Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Pull Request check-list
To ensure your Pull Request can be accepted as fast as possible, make sure to review and check all of these items:
npm test
on both front/server)npm run eslint
on both front/server)npm run prettier
on both front/server)npm run compare-translations
on front)front/src/config/demo.js
) so that the demo website is working without a backend? (if needed) See https://demo.gladysassistant.com.NOTE: these things are not required to open a PR and can be done afterwards / while the PR is open.
Description of change
This is a quick fix for a privilege escalation vulnerability reported privately through the security.md process.
The /api/v1/me endpoint is called when updating/saving a users profile. This endpoints route handling is vulnerable to mass assignment which means, changing the role parameter from “user” to “admin” while submitting a save profile request will change your role to admin. This lets you have full control to the Gladys and could even kick out the original administrator. This fix is to delete the role parameter before passing it to the update function. A more robust solution in the future will be to use options.fields from here https://sequelize.org/api/v6/class/src/model.js~model#static-method-update to allowlist what fields can be updated.