mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
fix(coderd/workspaceapps): verify workspace owner matches app username (#26085)
fix(coderd/workspaceapps): verify workspace owner matches app username When resolving a workspace app by workspace UUID, the URL's username segment was never reconciled against the resolved workspace's owner. A user could serve their own workspace app from a hostname embedding another user's username, so the parsed origin username belonged to the victim. Combined with the username-equality CORS check, this allowed credentialed cross-origin reads of the victim's app responses. Reject the request with a 404 when the resolved workspace's owner does not match the user named in the request. Refs: https://linear.app/codercom/issue/PLAT-260
This commit is contained in:
@@ -248,6 +248,9 @@ func (r Request) getDatabase(ctx context.Context, db database.Store) (*databaseR
|
||||
)
|
||||
if workspaceID, uuidErr := uuid.Parse(r.WorkspaceNameOrID); uuidErr == nil {
|
||||
workspace, workspaceErr = db.GetWorkspaceByID(ctx, workspaceID)
|
||||
if workspaceErr == nil && workspace.OwnerID != user.ID {
|
||||
workspaceErr = sql.ErrNoRows
|
||||
}
|
||||
} else {
|
||||
workspace, workspaceErr = db.GetWorkspaceByOwnerIDAndName(ctx, database.GetWorkspaceByOwnerIDAndNameParams{
|
||||
OwnerID: user.ID,
|
||||
|
||||
Reference in New Issue
Block a user