雙向憑證要嘛真驗、要嘛拿掉 | 部署 | test repo，對 190 | deploy-checks 3 項 | 3 部署（1 人工） | ⚠️ |
| [SR-03.7](../requirements/SR-03-transport.html#sr-03-7) | 依設定才存在的對外連線位址只收 https | 守衛 | BE repo，本機 | pytest `test_security_shape_external_calls.py`（2 支） | 2 守衛 | ⚠️ |

### SR-04 輸入處理

| SR | 要求一句話 | 類別 | 執行者 | 落點 | 案例數 | 初查 |
|---|---|---|---|---|---|---|
| [SR-04.1](../requirements/SR-04-input-handling.html#sr-04-1) | 驗身分之前只做便宜、有上限的事 | API | test repo，對 190 | feature `sr-04-1-cheap-work-before-auth.feature` | 2 情境 | ⚠️ |
| [SR-04.2](../requirements/SR-04-input-handling.html#sr-04-2) | 所有匯入與解析端點在解析前先量大小 | 守衛 | BE repo，本機 | pytest `test_security_shape_parsing_ai_logging.py`（2 支） | 2 守衛 | ⚠️ |
| [SR-04.3](../requirements/SR-04-input-handling.html#sr-04-3) | 列表查詢條件沒填就拒絕、每頁筆數有上限 | API | test repo，對 190 | feature `sr-04-3-list-empty-filter-page-limit.feature` | 2 情境 | ⚠️ |
| [SR-04.4](../requirements/SR-04-input-handling.html#sr-04-4) | 交回瀏覽器的檔案由伺服器決定格式 | API | test repo，對 190 | feature `sr-04-4-server-decides-file-format.feature` | 2 情境 | ⚠️ |
| [SR-04.5](../requirements/SR-04-input-handling.html#sr-04-5) | 不需登入的頁面，網址參數不進頁面程式 | API | test repo，對 190 | feature `sr-04-5-anon-page-url-params.feature` | 1 情境 | ⚠️ |
| [SR-04.6](../requirements/SR-04-input-handling.html#sr-04-6) | 外部系統回來的一切都是外部輸入 | 守衛 | BE repo，本機 | pytest `test_security_shape_parsing_ai_logging.py`（2 支） | 2 守衛 | ⚠️ |
| [SR-04.7](../requirements/SR-04-input-handling.html#sr-04-7) | 使用者的字進 AI 前與指令分開 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-04-7) | 1 節 | ⚠️ |
| [SR-04.8](../requirements/SR-04-input-handling.html#sr-04-8) | 交給外部程式執行的內容先看內容、外部程式關進沙箱 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-04-8) | 1 節 | ⚠️ |
| [SR-04.9](../requirements/SR-04-input-handling.html#sr-04-9) | 伺服器端抓取外部網址有 SSRF 防線 | 守衛 | BE repo，本機 | pytest `test_security_shape_external_calls.py`（1 支） | 1 守衛 | ⚠️ |
| [SR-04.10](../requirements/SR-04-input-handling.html#sr-04-10) | 源碼包與規則包四道關卡 | API | test repo，對 190 | feature `sr-04-10-profile-pack-gates.feature` | 1 情境 | ⚠️ |
| [SR-04.11](../requirements/SR-04-input-handling.html#sr-04-11) | 檔案拆解沙箱有上限、有隔離、有入口驗證 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-04-11) | 1 節 | ⚠️ |
| [SR-04.12](../requirements/SR-04-input-handling.html#sr-04-12) | 推播訊息送進瀏覽器前驗格式 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-04-12) | 1 節 | ⚠️ |

