Page MenuHomePhabricator

Fix a policy issue where permissions were not properly checked when disabling global builtin queries
ClosedPublic

Authored by epriestley on May 31 2022, 5:59 PM.
Tags
None
Referenced Files
F19515412: D21851.diff
Wed, Jan 14, 11:10 AM
F19152554: D21851.diff
Dec 11 2025, 3:33 AM
F19152046: D21851.id52081.diff
Dec 11 2025, 12:21 AM
F19151956: D21851.id52081.diff
Dec 10 2025, 11:50 PM
F19127016: D21851.id52080.diff
Dec 10 2025, 3:14 AM
F19125261: D21851.id52080.diff
Dec 10 2025, 1:44 AM
F19068653: D21851.diff
Nov 30 2025, 12:28 PM
F19065712: D21851.diff
Nov 30 2025, 2:53 AM
Subscribers
None

Details

Summary

See https://hackerone.com/reports/1573143. The pathway for disabling global builtin queries is missing a policy check. Add it.

Test Plan
  • Accessed the "/search/delete/id/.../" URI for a global builtin query as a non-administrator.
  • Before patch: could improperly disable queries. -After patch: proper policy exception.

Diff Detail

Repository
rP Phabricator
Branch
query1
Lint
Lint Passed
Unit
Tests Passed
Build Status
Buildable 25759
Build 35587: arc lint + arc unit

Event Timeline

epriestley created this revision.
This revision was not accepted when it landed; it landed in state Needs Review.May 31 2022, 6:00 PM
This revision was automatically updated to reflect the committed changes.