Skip to content

api(bounties): aggregates ignore repo visibility, exposing private-repo activity #477

Description

@euxaristia

Summary

bounty_stats and agent_bounty_stats (crates/gitlawb-node/src/api/bounties.rs:460-502) run unfiltered aggregates over all bounties (crates/gitlawb-node/src/db/mod.rs:4530-4565) with no repo-read gating. The sibling stats endpoint was deliberately scoped to anonymously listable repos (#104, server.rs:546-570), and row-level bounty routes are visibility-gated; these two aggregates were not updated.

Impact

An anonymous caller can infer private-repo bounty activity from aggregate deltas and read per-agent earnings totals. No repo identity is disclosed; aggregate-granularity signal only.

Remediation

  1. Restrict both aggregates to anonymously readable repos (mirror Unauthenticated GET /api/v1/stats leaks the count of private/mode-A repos (count oracle) #104) or gate the routes.

Proposed labels: kind:security, crate:node, subsystem:api.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    crate:nodegitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningsev:mediumDegraded but workaround existssubsystem:apiNode REST API request/response surfacesubsystem:visibilityPath-scoped visibility and content withholding

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions