You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
P0: MaxPurchaseAmount permission cap bypassable (upfront-only basis + no retry enforcement) #1494
Tracking issue for a P0 / critical security bug: two live evasion paths against the MaxPurchaseAmount permission constraint, confirmed against current main. The fix is in review as #1477 (adversarial-review follow-up to #1210 / SEC-01, issue #1141); this issue exists so the P0 is visible in the priority-ordered issue queue independent of the PR.
The bugs (from #1477's analysis, verified on main)
Basis was upfront-cost-only, not total commitment.purchaseConstraintSets summed only rec.UpfrontCost across the batch, so a no-upfront (or partial-upfront) RI/Savings Plan — whose UpfrontCost is at/near zero — sails past a MaxPurchaseAmount cap regardless of the true total commitment. An API-key/limited principal could commit far more than their cap allows.
Summary
Tracking issue for a P0 / critical security bug: two live evasion paths against the
MaxPurchaseAmountpermission constraint, confirmed against currentmain. The fix is in review as #1477 (adversarial-review follow-up to #1210 / SEC-01, issue #1141); this issue exists so the P0 is visible in the priority-ordered issue queue independent of the PR.The bugs (from #1477's analysis, verified on
main)purchaseConstraintSetssummed onlyrec.UpfrontCostacross the batch, so a no-upfront (or partial-upfront) RI/Savings Plan — whoseUpfrontCostis at/near zero — sails past aMaxPurchaseAmountcap regardless of the true total commitment. An API-key/limited principal could commit far more than their cap allows.Both are money + auth path: a permission constraint that is supposed to bound spend can be bypassed.
Status
Done when
main, andClose this issue when #1477 lands.