mirror of
https://github.com/parse-community/parse-server
synced 2026-08-09 13:03:18 +00:00
fix: Endpoint /loginAs allows readOnlyMasterKey to gain full read and write access as any user ([GHSA-79wj-8rqv-jvp5](https://github.com/parse-community/parse-server/security/advisories/GHSA-79wj-8rqv-jvp5)) (#10099)
This commit is contained in:
@@ -1364,6 +1364,32 @@ describe('read-only masterKey', () => {
|
||||
expect(res.data.error).toBe('Permission denied');
|
||||
}
|
||||
});
|
||||
|
||||
it('should throw when trying to loginAs with readOnlyMasterKey', async () => {
|
||||
// Create a target user
|
||||
await Parse.User.signUp('readonly-loginas-test', 'password123');
|
||||
const userId = Parse.User.current().id;
|
||||
await Parse.User.logOut();
|
||||
|
||||
// Attempt loginAs with readOnlyMasterKey — should be rejected
|
||||
loggerErrorSpy.calls.reset();
|
||||
try {
|
||||
await request({
|
||||
method: 'POST',
|
||||
url: `${Parse.serverURL}/loginAs`,
|
||||
headers: {
|
||||
'X-Parse-Application-Id': Parse.applicationId,
|
||||
'X-Parse-Master-Key': 'read-only-test',
|
||||
'Content-Type': 'application/json',
|
||||
},
|
||||
body: { userId },
|
||||
});
|
||||
fail('should have thrown');
|
||||
} catch (res) {
|
||||
expect(res.data.code).toBe(Parse.Error.OPERATION_FORBIDDEN);
|
||||
expect(res.data.error).toBe('Permission denied');
|
||||
}
|
||||
});
|
||||
});
|
||||
|
||||
describe('rest context', () => {
|
||||
|
||||
@@ -341,6 +341,13 @@ export class UsersRouter extends ClassesRouter {
|
||||
req.config
|
||||
);
|
||||
}
|
||||
if (req.auth.isReadOnly) {
|
||||
throw createSanitizedError(
|
||||
Parse.Error.OPERATION_FORBIDDEN,
|
||||
"read-only masterKey isn't allowed to login as another user.",
|
||||
req.config
|
||||
);
|
||||
}
|
||||
|
||||
const userId = req.body?.userId || req.query.userId;
|
||||
if (!userId) {
|
||||
|
||||
Reference in New Issue
Block a user