fix: Endpoint /loginAs allows readOnlyMasterKey to gain full read and write access as any user ([GHSA-79wj-8rqv-jvp5](https://github.com/parse-community/parse-server/security/advisories/GHSA-79wj-8rqv-jvp5)) (#10099)

This commit is contained in:
Manuel
2026-03-05 02:28:05 +00:00
committed by GitHub
parent bfe11c4917
commit 0c940b7089
2 changed files with 33 additions and 0 deletions
+26
View File
@@ -1364,6 +1364,32 @@ describe('read-only masterKey', () => {
expect(res.data.error).toBe('Permission denied');
}
});
it('should throw when trying to loginAs with readOnlyMasterKey', async () => {
// Create a target user
await Parse.User.signUp('readonly-loginas-test', 'password123');
const userId = Parse.User.current().id;
await Parse.User.logOut();
// Attempt loginAs with readOnlyMasterKey — should be rejected
loggerErrorSpy.calls.reset();
try {
await request({
method: 'POST',
url: `${Parse.serverURL}/loginAs`,
headers: {
'X-Parse-Application-Id': Parse.applicationId,
'X-Parse-Master-Key': 'read-only-test',
'Content-Type': 'application/json',
},
body: { userId },
});
fail('should have thrown');
} catch (res) {
expect(res.data.code).toBe(Parse.Error.OPERATION_FORBIDDEN);
expect(res.data.error).toBe('Permission denied');
}
});
});
describe('rest context', () => {
+7
View File
@@ -341,6 +341,13 @@ export class UsersRouter extends ClassesRouter {
req.config
);
}
if (req.auth.isReadOnly) {
throw createSanitizedError(
Parse.Error.OPERATION_FORBIDDEN,
"read-only masterKey isn't allowed to login as another user.",
req.config
);
}
const userId = req.body?.userId || req.query.userId;
if (!userId) {