Skip to content

Scope endpoint list filters to the requesting product's references - #15760

Open
svader0 wants to merge 1 commit into
DefectDojo:bugfixfrom
svader0:harden-location-filter-join-scoping
Open

Scope endpoint list filters to the requesting product's references#15760
svader0 wants to merge 1 commit into
DefectDojo:bugfixfrom
svader0:harden-location-filter-join-scoping

Conversation

@svader0

@svader0 svader0 commented Aug 21, 2026

Copy link
Copy Markdown
Collaborator

Hardening and consistency improvement to the endpoint list filters under the V3 Locations feature.

A Location row is deduplicated across every product that records the same value, so a filter that reaches outward from the row can be satisfied through a reference that belongs to a different product. Each filter now matches against the requesting user's own references only. The list and host views keep their existing counts, ordering and product tab behaviour.

Adds a regression test. No functional change for a product that is the only one recording the value.

A Location is deduplicated across every product that references it, so the
endpoint list filters that join outward into products and findings can be
satisfied by a reference the caller is not authorized for. Authorizing the
result set afterwards is a separate filter() call, which Django compiles to a
second join, so the row still qualifies through the caller's own product and
the match through the other product's data stays observable.

Match each outward predicate against the caller's authorized references only,
using an Exists subquery over the reference model so the existing distinct and
annotation behaviour of the list and host views is unchanged.

Refs sc-14772
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant