Skip to content

v1.4.0-fixes - #9496

Merged
mguptahub merged 2 commits into
canaryfrom
preview
Jul 29, 2026
Merged

v1.4.0-fixes#9496
mguptahub merged 2 commits into
canaryfrom
preview

Conversation

@mguptahub

Copy link
Copy Markdown
Collaborator

Description

This pull request improves security and correctness around file asset association and filename sanitization. The main changes are enhanced filtering to prevent cross-project or cross-user access to assets, and stricter filename sanitization to block all control characters, not just null bytes.

Security and access control improvements:

  • In asset/v2.py, the asset association endpoint now only allows users to associate assets they uploaded themselves, and only if the asset is either unassociated or already in the target project. This prevents cross-project and cross-user Insecure Direct Object Reference (IDOR) attacks. ([apps/api/plane/app/views/asset/v2.pyL711-R724](https://github.com/makeplane/plane/pull/9496/files#diff-0cb3dd35f23f4dbfdda402de5c8e1cfe70e1725b87200a5320e25fe84b8e13e8L711-R724))
  • Added usage of Django's Q objects to combine project association filters for more precise query logic. ([apps/api/plane/app/views/asset/v2.pyR13](https://github.com/makeplane/plane/pull/9496/files#diff-0cb3dd35f23f4dbfdda402de5c8e1cfe70e1725b87200a5320e25fe84b8e13e8R13))

Filename sanitization enhancements:

  • In path_validator.py, the sanitize_filename function now strips all ASCII control characters (0–31 and 127), not just null bytes, from user-supplied filenames, further reducing the risk of path traversal and other injection attacks. ([apps/api/plane/utils/path_validator.pyL18-R28](https://github.com/makeplane/plane/pull/9496/files#diff-8d1c38497efd8f3cddf8d440a1c217f4e47b1383ec114dbcaf9a59795f422617L18-R28))

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • Feature (non-breaking change which adds functionality)
  • Improvement (change that would cause existing functionality to not work as expected)
  • Code refactoring
  • Performance improvements
  • Documentation update

Screenshots and Media (if applicable)

Test Scenarios

References

karthiksuki and others added 2 commits July 28, 2026 17:52
Prevent tab, newline, and other ASCII control characters from appearing
in S3 object keys generated from user-provided upload filenames.

Fixes #9127

Co-authored-by: Cursor <cursoragent@cursor.com>
…ject_id (regression from #9288) (#9495)

* [SECUR-242] fix(api): scope bulk-asset associate by uploader, not project_id

Regression from #9288 (WEB-7776, cross-project IDOR scoping): adding
project_id=project_id to ProjectBulkAssetEndpoint.post broke project creation —
the "enable features" step 404s because the freshly-uploaded cover/feature asset
still has project_id=NULL (this endpoint is what sets it). master had no such
filter.

Scope the lookup by created_by=request.user instead. This still closes the IDOR
(#9288) — a caller can only touch assets they uploaded, and @allow_permission
already scopes them to the project — and is stricter than the original master
code (which had no ownership check), while allowing not-yet-associated assets to
be linked.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* [SECUR-242] fix: bound bulk-asset associate to unassociated-or-same-project (CodeRabbit)

Address CodeRabbit: created_by alone let a user move their own asset from another
project into this one via the PROJECT_COVER/ISSUE_DESCRIPTION update branches.
Add an unassociated-or-same-project bound (project_id=project_id OR project_id IS
NULL) alongside created_by, so freshly-uploaded (NULL) assets still link but
cross-project moves are rejected.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings July 29, 2026 06:47

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@coderabbitai

coderabbitai Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 00325683-8ece-4b95-882a-2809f53f8f5e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@mguptahub
mguptahub merged commit ff4bf5d into canary Jul 29, 2026
21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants