[pull] main from guacsec:main - #243
Merged
Merged
Conversation
A user with only CreateAdvisory permission can upload an SBOM through the advisory endpoint by passing ?format=spdx, bypassing the CreateSbom permission check entirely. The test enables real authorization, creates a user with only create.advisory, and demonstrates that the SBOM endpoint correctly rejects the user (403) while the advisory endpoint accepts the SBOM upload (201) and stores it in the sbom table. Also introduces CallerBuilder to the fundamental test harness and caller_app_auth to test-context, enabling tests with custom Authorizer configurations. Assisted-by: Claude Code Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Change the test assertion to expect that the advisory endpoint rejects SBOM uploads via ?format=spdx when the user lacks CreateSbom. The test now fails while the bypass exists, and will pass once the fix is applied. Assisted-by: Claude Code Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
The advisory and SBOM upload endpoints accepted any Format variant via the ?format= query parameter, allowing a user with only CreateAdvisory to upload SBOMs (and vice versa). Add Format::ensure_allowed_for() that validates concrete formats against the endpoint's category using the existing matches_hint() logic, and call it in both upload handlers. Format::Unknown is mapped to the endpoint's default category so that ?format=unknown cannot widen detection beyond the endpoint's scope. Also adds NVD to the Advisory category in matches_hint(). Assisted-by: Claude Code Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Assisted-by: Claude Code
Inline the app initialization into CallerBuilder::build() so there is a single builder for test app setup. Remove caller_app_auth from test-context since the authorizer is now owned by CallerBuilder. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Assisted-by: Claude Code
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Assisted-by: Claude Code
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
See Commits and Changes for more details.
Created by
pull[bot] (v2.0.0-alpha.4)
Can you help keep this open source service alive? 💖 Please sponsor : )