Skip to content

Any signed-in user can read every task dependency, also in projects they are not a member of #657

Description

@rubenvdlinde

Low priority. An edge carries only two task uuids and a link type, no titles or content.

What happens

Any signed-in user can list every task dependency edge in the instance through OpenRegister's objects API. That includes edges between tasks in projects the user is not a member of. Every other project-scoped schema (task, column, projectPhase, plannedTimeEntry) limits reads to project members.

Why

Read at development 6fa5ef5.

  • lib/Settings/planninq_register.json:1119 sets dependency.authorization.read to {"group": "authenticated"} with no match clause.
  • Compare task at :51, which matches project against projects whose members contain $userId.
  • The dependency schema has no project property, so the task pattern cannot be copied as is.
  • Writes are fine. create, update and delete are admin only in the schema, and lib/Service/DependencyService.php:112 checks project membership before it writes.

Fix direction

  1. Add a project property to dependency. DependencyService::create() already resolves the shared project id, so it can store it.
  2. Scope read with the same $lookup on project membership that task uses.
  3. Back-fill project on existing edges in a repair step.

Live check

  1. As user A, create an edge between two tasks in a project that user B is not a member of.
  2. As B, call GET /apps/openregister/api/objects/planninq/dependency. Expected today: A's edge is listed.

Matrix rows

plt-rbac in openspec/parity/capabilities.json (PR #645). The row names OpenRegister as owner because it enforces the rule, but the rule itself lives in this repo.

Related: #250 (security backlog).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingsecurityA user can read or write what they must nottriageAwaiting triage

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions