Skip to main content

Command Palette

Search for a command to run...

Assigning a task should check that the assignee can see it

Updated
•1 min read•View as Markdown
A
Practical lessons on auth, authorization, and access control.

Most "assign" endpoints check one thing: can the caller edit this task? If yes, PATCH /tasks/88 {"assignee_id": 512} goes through.

Nobody asks whether user 512 can see task 88. In a multi-tenant app the assignee picker usually filters by workspace, but the API often takes any user id it's given. So a crafted request can assign a private task to someone outside the project, or outside the tenant. Then the assignment email, the "assigned to me" list, and the mobile push all show that person a title and description they were never allowed to read.

Check the assignee on the server. Before saving, run the same read check you'd run if user 512 opened /tasks/88 themselves, and reject the request with a 422 if it fails. Do the same for watchers, reviewers, and any other field that holds a user id and causes the app to show that user the record.

To test it, create a private project, then send the assign request with a user id from a second workspace. If it saves, the check is missing.