mirror of
https://github.com/parse-community/parse-server
synced 2026-08-09 13:03:18 +00:00
fix: Maintenance key blocked from querying protected fields (#10290)
This commit is contained in:
@@ -2368,4 +2368,37 @@ describe('ProtectedFields', function () {
|
||||
expect(response.data.secretField).toBeUndefined();
|
||||
});
|
||||
});
|
||||
|
||||
describe('maintenance auth', function () {
|
||||
it('should allow maintenance auth to query using protected fields as WHERE keys', async function () {
|
||||
await reconfigureServer({
|
||||
protectedFields: { _User: { '*': ['email', 'emailVerified'] } },
|
||||
protectedFieldsOwnerExempt: false,
|
||||
});
|
||||
|
||||
const user = new Parse.User();
|
||||
user.setUsername('testuser');
|
||||
user.setPassword('password');
|
||||
user.setEmail('test@example.com');
|
||||
await user.signUp();
|
||||
|
||||
// Query using a protected field as a WHERE key with maintenance auth
|
||||
const Auth = require('../lib/Auth');
|
||||
const Config = require('../lib/Config');
|
||||
const RestQuery = require('../lib/RestQuery');
|
||||
const config = Config.get('test');
|
||||
const maintenanceAuth = Auth.maintenance(config);
|
||||
const query = await RestQuery({
|
||||
method: RestQuery.Method.get,
|
||||
config,
|
||||
auth: maintenanceAuth,
|
||||
className: '_User',
|
||||
restWhere: { email: 'test@example.com' },
|
||||
runBeforeFind: false,
|
||||
});
|
||||
const result = await query.execute();
|
||||
expect(result.results.length).toBe(1);
|
||||
expect(result.results[0].objectId).toBe(user.id);
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
+1
-1
@@ -896,7 +896,7 @@ _UnsafeRestQuery.prototype.runCount = function () {
|
||||
};
|
||||
|
||||
_UnsafeRestQuery.prototype.denyProtectedFields = async function () {
|
||||
if (this.auth.isMaster) {
|
||||
if (this.auth.isMaster || this.auth.isMaintenance) {
|
||||
return;
|
||||
}
|
||||
const schemaController = await this.config.database.loadSchema();
|
||||
|
||||
Reference in New Issue
Block a user