### SR-05 輸出與回應

| SR | 要求一句話 | 類別 | 執行者 | 落點 | 案例數 | 初查 |
|---|---|---|---|---|---|---|
| [SR-05.1](../requirements/SR-05-output-encoding.html#sr-05-1) | 使用者輸入在出口依目的地格式跳脫 | API | test repo，對 190 | feature `sr-05-1-output-escaping.feature` | 2 情境 | ⚠️ |
| [SR-05.2](../requirements/SR-05-output-encoding.html#sr-05-2) | 回應欄位白名單；設定類回應遮密鑰；錯誤只回代碼 | API | test repo，對 190 | feature `sr-05-2-config-mask-error-code.feature` | 3 情境 | ⚠️ |
| [SR-05.3](../requirements/SR-05-output-encoding.html#sr-05-3) | 前門對所有回應加安全標頭 | 部署 | test repo，對 190 | deploy-checks 4 項 | 4 部署（1 人工） | ⚠️ |
| [SR-05.4](../requirements/SR-05-output-encoding.html#sr-05-4) | 推到第三方頻道的內容最小化 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-05-4) | 1 節 | ⚠️ |
| [SR-05.5](../requirements/SR-05-output-encoding.html#sr-05-5) | 資料出境（外部 AI）的範圍有清單、客戶看得到 | 守衛 | BE repo，本機 | pytest `test_security_shape_parsing_ai_logging.py`（2 支） | 2 守衛 | ⚠️ |

### SR-06 祕密管理

| SR | 要求一句話 | 類別 | 執行者 | 落點 | 案例數 | 初查 |
|---|---|---|---|---|---|---|
| [SR-06.1](../requirements/SR-06-secrets.html#sr-06-1) | 整合憑證加密落庫、讀取遮罩，不以明文回給瀏覽器 | API | test repo，對 190 | feature `sr-06-1-secret-at-rest-masked.feature` | 2 情境 | ⚠️ |
| [SR-06.2](../requirements/SR-06-secrets.html#sr-06-2) | 祕密在寫出去的那一刻就遮掉 | 守衛 | BE repo，本機 | pytest `test_security_shape_parsing_ai_logging.py`（2 支） | 2 守衛 | ⚠️ |
| [SR-06.3](../requirements/SR-06-secrets.html#sr-06-3) | 存著的密碼只能跟著存著的主機走 | API | test repo，對 190 | feature `sr-06-3-test-connection-host-change.feature` | 4 情境 | ⚠️ |
| [SR-06.4](../requirements/SR-06-secrets.html#sr-06-4) | 解密後的帳密只留記憶體 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-06-4) | 1 節 | ⚠️ |
| [SR-06.5](../requirements/SR-06-secrets.html#sr-06-5) | 位址跟著金鑰走，兩者只能來自同一層 | API | test repo，對 190 | feature `sr-06-5-ai-base-url-key-same-layer.feature` | 3 情境 | ⚠️ |
| [SR-06.6](../requirements/SR-06-secrets.html#sr-06-6) | 服務帳號最小權限，密碼由安裝程式產生 | 部署 | test repo，對 190 | deploy-checks 6 項 | 6 部署（1 人工） | ⚠️ |
| [SR-06.7](../requirements/SR-06-secrets.html#sr-06-7) | 簽發站 API 通行證與 DB 密碼同級保管並輪替 | 部署 | test repo，對 190 | deploy-checks 3 項 | 3 部署（3 人工） | ⚠️ |
| [SR-06.8](../requirements/SR-06-secrets.html#sr-06-8) | 備份與匯出受同等保護 | 部署 | test repo，對 190 | deploy-checks 2 項 | 2 部署 | ⚠️ |

### SR-07 可用性與資源

| SR | 要求一句話 | 類別 | 執行者 | 落點 | 案例數 | 初查 |
|---|---|---|---|---|---|---|
| [SR-07.1](../requirements/SR-07-availability.html#sr-07-1) | 前門有請求大小與速率上限，免登入端點另有濫用上限與告警 | 部署 | test repo，對 190 | deploy-checks 3 項 | 3 部署（1 人工） | ⚠️ |
| [SR-07.2](../requirements/SR-07-availability.html#sr-07-2) | 外部 AI 呼叫有長度、逾時、次數、額度四道上限 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-07-2) | 1 節 | ⚠️ |
| [SR-07.3](../requirements/SR-07-availability.html#sr-07-3) | 所有外部呼叫有逾時，失敗不拖垮本地操作 | 守衛 | BE repo，本機 | pytest `test_security_shape_external_calls.py`（1 支） | 1 守衛 | ⚠️ |
| [SR-07.4](../requirements/SR-07-availability.html#sr-07-4) | 背景工作有去重、並行與深度上限，佇列有租約與重撿 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-07-4) | 1 節 | ⚠️ |
| [SR-07.5](../requirements/SR-07-availability.html#sr-07-5) | 即時連線有同時連線數與事件速率上限，跨來源白名單與 HTTP 對齊 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-07-5) | 1 節 | ⚠️ |
| [SR-07.6](../requirements/SR-07-availability.html#sr-07-6) | 資料庫做的事有上限 | API | test repo，對 190 | feature `sr-07-6-db-work-limits.feature` | 3 情境 | ⚠️ |
| [SR-07.7](../requirements/SR-07-availability.html#sr-07-7) | agent 側暫存有容量上限與清理，磁碟低水位告警 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-07-7) | 1 節 | ⚠️ |
| [SR-07.8](../requirements/SR-07-availability.html#sr-07-8) | 掃描可即時取消、有逾時，預設強度保守 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-07-8) | 1 節 | ⚠️ |
| [SR-07.9](../requirements/SR-07-availability.html#sr-07-9) | Redis 不持久化、不留免密入口，衍生檔同生共死 | 部署 | test repo，對 190 | deploy-checks 6 項 | 6 部署（3 人工） | ⚠️ |

### SR-08 紀錄與稽核

| SR | 要求一句話 | 類別 | 執行者 | 落點 | 案例數 | 初查 |
|---|---|---|---|---|---|---|
| [SR-08.1](../requirements/SR-08-logging-audit.html#sr-08-1) | 紀錄是旁路：寫失敗不拖垮請求，超長先截斷，過期要真的刪 | 守衛 | BE repo，本機 | pytest `test_security_shape_parsing_ai_logging.py`（5 支）、`test_scheduler_system_context.py`（1 支） | 6 守衛 | ✅ |
| [SR-08.2](../requirements/SR-08-logging-audit.html#sr-08-2) | 目標由呼叫者填的動作要限量、收斂回應、稽核記操作者與目標 | API | test repo，對 190 | feature `sr-08-2-scan-target-audit.feature` | 3 情境 | ⚠️ |
| [SR-08.3](../requirements/SR-08-logging-audit.html#sr-08-3) | 刪除順序：先刪紀錄，紀錄真的刪掉才刪實體 | API | test repo，對 190 | feature `sr-08-3-delete-record-first.feature`；pytest `test_delete_order_record_first.py` | 2 情境 | ✅ |
| [SR-08.4](../requirements/SR-08-logging-audit.html#sr-08-4) | 日誌轉送有送達確認或斷線告警，加密設定變更觸發重掛 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-08-4) | 1 節 | ⚠️ |
| [SR-08.5](../requirements/SR-08-logging-audit.html#sr-08-5) | 安全狀態當場算，排程只寫副本，兩者取較嚴 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-08-5)；pytest `test_license_readonly_gate_routing.py` | 1 節 | ✅ |
| [SR-08.6](../requirements/SR-08-logging-audit.html#sr-08-6) | 網址型規則包內容漂移可見，抽取失敗的版本不得派工 | API | test repo，對 190 | feature `sr-08-6-url-profile-drift.feature` | 3 情境 | ⚠️ |

### SR-09 代理程式專章

| SR | 要求一句話 | 類別 | 執行者 | 落點 | 案例數 | 初查 |
|---|---|---|---|---|---|---|
| [SR-09.1](../requirements/SR-09-agent.html#sr-09-1) | 誰能派工、取消、重派、刪紀錄在畫面那頭就守住 | API | test repo，對 190 | feature `sr-09-1-scan-operator-guard.feature` | 4 情境 | ✅ |
| [SR-09.2](../requirements/SR-09-agent.html#sr-09-2) | 資料面 :8443 只對雲端開，demo 模式不得進正式部署 | 部署 | test repo，對 190 | deploy-checks 4 項 | 4 部署（1 人工） | ⚠️ |
| [SR-09.3](../requirements/SR-09-agent.html#sr-09-3) | 證據的可信副本在雲端；agent 側 S3 不誇稱不可竄改 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-09-3) | 1 節 | ⚠️ |
| [SR-09.4](../requirements/SR-09-agent.html#sr-09-4) | 規則包完整性有信任根，url 型與 file 型走同一條路 | API | test repo，對 190 | feature `sr-09-4-profile-integrity.feature` | 1 情境 | ⚠️ |
| [SR-09.5](../requirements/SR-09-agent.html#sr-09-5) | agent 容器非 root、能力全拿掉、有資源上限；沙箱 image 有版本有簽章 | 部署 | test repo，對 190 | deploy-checks 4 項 | 4 部署（1 人工） | ⚠️ |
| [SR-09.6](../requirements/SR-09-agent.html#sr-09-6) | 受檢主機用 agent 專用最小權限帳號，sudoers 只白名單 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-09-6) | 1 節 | ⚠️ |
| [SR-09.7](../requirements/SR-09-agent.html#sr-09-7) | 掃描前明示目標，外部位址額外確認，文件說清掃描就是攻擊流量 | API | test repo，對 190 | feature `sr-09-7-external-target-confirm.feature` | 1 情境 | ⚠️ |

### SR-10 外部整合專章

| SR | 要求一句話 | 類別 | 執行者 | 落點 | 案例數 | 初查 |
|---|---|---|---|---|---|---|
| [SR-10.1](../requirements/SR-10-external.html#sr-10-1) | Drive 不收呼叫者直接給的檔案編號，OAuth scope 收窄到 drive.file | API | test repo，對 190 | feature `sr-10-1-drive-file-id-scope.feature` | 4 情境 | ⚠️ |
| [SR-10.2](../requirements/SR-10-external.html#sr-10-2) | Drive 回呼身分只用於這一次寫入，Google 帳號一租戶一綁 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-10-2) | 1 節 | ⚠️ |
| [SR-10.3](../requirements/SR-10-external.html#sr-10-3) | Drive webhook 固定時間比對，驗過只排工作不信內容 | API | test repo，對 190 | feature `sr-10-3-drive-webhook.feature` | 4 情境 | ✅ |
| [SR-10.4](../requirements/SR-10-external.html#sr-10-4) | 授權序號夠長、有失敗鎖定，收回的授權檔一律本地驗章 | API | test repo，對 190 | feature `sr-10-4-license-activation.feature` | 3 情境 | ✅ |
| [SR-10.5](../requirements/SR-10-external.html#sr-10-5) | 外部 AI 輸入守門與出口守門 | 人工 | 人 | [清單](TC-manual-checklist.html#sr-10-5) | 1 節 | ⚠️ |

## 四、人工條裡能轉自動化的部分

23 條人工裡多數小點在測試主機 190 上其實打得到，關鍵是兩個既有手法：租戶把 AI 位址指到測試主機上的替身（看送出的內容、讓替身不回應或回特定內容），以及把郵件、日誌轉送、問題單位址指到測試主機上的監聽程式。逐條的可轉小點與做法見[人工驗證清單第三部分](TC-manual-checklist.html)。仍須人工的只剩：真 Google 回呼、真跑掃描工具的 agent、要重啟或改主機設定、要看告警通道或畫面、客戶主機上的設定。
