Skip to content

Require testcase access before disclosing crash_query duplicates#5390

Open
herdiyana256 wants to merge 1 commit into
google:masterfrom
herdiyana256:fix-crash-query-cross-project-disclosure
Open

Require testcase access before disclosing crash_query duplicates#5390
herdiyana256 wants to merge 1 commit into
google:masterfrom
herdiyana256:fix-crash-query-cross-project-disclosure

Conversation

@herdiyana256

Copy link
Copy Markdown

crash_query's post handler passes project/crash_type/crash_state straight into find_testcase, which filters by those fields alone with no ownership check. Any authenticated user could pass an arbitrary project name and, if a matching open testcase existed there, get back its duplicate_id and bug_id.

The handler already called access.can_user_access_testcase before disclosing a match, but only when the testcase was security-flagged. Non-security-flagged testcases in any other project were disclosed unconditionally, regardless of whether the caller had any relationship to that project.

Applies the same access check regardless of the security flag, so a match is only disclosed to a caller who actually has access to that testcase (job/fuzzer ACL, uploader, or issue-tracker ownership) -- the same standard already used everywhere else a testcase gets shown to a user.

Added a test for the non-security-flagged cross-project case; the existing test only covered the security-flagged one.

crash_query's post handler passes project/crash_type/crash_state
straight into find_testcase, which filters by those fields alone with
no ownership check. Any authenticated user could pass an arbitrary
project name and, if a matching open testcase existed there, get back
its duplicate_id and bug_id.

The handler already called access.can_user_access_testcase before
disclosing a match, but only when the testcase was security-flagged.
Non-security-flagged testcases in any other project were disclosed
unconditionally.

Apply the same access check regardless of the security flag, so a
match is only disclosed to a caller who actually has access to that
testcase (job/fuzzer ACL, uploader, or issue-tracker ownership).

Added a test for the non-security-flagged cross-project case; the
existing test only covered the security-flagged one.
@herdiyana256
herdiyana256 requested a review from a team as a code owner July 25, 2026 16:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant