Manish Gupta 7cecb466d3 fix(security): refuse routed actions served by unauthorized DRF mixins
Authorization in the app viewsets lives on the concrete method — an
@allow_permission decorator or an inline role check. BaseViewSet subclasses
DRF's ModelViewSet, which supplies list/retrieve/create/update/partial_update/
destroy for free, so when a URLconf maps a verb to an action the viewset does
not implement, the request is served by the mixin with nothing but the bare
default permission class. The caller is authenticated but not authorized at
all, and the only thing between them and the object is whatever get_queryset()
happens to filter on.

Measured across the live URLconf: 225 routed actions, 27 of which resolved to
a mixin under the bare default. The worst let any authenticated account with no
membership in the target workspace rewrite a project it could not otherwise
read — including its `workspace` field, since ProjectListSerializer declares
fields="__all__" with no read_only_fields — re-parenting the project into the
caller's own workspace. Others allowed overwriting or soft-deleting work items
and comments with no activity record or webhook, reading project invitation
tokens, and creating views in arbitrary workspaces by guessable slug.

Guard it structurally in BaseViewSet.initial(): if the resolved action is one
DRF's mixins provide and nothing in our own MRO implements it, refuse with 405
rather than letting the mixin operate. Three shapes are deliberately exempt —
a custom @action, a perform_create override riding CreateModelMixin, and a
viewset carrying a genuinely restrictive permission class. Permission classes
are membership-tested rather than compared against the default, so a weaker
declaration ([AllowAny], or an empty list) is not mistaken for a deliberate
restrictive one.

Point-fixing these one endpoint at a time is what produced two reports of the
same class nine days apart, and it does not hold: of the routes that were not
exploitable, most failed closed on an accident — a missing pk kwarg, or a
decorator applied to a perform_create signature so it crashed before inserting
— rather than on authorization. One lookup_url_kwarg change re-arms them.

Also implements the five actions that clients do call and that were relying on
a mixin, so they carry the same check as their siblings rather than being
refused: issue and comment reaction list, project and workspace view create,
workspace invitation list, and state retrieve.

A contract test drives the real guard over Django's own resolver and asserts
the refused set matches a reviewed manifest, in both directions, so a newly
routed verb fails here instead of shipping unauthorized — and a fixed one
cannot rot the list. A second manifest covers plane.api and plane.space, which
define their own duplicated BaseViewSet and are not reached by this guard.

Co-authored-by: Plane AI <noreply@plane.so>
2026-08-27 11:02:37 +05:30



Plane Logo

Modern project management for all teams

WebsiteForumXDocumentation

Plane Screens

Meet Plane, an open-source project management tool to track issues, run sprints cycles, and manage product roadmaps without the chaos of managing the tool itself. 🧘‍♀️

Plane is evolving every day. Your suggestions, ideas, and reported bugs help us immensely. Do not hesitate to join in the conversation on Forum or raise a GitHub issue. We read everything and respond to most.

🚀 Installation

Getting started with Plane is simple. Choose the setup that works best for you:

  • Plane Cloud Sign up for a free account on Plane Cloud—it's the fastest way to get up and running without worrying about infrastructure.

  • Self-host Plane Prefer full control over your data and infrastructure? Install and run Plane on your own servers. Follow our detailed deployment guides to get started.

Installation methods Docs link
Docker Docker
Kubernetes Kubernetes
Managed hosting Deploy with Zenith

Instance admins can configure instance settings with God mode.

🌟 Features

  • Work Items Efficiently create and manage tasks with a robust rich text editor that supports file uploads. Enhance organization and tracking by adding sub-properties and referencing related issues.

  • Cycles Maintain your teams momentum with Cycles. Track progress effortlessly using burn-down charts and other insightful tools.

  • Modules Simplify complex projects by dividing them into smaller, manageable modules.

  • Views Customize your workflow by creating filters to display only the most relevant issues. Save and share these views with ease.

  • Pages Capture and organize ideas using Plane Pages, complete with AI capabilities and a rich text editor. Format text, insert images, add hyperlinks, or convert your notes into actionable items.

  • Analytics Access real-time insights across all your Plane data. Visualize trends, remove blockers, and keep your projects moving forward.

🛠️ Local development

See CONTRIBUTING

⚙️ Built with

React Router Django Node JS

📸 Screenshots

Plane Views

Plane Cycles and Modules

Plane Analytics

Plane Pages

📝 Documentation

Explore Plane's product documentation and developer documentation to learn about features, setup, and usage.

❤️ Community

Join the Plane community on GitHub Discussions and our Forum. We follow a Code of conduct in all our community channels.

Feel free to ask questions, report bugs, participate in discussions, share ideas, request features, or showcase your projects. Wed love to hear from you!

🛡️ Security

If you discover a security vulnerability in Plane, please report it responsibly instead of opening a public issue. We take all legitimate reports seriously and will investigate them promptly. See Security policy for more info.

To disclose any security issues, please email us at security@plane.so.

🤝 Contributing

There are many ways you can contribute to Plane:

Please read CONTRIBUTING.md for details on the process for submitting pull requests to us.

Repo activity

Plane Repo Activity

We couldn't have done this without you.

License

This project is licensed under the GNU Affero General Public License v3.0.

Description
🔥 🔥 🔥 Open Source JIRA, Linear, Monday, and Asana Alternative. Plane helps you track your issues, epics, and cycles the easiest way on the planet. plane.so
Readme 473 MiB
Languages
TypeScript 69.6%
Python 26.6%
HTML 2.4%
JavaScript 0.6%
Shell 0.5%
Other 0.3%