Skip to content

sec(plans): listPlans does not scope account_ids to caller's allowed_accounts #29

Description

@cristim

Summary

listPlans (internal/api/handler_plans.go) gates only on view:plans and passes the client-supplied account_ids straight to the store query without intersecting them with the caller's getAllowedAccounts. The no-filter path returns every plan across all accounts. This is pre-existing (not introduced by PR LeanerCloud/cloud-commitments-cli#994), but PR LeanerCloud/cloud-commitments-cli#994's OR NOT EXISTS arm broadens the surface of an already-unscoped endpoint by also returning all zero-account ("Unassigned") plans regardless of caller scope.

Concern

A non-admin user scoped to a subset of accounts may be able to enumerate plans (including Unassigned legacy plans) belonging to accounts outside their allowed_accounts, depending on how view:plans is granted.

Acceptance criteria

  • Decide whether listPlans should intersect the requested account_ids with getAllowedAccounts for non-admin callers (and how Unassigned plans should be scoped: visible to all view:plans holders, or only to admins?).
  • If yes, add the intersection + a cross-tenant regression test (a scoped user does not see another account's plans).
  • Confirm against the group-only authz model (Administrators vs Standard vs Read-Only).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions