Conversation
Prevent tab, newline, and other ASCII control characters from appearing in S3 object keys generated from user-provided upload filenames. Fixes #9127 Co-authored-by: Cursor <cursoragent@cursor.com>
…ject_id (regression from #9288) (#9495) * [SECUR-242] fix(api): scope bulk-asset associate by uploader, not project_id Regression from #9288 (WEB-7776, cross-project IDOR scoping): adding project_id=project_id to ProjectBulkAssetEndpoint.post broke project creation — the "enable features" step 404s because the freshly-uploaded cover/feature asset still has project_id=NULL (this endpoint is what sets it). master had no such filter. Scope the lookup by created_by=request.user instead. This still closes the IDOR (#9288) — a caller can only touch assets they uploaded, and @allow_permission already scopes them to the project — and is stricter than the original master code (which had no ownership check), while allowing not-yet-associated assets to be linked. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * [SECUR-242] fix: bound bulk-asset associate to unassociated-or-same-project (CodeRabbit) Address CodeRabbit: created_by alone let a user move their own asset from another project into this one via the PROJECT_COVER/ISSUE_DESCRIPTION update branches. Add an unassociated-or-same-project bound (project_id=project_id OR project_id IS NULL) alongside created_by, so freshly-uploaded (NULL) assets still link but cross-project moves are rejected. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Contributor
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
pratapalakshmi
approved these changes
Jul 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This pull request improves security and correctness around file asset association and filename sanitization. The main changes are enhanced filtering to prevent cross-project or cross-user access to assets, and stricter filename sanitization to block all control characters, not just null bytes.
Security and access control improvements:
asset/v2.py, the asset association endpoint now only allows users to associate assets they uploaded themselves, and only if the asset is either unassociated or already in the target project. This prevents cross-project and cross-user Insecure Direct Object Reference (IDOR) attacks. ([apps/api/plane/app/views/asset/v2.pyL711-R724](https://github.com/makeplane/plane/pull/9496/files#diff-0cb3dd35f23f4dbfdda402de5c8e1cfe70e1725b87200a5320e25fe84b8e13e8L711-R724))Qobjects to combine project association filters for more precise query logic. ([apps/api/plane/app/views/asset/v2.pyR13](https://github.com/makeplane/plane/pull/9496/files#diff-0cb3dd35f23f4dbfdda402de5c8e1cfe70e1725b87200a5320e25fe84b8e13e8R13))Filename sanitization enhancements:
path_validator.py, thesanitize_filenamefunction now strips all ASCII control characters (0–31 and 127), not just null bytes, from user-supplied filenames, further reducing the risk of path traversal and other injection attacks. ([apps/api/plane/utils/path_validator.pyL18-R28](https://github.com/makeplane/plane/pull/9496/files#diff-8d1c38497efd8f3cddf8d440a1c217f4e47b1383ec114dbcaf9a59795f422617L18-R28))Type of Change
Screenshots and Media (if applicable)
Test Scenarios
References