Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

CustomAlert can survive user deletion and become associated with a recreated login

Abierto
#287 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
5/5
Tiempo estimado
Más de una semana
Aptitud para principiantes
35/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
php
Área
backend, database

Línea de trabajo

Start by reading the CustomAlerts.addAlert flow alongside UsersManager.deleteUser and its cleanup handling. Review CustomAlerts.getAlerts and Processor::shouldBeProcessed to understand how residual alerts become visible after login reuse. Done means a chosen lifecycle or concurrency safeguard prevents the reproduced deletion-and-recreation sequence, with a regression test covering deletion during addAlert.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

bug triaged

Description

A CustomAlert can remain in the database after its owning user is deleted if an addAlert request completes immediately after the UsersManager.deleteUser cleanup callback.

Because alerts are associated with the textual login value, recreating a user with the same login can make the residual alert visible to the new account once it has access to the same site.

This was previously reported through Matomo's HackerOne program and was assessed as a regular lifecycle bug rather than a security vulnerability. The Matomo team suggested filing it here for hardening.

Root cause

CustomAlerts removes existing alerts when handling UsersManager.deleteUser.

However, an already-authorized CustomAlerts.addAlert request can still complete its database insert after that cleanup has run.

The alert row is associated using the login string rather than an immutable user identity, and there is currently no defensive cleanup when the same login is created again.

Reproduction

Tested locally with:

  • Matomo 5.13.0
  • CustomAlerts 5.3.3
  • self-hosted Docker environment

Sequence:

  1. Create user race-user with access to a test site.
  2. Start a CustomAlerts.addAlert request as that user.
  3. Concurrently delete race-user.
  4. Arrange the interleaving so deletion cleanup executes before the alert insert finishes.
  5. Recreate race-user with a different password/email and restore access to the same site.
  6. Call CustomAlerts.getAlerts.
  7. The newly created account can see the residual alert created by the previous identity.

The behavior was reproduced multiple times in a local environment.

Expected behavior

Deleting a user should guarantee that no alert belonging to the deleted identity can later become associated with a new account that happens to reuse the same login.

Possible fixes

Some possible approaches:

  • associate alerts with an immutable user identifier instead of only the login string;
  • serialize alert creation against user deletion;
  • verify that the same user identity still exists before committing the alert insert;
  • defensively remove residual alerts when a login is created/reused;
  • add a concurrency regression test covering deletion during addAlert.

Additional note

The residual alert is not processed while the login lacks site access, because Processor::shouldBeProcessed() checks current access. The issue is specifically the lifecycle persistence and reassociation of the alert when the same login is later recreated.

Lenguaje dominante
PHP
Estrellas
17
Forks
24
Merge medio
2 d 17 h
PR fusionados (30 d)
5

Preparar el entorno

  • Sin Dockerfile ni archivo de Docker Compose
  • Tiene una plantilla de pull request
  • Sin guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de matomo-org/plugin-CustomAlerts

Todos los issues de matomo-org/plugin-CustomAlerts

Issues similares

Más issues de PHP

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.