get_accounts WHERE clause is unscoped by relay for the blocked branch #10

Open
opened 2026-10-09 17:11:42 +00:00 by padreug · 0 comments
Owner

crud.py:309:

WHERE relay_id = :id AND allowed = :allowed OR blocked = :blocked

SQL binds AND tighter than OR, so this is (relay_id = :id AND allowed = :allowed) OR (blocked = :blocked). The blocked branch has no relay scope.

GET /api/v1/account (views_api.py:190-205) defaults to allowed=False, blocked=True, so with defaults the query returns every blocked account in the whole extension, across every relay and operator, plus every non-allowed row of the caller's relay. The ownership check at :197-203 does not help because the leak is through the unscoped branch.

Impact: other tenants' blocked pubkey lists are disclosed to anyone owning a relay; the allowed/blocked listing semantics are wrong even for the caller's own relay.

Fix direction: WHERE relay_id = :id AND (allowed = :allowed OR blocked = :blocked). Add a two-relay test.

Found during reforge run #1 (sandbox nostrrelay#4).

`crud.py:309`: ``` WHERE relay_id = :id AND allowed = :allowed OR blocked = :blocked ``` SQL binds `AND` tighter than `OR`, so this is `(relay_id = :id AND allowed = :allowed) OR (blocked = :blocked)`. The `blocked` branch has no relay scope. `GET /api/v1/account` (`views_api.py:190-205`) defaults to `allowed=False, blocked=True`, so with defaults the query returns every blocked account in the whole extension, across every relay and operator, plus every non-allowed row of the caller's relay. The ownership check at `:197-203` does not help because the leak is through the unscoped branch. Impact: other tenants' blocked pubkey lists are disclosed to anyone owning a relay; the `allowed`/`blocked` listing semantics are wrong even for the caller's own relay. Fix direction: `WHERE relay_id = :id AND (allowed = :allowed OR blocked = :blocked)`. Add a two-relay test. Found during reforge run #1 (sandbox nostrrelay#4).
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
aiolabs/nostrrelay#10
No description provided.