That UI Bug with Missing Data is a Security Issue
This is (sometimes) a development blog, so I am going to write about some failed development of mine since writing about success is much less interesting. You know that UI bug that someone added to your GitHub Issues where there is some missing data? You know the one, it only happens in production, all of your tests pass, and you marked it as a low priority. Yeah, that one. It’s probably a security bug and you should look into it right away. At least, that is the lesson I taught myself yet again when I began to research this bug.
before
<a id="shared_note.id)" href=""{{">
{{current_user.notes.filter_by(id=shared_note.id).first().title}}
</a>
after
<a href="{{ url_for('main.note', id=shared_note.note_id) }}">
{{current_user.notes.filter_by(id=shared_note.note_id).first().title}}
</a>
The difference is very subtle, but the key issue here is shared_note.id
vs shared_note.note_id
; I released a feature a few weeks ago that showed you all of the notes that you have shared. Locally everything worked fine, but I noticed later on, once it was in production, that the note title was not showing up. This is, of course, due to the fact that rather than showing the title of the note with the ID shared_note.note_id (the foreign key linking to the note) I was showing the title for the note with the primary key of shared_note.id. The reason why this is a security issue is because this allows someone to share a bunch of notes and start seeing the titles for notes that they do not own. The reason why this worked locally is because I am only testing with a single user, with a single notebook, with a single note, and with a single shared note. This means that in this specific case all of the Primary Keys and Foreign Keys are usually “1” so everything just happens to work.
Key Takeaways
- Always test with multiple users, make your local environment as similar to production as possible
- Consider using UUID instead of Auto Incrementing Integers, this would have been immediately caught if that was the case.
- “Partial Missing Data” == Security Bug (most of the time)
Thank you for reading! Share your thoughts with me on mastodon or via email.
Check out some more stuff to read down below.
Most popular posts this month
- Daggerversary
- SQLite DB Migrations with PRAGMA user_version
- Moving to New Jersey
- Setting up ANTLR4 on Windows
- Forbidden Words
Recent Favorite Blog Posts
This is a collection of the last 8 posts that I bookmarked.
- Pluralistic: What the fuck is a PBM? (23 Sep 2024) from Pluralistic: Daily links from Cory Doctorow
- The Framework 13 has a new high-res screen! from David Heinemeier Hansson
- 40 Thoughts At 40 from Blog – Brad Frost
- To Blog or to Social-Post from jwz
- Gotchas with SQLite in Production from Anže’s Blog
- Petter Reinholdtsen: More than 200 orphaned Debian packages moved to git, 216 to go from Planet Debian
- Eli Bendersky: You don't need virtualenv in Go from Planet Python
- Introducing Writebook from Jason Fried
Articles from blogs I follow around the net
OpenAI Twitter account once again hacked and used to promote scam token
The Twitter account belonging to OpenAI's news account was compromised and used to "announce" a scam website purporting to announce the $OPENAI token. "All OpenAI users are eligible to claim a piece of $OPENAI’s initi…
via Web3 is Going Just Great September 23, 2024DNA Lounge: Wherein a winnar is us!
As foretold by prophecy, you the people have once again declared DNA Lounge to be "Best Nightclub", and Hubba Hubba Revue to be "Best Burlesque" in the 2024 Best of the Bay! Also "Best Pizza" runner-up for DNA Pizza, and "Best D…
via jwz September 23, 2024SmashingConf NYC
I’m extremely excited to be a part of Smashing Conf NYC coming up on October 7-10. I’ll be: If you’re in NYC or able to make it there, I hope you’re able to make it!
via Blog – Brad Frost September 23, 2024Generated by openring