Skip to content

sec: enforce view-only+write group-combination contradiction in the backend (guardGroupChange) #78

Description

@cristim

Adversarial review of LeanerCloud/cloud-commitments-cli#1427 (frontend validateGroupCombination) noted the contradiction check (a view-only group must not combine with a write-capable group) is FRONTEND-ONLY. Backend guardGroupChange (internal/auth/service_user.go:~369) enforces >=1 group / last-admin / self-escalation (LeanerCloud/cloud-commitments-cli#907) but NOT the view-only+write contradiction, so the /api/users update endpoint accepts contradictory combos from a non-UI API consumer. Low security impact (additive permission model; a malicious update:users holder could assign the write group alone anyway - it's an accident guard, not a security boundary), but worth backend parity for defense-in-depth and non-UI consumers. Add the same view-only/write-capable classification to guardGroupChange and reject with a clear error. Effort ~S. Source: LeanerCloud/cloud-commitments-cli#1427 review.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority/p3Polish / idea / may never shipseverity/lowMinor harmtriagedItem has been triagedtype/choreMaintenance / non-user-visible

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions