Scope endpoint list filters to the requesting product's references - #15760
Open
svader0 wants to merge 1 commit into
Open
Scope endpoint list filters to the requesting product's references#15760svader0 wants to merge 1 commit into
svader0 wants to merge 1 commit into
Conversation
A Location is deduplicated across every product that references it, so the endpoint list filters that join outward into products and findings can be satisfied by a reference the caller is not authorized for. Authorizing the result set afterwards is a separate filter() call, which Django compiles to a second join, so the row still qualifies through the caller's own product and the match through the other product's data stays observable. Match each outward predicate against the caller's authorized references only, using an Exists subquery over the reference model so the existing distinct and annotation behaviour of the list and host views is unchanged. Refs sc-14772
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Hardening and consistency improvement to the endpoint list filters under the V3 Locations feature.
A Location row is deduplicated across every product that records the same value, so a filter that reaches outward from the row can be satisfied through a reference that belongs to a different product. Each filter now matches against the requesting user's own references only. The list and host views keep their existing counts, ordering and product tab behaviour.
Adds a regression test. No functional change for a product that is the only one recording the value.