Files
plane/apps
Manish Gupta 15e835710c [SECUR-242] fix(api): scope bulk-asset associate by uploader, not project_id (regression from #9288) (#9495)
* [SECUR-242] fix(api): scope bulk-asset associate by uploader, not project_id

Regression from #9288 (WEB-7776, cross-project IDOR scoping): adding
project_id=project_id to ProjectBulkAssetEndpoint.post broke project creation —
the "enable features" step 404s because the freshly-uploaded cover/feature asset
still has project_id=NULL (this endpoint is what sets it). master had no such
filter.

Scope the lookup by created_by=request.user instead. This still closes the IDOR
(#9288) — a caller can only touch assets they uploaded, and @allow_permission
already scopes them to the project — and is stricter than the original master
code (which had no ownership check), while allowing not-yet-associated assets to
be linked.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* [SECUR-242] fix: bound bulk-asset associate to unassociated-or-same-project (CodeRabbit)

Address CodeRabbit: created_by alone let a user move their own asset from another
project into this one via the PROJECT_COVER/ISSUE_DESCRIPTION update branches.
Add an unassociated-or-same-project bound (project_id=project_id OR project_id IS
NULL) alongside created_by, so freshly-uploaded (NULL) assets still link but
cross-project moves are rejected.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-29 12:16:05 +05:30
..
2026-07-28 15:50:53 +05:30
2026-07-28 15:50:53 +05:30
2026-07-28 15:50:53 +05:30
2026-07-28 15:50:53 +05:30