Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Security: enforce ownership and auth on user profile and saved policy routes

オープン
#3,395 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
38/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
静か
技術スタック
python

調査の方向性

policyengine_api/routes/user_profile_routes.py、policyengine_api/endpoints/policy.py、および policyengine_api/api.py のルートマウントを確認してください。ユーザー間アクセスの認可テストを追加する前に、既存の認証メカニズムと、検証済みの principal がどのように公開されるかを特定してください。完了条件は、user-profile および saved-policy ルートで認証が必須となり、呼び出し元が指定した他ユーザーの auth0_id または user_id の値を拒否することです。

索引モデルが issue の本文から書いたものです。

説明

Summary

policyengine-api exposes unauthenticated user-profile and user-policy routes with caller-controlled identifiers.

Severity

High

Impact

Any client can create, read, or mutate another user’s profile and saved policies by supplying arbitrary auth0_id or user_id values.

Affected code

  • policyengine_api/routes/user_profile_routes.py:12-135
  • policyengine_api/endpoints/policy.py:81-359
  • policyengine_api/api.py:100-101,148-154

Details

The affected routes have no auth or ownership checks and are mounted with app-wide CORS enabled.

Expected behavior

User-scoped routes should require authenticated callers and enforce ownership based on the authenticated principal, not caller-supplied IDs.

Suggested remediation

  • Add auth middleware/decorators to user-scoped routes
  • Derive subject/ownership from the validated token
  • Reject caller-supplied foreign auth0_id/user_id combinations
  • Add authorization tests for cross-user access attempts
主要言語
Python
スター
18
フォーク
33
平均マージ
1日 10時間
マージ済み PR(30日)
20

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

PolicyEngine/policyengine-api のほかの issue

PolicyEngine/policyengine-api の issue をすべて見る

似ている issue

Python の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。