That UI Bug with Missing Data is a Security Issue
This is (sometimes) a development blog, so I am going to write about some failed development of mine since writing about success is much less interesting. You know that UI bug that someone added to your GitHub Issues where there is some missing data? You know the one, it only happens in production, all of your tests pass, and you marked it as a low priority. Yeah, that one. It’s probably a security bug and you should look into it right away. At least, that is the lesson I taught myself yet again when I began to research this bug.
before
<a id="shared_note.id)" href=""{{">
{{current_user.notes.filter_by(id=shared_note.id).first().title}}
</a>
after
<a href="{{ url_for('main.note', id=shared_note.note_id) }}">
{{current_user.notes.filter_by(id=shared_note.note_id).first().title}}
</a>
The difference is very subtle, but the key issue here is shared_note.id vs shared_note.note_id; I released a feature a few weeks ago that showed you all of the notes that you have shared. Locally everything worked fine, but I noticed later on, once it was in production, that the note title was not showing up. This is, of course, due to the fact that rather than showing the title of the note with the ID shared_note.note_id (the foreign key linking to the note) I was showing the title for the note with the primary key of shared_note.id. The reason why this is a security issue is because this allows someone to share a bunch of notes and start seeing the titles for notes that they do not own. The reason why this worked locally is because I am only testing with a single user, with a single notebook, with a single note, and with a single shared note. This means that in this specific case all of the Primary Keys and Foreign Keys are usually “1” so everything just happens to work.
Key Takeaways
- Always test with multiple users, make your local environment as similar to production as possible
- Consider using UUID instead of Auto Incrementing Integers, this would have been immediately caught if that was the case.
- “Partial Missing Data” == Security Bug (most of the time)
Thank you for reading! Share your thoughts with me on bluesky, mastodon, or via email.
Check out some more stuff to read down below.
Most popular posts this month
- One Year of Foxglove
- SQLite DB Migrations with PRAGMA user_version
- Lev Lazinskiy
- Microblog
- Vagrant Box for ROS2 on Apple Silicon
Recent Favorite Blog Posts
This is a collection of the last 8 posts that I bookmarked.
- The contagion of fear from The Observation Deck
- The revolt of the reader from The Observation Deck
- Deeper dive: Were Touch Bar’s problems software rather than hardware? from Unsung
- Joining Cursor from Fatih Arslan
- Pluralistic: Digital sewer socialism (08 Aug 2026) from Pluralistic: Daily links from Cory Doctorow
- Pluralistic: Enshittification and Reverse Centaurs go global (29 Jul 2026) from Pluralistic: Daily links from Cory Doctorow
- AI Mania Is Eviscerating Global Decision-Making from Ludicity
- The default person from https://popagandhi.com/
Articles from blogs I follow around the net
just a couple of things
And I have, again, fallen into a trap where I only post long essays to my blog that take days or longer to write. Oh, so many drafts that really go nowhere, because I wasn’t writing to tell a story, I was writing to have something to post. And it...
via WIL WHEATON dot NET September 16, 2026“59.94Hz is standard on televisions in North America.”
A big screen carries with it different UI expectations, and how that manifests itself in Apple TV’s Settings app, is that there’s always room for an additional hint about the thing you’ve just selected. So yes, I have been exploring Apple TV’s Settings aft...
via Unsung September 16, 2026Pollution
Woke up. Went to gym. Lifted weights. Came back home. Showered. Had coffee. Turned on computer. Replied to some work stuff. Scrolled through some feeds. Highlights include “No way to find what I’m looking for, $service full of gen AI to prompt new slop, de...
via ttntm.me - Blog September 16, 2026Generated by openring