Skip to content

Scope location and endpoint reference writes to authorized products#15300

Merged
Maffooch merged 1 commit into
DefectDojo:bugfixfrom
svader0:harden-location-reference-authz
Jul 23, 2026
Merged

Scope location and endpoint reference writes to authorized products#15300
Maffooch merged 1 commit into
DefectDojo:bugfixfrom
svader0:harden-location-reference-authz

Conversation

@svader0

@svader0 svader0 commented Jul 21, 2026

Copy link
Copy Markdown
Collaborator

Hardening and consistency improvement to object-level authorization on several API and UI write paths that associate locations and endpoints with findings and products.

These paths now restrict the selectable references to objects the requesting user is authorized for, matching the scoping the UI forms and dedicated viewsets already apply. No functional change for correctly-permissioned users.

Adds regression tests covering same-product (allowed) and cross-product (rejected) writes.

@svader0
svader0 force-pushed the harden-location-reference-authz branch 2 times, most recently from 88d6aff to 0a9d535 Compare July 21, 2026 07:26
@svader0
svader0 marked this pull request as ready for review July 21, 2026 07:34
@dryrunsecurity

dryrunsecurity Bot commented Jul 21, 2026

Copy link
Copy Markdown

DryRun Security

This pull request contains a critical finding where a sensitive codepath file, dojo/api_v2/serializers.py, was modified by an unauthorized author, 'svader0', violating the configured security policy. While not blocking, this poses a significant risk and requires immediate review.

🔴 Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/api_v2/serializers.py (drs_b595fad0)
Vulnerability Configured Sensitive Codepath Modified by Non-Allowed Author
Description File 'dojo/api_v2/serializers.py' matches configured sensitive codepath pattern 'dojo/api_v2/*.py' and was modified by 'svader0' (commit 8c77d9a) who is not in the allowed authors list.

We've notified @mtesauro.


Comment to provide feedback on these findings.

Report false positive: @dryrunsecurity fp [FINDING ID] [FEEDBACK]
Report low-impact: @dryrunsecurity nit [FINDING ID] [FEEDBACK]

Example: @dryrunsecurity fp drs_90eda195 This code is not user-facing

All finding details can be found in the DryRun Security Dashboard.

@svader0
svader0 force-pushed the harden-location-reference-authz branch from 0a9d535 to b435880 Compare July 21, 2026 15:46
valentijnscholten added a commit that referenced this pull request Jul 21, 2026
v3 security-parity review of three open v2 hardening PRs (#15300,
#15296, #15191): #15300 IMMUNE (v3 locations read-only, no reference-
write surface); #15296 IMMUNE (configuration_permissions not on the v3
user write surface); #15191 identity half was a REAL GAP now fixed.

Gap: get_authorized_users returns co-members, so a non-superuser with
view_user+change_user could PATCH/PUT a visible co-member's email or
username -> account takeover via password reset. Adds
_enforce_identity_field_rules (mirrors UserSerializer.validate()):
superuser unrestricted, self-edit allowed, email/username change to
another account -> 400; create is a no-op. Wired into PATCH and PUT
after the superuser/staff gate; deny-by-default sweep unchanged.

+6 tests. (API_V3_PLAN.md also carries the examples-refresh §12 row
committed next.)
@svader0 svader0 modified the milestones: 3.1.201, 3.1.300 Jul 22, 2026
@svader0
svader0 changed the base branch from dev to bugfix July 22, 2026 18:39
Hardening to object-level authorization on several API and UI write paths that
associate locations and endpoints with findings and products. These paths now
restrict the selectable references to the objects the requesting user is
authorized for, matching the scoping the UI forms and dedicated viewsets
already apply. Adds regression tests. No functional change for
correctly-permissioned users.
@svader0
svader0 force-pushed the harden-location-reference-authz branch from b435880 to 8c77d9a Compare July 22, 2026 18:48

@devGregA devGregA left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the change and the added regression tests — looks good, and CI is green. Thanks Sam! ✅

@Maffooch
Maffooch merged commit 3f2ebcf into DefectDojo:bugfix Jul 23, 2026
148 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants