Skip to content

Align the merge finding action with the object-level permission check - #16027

Merged
Maffooch merged 1 commit into
DefectDojo:bugfixfrom
svader0:h1-4032822-merge-delete-authz
Sep 23, 2026
Merged

Maffooch merged 1 commit into
DefectDojo:bugfixfrom
svader0:h1-4032822-merge-delete-authz

Conversation

@svader0

@svader0 svader0 commented Sep 21, 2026

Copy link
Copy Markdown
Collaborator

Hardening / consistency improvement to the finding merge view's permission checks.

One branch of the merge Finding Action selector acted on a stricter intent than the check in front of the route, so it accepted callers that the sibling routes for the same action already refuse. This adds the matching object-level check, plus regression tests.

The check runs before the merge writes anything, so a refusal cannot leave work half applied. No functional change for correctly-permissioned users, and the other branch of the same selector is untouched.

Tested: unittests.test_bulk_finding_authorization 10/10, unittests.test_merge_findings_locations and unittests.test_finding_template_merge_endpoints_v3 6/6, on both the DD_V3_FEATURE_LOCATIONS true and false legs.

One branch of the merge view acted on a stricter intent than the check in
front of it, so it accepted callers the sibling routes for the same action
already refuse. The check runs before the merge writes anything, so a
refusal cannot leave work half applied. Behaviour for correctly
permissioned callers is unchanged, including the other branch of the same
selector.

Adds regression tests for the refusal, for the unaffected branch, and for
the permitted caller.
@Maffooch Maffooch added this to the 3.3.300 milestone Sep 23, 2026
@Maffooch
Maffooch added this pull request to the merge queue Sep 23, 2026
Merged via the queue into DefectDojo:bugfix with commit 3d7300d Sep 23, 2026
47 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants