Admin config validation responds before role denial #276

Closed
opened 2026-09-27 21:58:32 +00:00 by kayg · 1 comment
Owner

Evidence

The real-server authorization matrix made 936 requests across 234 OpenAPI operations and four identities. As a standard User, PUT /api/v1/admin/config returned 422 where the matrix expected 403.

Impact

This probe did not gain access. The response suggests request validation runs before the role check, so a non-admin can distinguish malformed or invalid input from a denied request. Keep the status consistent with the permission boundary.

Reproduction

Run tests/adversarial/run.sh with the authz matrix enabled. The failure is reported by tests/adversarial/authz_matrix.py for PUT /api/v1/admin/config as a standard User.

Found during the final adversarial round for #243 after merging dev.

### Evidence The real-server authorization matrix made 936 requests across 234 OpenAPI operations and four identities. As a standard User, `PUT /api/v1/admin/config` returned 422 where the matrix expected 403. ### Impact This probe did not gain access. The response suggests request validation runs before the role check, so a non-admin can distinguish malformed or invalid input from a denied request. Keep the status consistent with the permission boundary. ### Reproduction Run `tests/adversarial/run.sh` with the authz matrix enabled. The failure is reported by `tests/adversarial/authz_matrix.py` for `PUT /api/v1/admin/config` as a standard User. Found during the final adversarial round for #243 after merging `dev`.
Author
Owner

The authorization-before-body-extraction test passes: anonymous and non-admin callers are distinguished before malformed request bodies are parsed. Added an adversarial member request with invalid TOML and an exact 403 expectation; the single planned API adversarial round will exercise it against the real server.

The authorization-before-body-extraction test passes: anonymous and non-admin callers are distinguished before malformed request bodies are parsed. Added an adversarial member request with invalid TOML and an exact 403 expectation; the single planned API adversarial round will exercise it against the real server.
kayg closed this issue 2026-09-29 08:29:16 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#276
No description provided.