The project-membership rule for asset access lived as a method on
WorkspaceFileAssetEndpoint with three call sites. Every other asset route is a
sibling BaseAPIView subclass and therefore could not reach it, so four
workspace-level routes in the app and the whole external-API asset surface
resolved assets on the workspace alone. A workspace member or guest belonging to
none of the asset's projects could download another project's uploads, copy them
into a project they controlled, reverse a deletion its owner performed, probe
for asset ids, and flip is_uploaded to take an attachment offline.
Move the rule onto the model as FileAsset.is_project_accessible_to so any
surface that can load a FileAsset can ask the question, and a route added later
cannot silently omit it -- which is how this gap arose.
app/views/asset/v2.py
- AssetRestoreEndpoint.post, AssetCheckEndpoint.get,
WorkspaceAssetDownloadEndpoint.get and DuplicateAssetEndpoint.post now check
the asset's project. Check answers exists=false rather than confirming a
foreign asset, so it stops being a cross-project existence oracle.
- DuplicateAssetEndpoint also requires active membership of the destination
project from the request body; existence in the workspace was being treated
as authorization.
api/views/asset.py
- GenericAssetEndpoint.get and .patch gained the same check. is_uploaded gates
every download path, so an unscoped patch is a takedown primitive.
- .post validates the body-supplied project_id against the URL workspace and
the caller's membership; it was stored unvalidated, so a row in one
workspace could point at a project in another -- exactly the inconsistency
the access check has to defend against downstream.
Also fixes three unconditional 500s in the same file: S3Storage.__init__ is
(self, request=None) and never accepted is_server, so S3Storage(request=request,
is_server=True) at :338, :451 and :581 raised TypeError for every caller.
Passing no request is what selects the internal endpoint, making the keyword
both wrong and redundant. This ships with the authorization checks on purpose:
repairing the crash alone would have exposed a cross-project asset read on a
route that currently only looks harmless.
Contract tests cover each route from a non-member, a member, and a
workspace-level asset whose project_id is NULL, so the fix cannot over-reach.
The external-API positive paths patch S3Storage with autospec=True so the
constructor signature is validated and the crash cannot regress unnoticed.
Adds plane/tests/contract/api/conftest.py to reset the ApiKeyRateThrottle bucket
around each external-API contract test. That throttle keys on the token string,
which is a constant across the package, so all of those tests shared one
60/minute budget for the whole run. Adding tests here pushed the package past it
and produced 429s in unrelated files. Only this throttle's key is cleared,
following the existing narrowly-scoped auth-throttle helper rather than
cache.clear().
Co-authored-by: Plane AI <noreply@plane.so>
Modern project management for all teams
Website • Forum • X • Documentation
Meet Plane, an open-source project management tool to track issues, run sprints cycles, and manage product roadmaps without the chaos of managing the tool itself. 🧘♀️
Plane is evolving every day. Your suggestions, ideas, and reported bugs help us immensely. Do not hesitate to join in the conversation on Forum or raise a GitHub issue. We read everything and respond to most.
🚀 Installation
Getting started with Plane is simple. Choose the setup that works best for you:
-
Plane Cloud Sign up for a free account on Plane Cloud—it's the fastest way to get up and running without worrying about infrastructure.
-
Self-host Plane Prefer full control over your data and infrastructure? Install and run Plane on your own servers. Follow our detailed deployment guides to get started.
| Installation methods | Docs link |
|---|---|
| Docker | |
| Kubernetes | |
| Managed hosting |
Instance admins can configure instance settings with God mode.
🌟 Features
-
Work Items Efficiently create and manage tasks with a robust rich text editor that supports file uploads. Enhance organization and tracking by adding sub-properties and referencing related issues.
-
Cycles Maintain your team’s momentum with Cycles. Track progress effortlessly using burn-down charts and other insightful tools.
-
Modules Simplify complex projects by dividing them into smaller, manageable modules.
-
Views Customize your workflow by creating filters to display only the most relevant issues. Save and share these views with ease.
-
Pages Capture and organize ideas using Plane Pages, complete with AI capabilities and a rich text editor. Format text, insert images, add hyperlinks, or convert your notes into actionable items.
-
Analytics Access real-time insights across all your Plane data. Visualize trends, remove blockers, and keep your projects moving forward.
🛠️ Local development
See CONTRIBUTING
⚙️ Built with
📸 Screenshots
📝 Documentation
Explore Plane's product documentation and developer documentation to learn about features, setup, and usage.
❤️ Community
Join the Plane community on GitHub Discussions and our Forum. We follow a Code of conduct in all our community channels.
Feel free to ask questions, report bugs, participate in discussions, share ideas, request features, or showcase your projects. We’d love to hear from you!
🛡️ Security
If you discover a security vulnerability in Plane, please report it responsibly instead of opening a public issue. We take all legitimate reports seriously and will investigate them promptly. See Security policy for more info.
To disclose any security issues, please email us at security@plane.so.
🤝 Contributing
There are many ways you can contribute to Plane:
- Report bugs or submit feature requests.
- Review the documentation and submit pull requests to improve it—whether it's fixing typos or adding new content.
- Talk or write about Plane or any other ecosystem integration and let us know!
- Show your support by upvoting popular feature requests.
Please read CONTRIBUTING.md for details on the process for submitting pull requests to us.
Repo activity
We couldn't have done this without you.
License
This project is licensed under the GNU Affero General Public License v3.0.