Skip to content

Apply the tool-configuration permission check in the shared serializer guard - #15650

Open
svader0 wants to merge 1 commit into
DefectDojo:bugfixfrom
svader0:harden-api-scan-configuration-tool-guard
Open

Apply the tool-configuration permission check in the shared serializer guard#15650
svader0 wants to merge 1 commit into
DefectDojo:bugfixfrom
svader0:harden-api-scan-configuration-tool-guard

Conversation

@svader0

@svader0 svader0 commented Aug 12, 2026

Copy link
Copy Markdown
Collaborator

Hardening / consistency improvement to API object permission checks. Moves an existing
authorization check out of a single serializer and into the shared serializer-guard module, so it
applies to every serializer that writes the field rather than to one of them. Adds regression
tests.

No functional change for correctly-permissioned users.

… guard

The check lived on a single serializer. It now sits with the other serializer
guards and is applied to every serializer that writes the field, so a second
serializer over the same model cannot be added without it. Adds regression
tests.
@dryrunsecurity

Copy link
Copy Markdown

DryRun Security

This pull request contains a critical finding where a sensitive authorization file was modified by an unauthorized author.

🔴 Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/authorization/serializer_guards.py (drs_a6d70c7f)
Vulnerability Configured Sensitive Codepath Modified by Non-Allowed Author
Description File 'dojo/authorization/serializer_guards.py' matches configured sensitive codepath pattern 'dojo/authorization/*.py' and was modified by 'svader0' (commit 76ceb19) who is not in the allowed authors list.

We've notified @mtesauro.


Comment to provide feedback on these findings.

Report false positive: @dryrunsecurity fp [FINDING ID] [FEEDBACK]
Report low-impact: @dryrunsecurity nit [FINDING ID] [FEEDBACK]

Example: @dryrunsecurity fp drs_90eda195 This code is not user-facing

All finding details can be found in the DryRun Security Dashboard.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant