CustomAlert can survive user deletion and become associated with a recreated login
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 35/100
Línea de trabajo
Start by reading the CustomAlerts.addAlert flow alongside UsersManager.deleteUser and its cleanup handling. Review CustomAlerts.getAlerts and Processor::shouldBeProcessed to understand how residual alerts become visible after login reuse. Done means a chosen lifecycle or concurrency safeguard prevents the reproduced deletion-and-recreation sequence, with a regression test covering deletion during addAlert.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Description
A CustomAlert can remain in the database after its owning user is deleted if an addAlert request completes immediately after the UsersManager.deleteUser cleanup callback.
Because alerts are associated with the textual login value, recreating a user with the same login can make the residual alert visible to the new account once it has access to the same site.
This was previously reported through Matomo's HackerOne program and was assessed as a regular lifecycle bug rather than a security vulnerability. The Matomo team suggested filing it here for hardening.
Root cause
CustomAlerts removes existing alerts when handling UsersManager.deleteUser.
However, an already-authorized CustomAlerts.addAlert request can still complete its database insert after that cleanup has run.
The alert row is associated using the login string rather than an immutable user identity, and there is currently no defensive cleanup when the same login is created again.
Reproduction
Tested locally with:
- Matomo 5.13.0
- CustomAlerts 5.3.3
- self-hosted Docker environment
Sequence:
- Create user
race-userwith access to a test site. - Start a
CustomAlerts.addAlertrequest as that user. - Concurrently delete
race-user. - Arrange the interleaving so deletion cleanup executes before the alert insert finishes.
- Recreate
race-userwith a different password/email and restore access to the same site. - Call
CustomAlerts.getAlerts. - The newly created account can see the residual alert created by the previous identity.
The behavior was reproduced multiple times in a local environment.
Expected behavior
Deleting a user should guarantee that no alert belonging to the deleted identity can later become associated with a new account that happens to reuse the same login.
Possible fixes
Some possible approaches:
- associate alerts with an immutable user identifier instead of only the login string;
- serialize alert creation against user deletion;
- verify that the same user identity still exists before committing the alert insert;
- defensively remove residual alerts when a login is created/reused;
- add a concurrency regression test covering deletion during
addAlert.
Additional note
The residual alert is not processed while the login lacks site access, because Processor::shouldBeProcessed() checks current access. The issue is specifically the lifecycle persistence and reassociation of the alert when the same login is later recreated.
- Lenguaje dominante
- PHP
- Estrellas
- 17
- Forks
- 24
- Merge medio
- 2 d 17 h
- PR fusionados (30 d)
- 5
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Sin guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de matomo-org/plugin-CustomAlerts
-
Dificultad 4/5 3-5 días Aptitud para principiantes 52/100
-
enhancement
Dificultad 3/5 1-2 días Aptitud para principiantes 38/100
matomo-org/plugin-CustomAlerts#170 · 1 comentario ·
-
Dificultad 3/5 1-2 días Aptitud para principiantes 38/100
matomo-org/plugin-CustomAlerts#142 · 1 comentario ·
-
Dificultad 4/5 3-5 días Aptitud para principiantes 30/100
matomo-org/plugin-CustomAlerts#134 · 1 comentario ·
-
Unsubscribe from custom alertsAbiertoc: Privacy enhancement triaged
Dificultad 4/5 3-5 días Aptitud para principiantes 25/100
matomo-org/plugin-CustomAlerts#119 · 1 comentario ·
Todos los issues de matomo-org/plugin-CustomAlerts
Issues similares
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
rap2hpoutre/fast-excel#425 ·
-
bug Medium Priority
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 1 día
-
sync-en
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
sync-en
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 2 días
-
Перевод устарел
Dificultad 1/5 1-3 horas Aptitud para principiantes 78/100