需求数据最后更新:6/22/2026, 2:02:48 PM

需求列表

554 个已验证需求,来自 53 条原始帖。数据来源:hackernews + indiehackers + reddit + twitter + v2ex

554
已验证需求
180
分类
26.0
平均评分
1398
证据帖数
显示 554 个需求中的 5
#1极高Security

多租户SaaS→水平权限漏洞检测

SaaS开发者在构建多租户应用时,难以发现和验证水平权限漏洞(IDOR)。由于测试时仅使用单一账户,此类漏洞在开发阶段极难察觉,可能导致严重数据泄露。

the part that gets me is it looks totally fine when you test it yourself, because you're only ever looking at your own account. it only breaks when a second person pokes at a first person's data, which you just never do while building.
100/100119 参与
reddit
#2早期Security

AI Agent 生产环境安全与鉴权

AI Agent 在访问真实生产环境时,现有网关和沙箱无法提供针对底层协议和复杂网络拓扑的安全控制。同时,Agent 调用第三方服务时缺乏通用的短期令牌生成机制,存在长期令牌泄露风险。

There are a few projects that sit as a proxy in front of agents to do secret injection or apply various guardrails, but none met our needs... particularly the need to handle low-level protocols, or handle complex real world situations like tunneling postgres through k8s.
24/1002123 参与
hackernews
#3早期Security

macOS隐私→原生级特定应用锁定

用户在不锁定整台Mac的情况下需要保护特定个人应用的隐私,但现有的macOS应用锁工具大多过时、收费、被放弃或不够原生。

If you hand your laptop to someone for a few minutes, they can still open Messages, Photos, Notes, Mail, WhatsApp, browsers, password managers, and other personal apps.
6.5/10016 参与
reddit
#4早期Security

SaaS销售→企业合规问卷自动化

面向企业销售时缺乏标准化流程处理安全问卷与合规审查,拖慢销售周期并增加沟通成本。

Founders selling to enterprise: how are you handling the security-questionnaire + subprocessor asks?
5/10019 参与
indiehackers
#5早期Security

独立开发资产→域名防劫持与UI侵权监控

独立开发者的域名被恶意劫持且UI设计被直接抄袭,缺乏有效的预防和侵权监控机制。

Somehow, someone had taken control of the domain or redirected it, and now [astrae.design](http://astrae.design) leads to what looks like a shadcn style template store.
5/100128 参与
reddit