Skip to content

🛡️ Sentinel: [CRITICAL] Fix authorization bypass in file deletion endpoint#156

Open
xb1g wants to merge 1 commit into
mainfrom
sentinel-fix-file-deletion-bypass-3678801344530333967
Open

🛡️ Sentinel: [CRITICAL] Fix authorization bypass in file deletion endpoint#156
xb1g wants to merge 1 commit into
mainfrom
sentinel-fix-file-deletion-bypass-3678801344530333967

Conversation

@xb1g

@xb1g xb1g commented Mar 29, 2026

Copy link
Copy Markdown
Collaborator

🚨 Severity: CRITICAL
💡 Vulnerability: Insecure Direct Object Reference (IDOR) via path manipulation in the DELETE /api/upload endpoint. The code used fileName.includes(\submissions/${user.id}/`)to verify ownership, allowing an attacker to bypass authorization if their user ID appeared anywhere within a maliciously crafted file path. 🎯 Impact: Attackers could delete files belonging to other users if they correctly constructed a payload to bypass the.includescheck. 🔧 Fix: Changed.includesto.startsWithto strictly verify that the path begins with the authorized user's directory. ✅ Verification:pnpm testandpnpm lint` passed cleanly. Verified the logic mathematically guarantees strict prefix matching.


PR created automatically by Jules for task 3678801344530333967 started by @xb1g

…point

Co-authored-by: xb1g <70068561+xb1g@users.noreply.github.com>
@google-labs-jules

Copy link
Copy Markdown
Contributor

👋 Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

@vercel

vercel Bot commented Mar 29, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
pseed Ready Ready Preview, Comment Mar 29, 2026 3:57am

Copilot AI review requested due to automatic review settings May 11, 2026 17:28
@xb1g xb1g force-pushed the sentinel-fix-file-deletion-bypass-3678801344530333967 branch from 9e1d8e6 to 377ddd1 Compare May 11, 2026 17:28
@vercel

vercel Bot commented May 11, 2026

Copy link
Copy Markdown
Contributor

Unable to deploy a commit from a private repository on your GitHub organization to the wachaa1319's projects team on Vercel, which is currently on the Hobby plan. In order to deploy, you can:

  • Make your repository public or
  • Upgrade to Pro. A Pro subscription is required to deploy from a private organization repository.

To read more about collaboration on Vercel, click here.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes an authorization bypass (IDOR via path manipulation) in the DELETE /api/upload endpoint by tightening the ownership check from a substring match to a strict prefix match, ensuring a user can only delete objects stored under their own submissions/<userId>/... keyspace.

Changes:

  • Replaced fileName.includes(...) with fileName.startsWith(...) for strict ownership validation on delete.
  • Prevents crafted keys that merely contain submissions/<userId>/ from passing authorization.

@xb1g xb1g force-pushed the sentinel-fix-file-deletion-bypass-3678801344530333967 branch 2 times, most recently from 2391f03 to bb14073 Compare May 11, 2026 17:39
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented May 11, 2026

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
❌ Deployment failed
View logs
web bb14073 May 11 2026, 06:27 PM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants