That UI Bug with Missing Data is a Security Issue
This is (sometimes) a development blog, so I am going to write about some failed development of mine since writing about success is much less interesting. You know that UI bug that someone added to your GitHub Issues where there is some missing data? You know the one, it only happens in production, all of your tests pass, and you marked it as a low priority. Yeah, that one. It’s probably a security bug and you should look into it right away. At least, that is the lesson I taught myself yet again when I began to research this bug.
before
<a id="shared_note.id)" href=""{{">
{{current_user.notes.filter_by(id=shared_note.id).first().title}}
</a>
after
<a href="{{ url_for('main.note', id=shared_note.note_id) }}">
{{current_user.notes.filter_by(id=shared_note.note_id).first().title}}
</a>
The difference is very subtle, but the key issue here is shared_note.id vs shared_note.note_id; I released a feature a few weeks ago that showed you all of the notes that you have shared. Locally everything worked fine, but I noticed later on, once it was in production, that the note title was not showing up. This is, of course, due to the fact that rather than showing the title of the note with the ID shared_note.note_id (the foreign key linking to the note) I was showing the title for the note with the primary key of shared_note.id. The reason why this is a security issue is because this allows someone to share a bunch of notes and start seeing the titles for notes that they do not own. The reason why this worked locally is because I am only testing with a single user, with a single notebook, with a single note, and with a single shared note. This means that in this specific case all of the Primary Keys and Foreign Keys are usually “1” so everything just happens to work.
Key Takeaways
- Always test with multiple users, make your local environment as similar to production as possible
- Consider using UUID instead of Auto Incrementing Integers, this would have been immediately caught if that was the case.
- “Partial Missing Data” == Security Bug (most of the time)
Thank you for reading! Share your thoughts with me on bluesky, mastodon, or via email.
Check out some more stuff to read down below.
Most popular posts this month
- 3 packs
- Coming of Age in the Craw
- Coursera Rails Module 2 Notes
- Growing the CircleCI Community with Discourse
- I sold all my shit
Recent Favorite Blog Posts
This is a collection of the last 8 posts that I bookmarked.
- DEP-18: A proposal for Git-based collaboration in Debian from Optimized by Otto
- [RIDGELINE] No Phones in The Ten-don Shop from Craig Mod — Writer + Photographer
- My next chapter with Mastodon from Mastodon Blog
- How many pillars of observability can you fit on the head of a pin? from charity.wtf
- The Software Essays that Shaped Me from Refactoring English
- Give Your Spouse the Gift of a Couple's Email Domain from mtlynch.io
- Skip the Next iPhone from Articles on Jose M.
- Have smart glasses finally hit an inflection point? from The Torment Nexus
Articles from blogs I follow around the net
Pluralistic: Meta's new top EU regulator is contractually prohibited from hurting Meta's feelings (01 Dec 2025)
Today's links Meta's new top EU regulator is contractually prohibited from saying mean things about Meta: It's one thing to hire an ex-Meta lobbyist, another entirely if she's signed a non-disparagement contract. Hey look at this: Delights…
via Pluralistic: Daily links from Cory Doctorow December 1, 2025Getting Warmer
ESA/Hubble & NASA, ESO/ Lutz Wisotzki et al The early Universe as seen by the MUSE spectrograph on ESO’s Very Large Telescope. So first the Big Bang happens. Everything is incredibly hot and dense; there are photons flying everywhere, but they keep coll…
via Brian Koberlein December 1, 2025Recently
This’ll be the last Recently in 2025. It’s been a decent year for me, a pretty rough year for the rest of the world. I hope, for everyone, that 2026 sees the reversal of some of the current trends. Watching This video from Daniel Yang, who makes spectacular b…
via macwright.com December 1, 2025Generated by openring