Conversation
A Location row is deduplicated across every product that records the same URL, so a predicate that joins out of the row can be satisfied by a reference the caller is not authorized for. Authorizing the result set afterwards is a separate filter() call, which Django compiles to a second join, so the row still qualifies through the caller's own reference while the match through another product's data stays observable. The existing rewrite that bounds those predicates was a method on one filterset class. Move it to a mixin and apply it to the REST Location list filterset, then bound the two remaining predicates that are applied outside a filterset: the endpoint_status compatibility filter and the vulnerable-endpoint view body. The subquery now applies the predicate and the product bound as two filter() calls. As one kwargs dict they can spell the same lookup and silently drop one of them, which is reachable from the list-valued product filters. No query parameter, response field or schema change. For a non-privileged caller the only behaviour that changes is that a predicate stops matching through references they cannot see.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Hardening and consistency improvement to the Location filters under the V3 Locations feature.
A Location row is deduplicated across every product that records the same value, so a filter that reaches outward from the row can be satisfied through a reference that belongs to a different product. #15760 taught one filterset to match against the requesting user's own references only, but it left that rewrite as a method on a single class. This moves it to a mixin and applies it to the remaining readers, plus two predicates that are applied outside a filterset.
Adds regression tests. No query parameter, response field or schema change, and no functional change for a product that is the only one recording the value.