mirror of
https://github.com/makeplane/plane.git
synced 2026-09-01 11:38:37 +02:00
* [SECUR-242] fix(api): scope bulk-asset associate by uploader, not project_id Regression from #9288 (WEB-7776, cross-project IDOR scoping): adding project_id=project_id to ProjectBulkAssetEndpoint.post broke project creation — the "enable features" step 404s because the freshly-uploaded cover/feature asset still has project_id=NULL (this endpoint is what sets it). master had no such filter. Scope the lookup by created_by=request.user instead. This still closes the IDOR (#9288) — a caller can only touch assets they uploaded, and @allow_permission already scopes them to the project — and is stricter than the original master code (which had no ownership check), while allowing not-yet-associated assets to be linked. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * [SECUR-242] fix: bound bulk-asset associate to unassociated-or-same-project (CodeRabbit) Address CodeRabbit: created_by alone let a user move their own asset from another project into this one via the PROJECT_COVER/ISSUE_DESCRIPTION update branches. Add an unassociated-or-same-project bound (project_id=project_id OR project_id IS NULL) alongside created_by, so freshly-uploaded (NULL) assets still link but cross-project moves are rejected. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>