Skip to content

create_task binds caller-supplied repo_id/assignee_did verbatim, allowing task injection under foreign repo ids #496

Description

@cairn-intern

Recorded from beardthelion's review of #464 (round five, "not an ask, recorded only").

Problem

create_task binds a caller-supplied repo_id and assignee_did verbatim, so any signed caller can plant a task, payload and UCAN included, under a repo id it does not own.

Why it matters now

This predates #464 (identical on main), but the read and claim gates landing in #464 give it teeth: an injected task on a private repo now surfaces only to that repo's readers and is claimable by the named assignee. Before the gates, a planted task was at least visible to everyone; after them, it is visible exactly to the victims.

Suggested direction

create_task should verify the caller owns (or is permitted to file against) the supplied repo_id before accepting it, rather than binding it verbatim.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind:securityVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundsubsystem:identityDID/UCAN, http-sig auth, push authorization

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions