Skip to content

P0: MaxPurchaseAmount permission cap bypassable (upfront-only basis + no retry enforcement) #1494

Description

@cristim

Summary

Tracking issue for a P0 / critical security bug: two live evasion paths against the MaxPurchaseAmount permission constraint, confirmed against current main. The fix is in review as #1477 (adversarial-review follow-up to #1210 / SEC-01, issue #1141); this issue exists so the P0 is visible in the priority-ordered issue queue independent of the PR.

The bugs (from #1477's analysis, verified on main)

  1. Basis was upfront-cost-only, not total commitment. purchaseConstraintSets summed only rec.UpfrontCost across the batch, so a no-upfront (or partial-upfront) RI/Savings Plan — whose UpfrontCost is at/near zero — sails past a MaxPurchaseAmount cap regardless of the true total commitment. An API-key/limited principal could commit far more than their cap allows.
  2. Not enforced on retry. (See fix(auth): bind MaxPurchaseAmount to total commitment, enforce on retry (follow-up to #1210) #1477 for the retry path detail.)

Both are money + auth path: a permission constraint that is supposed to bound spend can be bypassed.

Status

Done when

Close this issue when #1477 lands.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions