Use a valid PUT body in the admin authorization matrix #271

Closed
opened 2026-09-27 21:10:14 +00:00 by kayg · 1 comment
Owner

Evidence

The authorization matrix reported that a standard User's PUT to /api/v1/admin/config returned 422 where the matrix expected 403.

The probe obtains the request body from GET /api/v1/admin/config as the Owner. GET returns AdminConfigView, while PUT deserializes InstanceConfig. The invalid request body can fail in Axum's JSON extractor before the handler calls the admin authorization check. This result does not show that an unauthorized update succeeded.

Please make the matrix send a valid InstanceConfig body for the standard User, then assert that the request returns 403 and does not change the configuration. Keep the current invalid-body case as a separate validation check if useful.

## Evidence The authorization matrix reported that a standard User's PUT to /api/v1/admin/config returned 422 where the matrix expected 403. The probe obtains the request body from GET /api/v1/admin/config as the Owner. GET returns AdminConfigView, while PUT deserializes InstanceConfig. The invalid request body can fail in Axum's JSON extractor before the handler calls the admin authorization check. This result does not show that an unauthorized update succeeded. Please make the matrix send a valid InstanceConfig body for the standard User, then assert that the request returns 403 and does not change the configuration. Keep the current invalid-body case as a separate validation check if useful.
Author
Owner

Fixed in 0a34b1592 on origin/dev: tests/adversarial/authz_matrix.py now builds a valid InstanceConfig body for PUT /api/v1/admin/config. The standard-User replay recorded on #275 reached the authorization guard and returned 403.

Fixed in 0a34b1592 on origin/dev: tests/adversarial/authz_matrix.py now builds a valid InstanceConfig body for PUT /api/v1/admin/config. The standard-User replay recorded on #275 reached the authorization guard and returned 403.
kayg closed this issue 2026-10-03 12:41:37 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#271
No description provided.