Page MenuHomePhabricator

Fix a policy issue where permissions were not properly checked when disabling global builtin queries
ClosedPublic

Authored by epriestley on May 31 2022, 5:59 PM.
Tags
None
Referenced Files
F15506418: D21851.diff
Tue, Apr 15, 11:08 AM
F15492702: D21851.diff
Sat, Apr 12, 5:23 PM
F15486999: D21851.id.diff
Thu, Apr 10, 10:29 AM
F15483388: D21851.diff
Wed, Apr 9, 12:02 PM
F15450982: D21851.id52081.diff
Fri, Mar 28, 7:27 PM
F15450980: D21851.id52080.diff
Fri, Mar 28, 7:26 PM
F15450979: D21851.id.diff
Fri, Mar 28, 7:25 PM
F15439096: D21851.diff
Wed, Mar 26, 5:44 AM
Subscribers
None

Details

Summary

See https://hackerone.com/reports/1573143. The pathway for disabling global builtin queries is missing a policy check. Add it.

Test Plan
  • Accessed the "/search/delete/id/.../" URI for a global builtin query as a non-administrator.
  • Before patch: could improperly disable queries. -After patch: proper policy exception.

Diff Detail

Repository
rP Phabricator
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

epriestley created this revision.
This revision was not accepted when it landed; it landed in state Needs Review.May 31 2022, 6:00 PM
This revision was automatically updated to reflect the committed changes.