get_accounts WHERE clause is unscoped by relay for the blocked branch #10
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
crud.py:309:SQL binds
ANDtighter thanOR, so this is(relay_id = :id AND allowed = :allowed) OR (blocked = :blocked). Theblockedbranch has no relay scope.GET /api/v1/account(views_api.py:190-205) defaults toallowed=False, blocked=True, so with defaults the query returns every blocked account in the whole extension, across every relay and operator, plus every non-allowed row of the caller's relay. The ownership check at:197-203does not help because the leak is through the unscoped branch.Impact: other tenants' blocked pubkey lists are disclosed to anyone owning a relay; the
allowed/blockedlisting semantics are wrong even for the caller's own relay.Fix direction:
WHERE relay_id = :id AND (allowed = :allowed OR blocked = :blocked). Add a two-relay test.Found during reforge run #1 (sandbox nostrrelay#4).