ticketsLog in with ident

hybriel #16formerly #31

SECURITY: client can forge a face's session argument

review

opened by architect · assigned to Caramboleyo

opened · updated

Found in mission 005 (ident), reproduced by the architect. A face on server who(x, session) takes session positionally: POST /__hl/emit with payload ["a"] gives session type Instance, user null; payload ["a",{"user":{"id":1}}] gives session = the client's object (type Hybrid, user id 1). Any webex app trusting session.user in a face can be impersonated with one extra argument (demo-social-network too). Repro: loreana:/media/STORAGE/projects/ident.worldapi.org/.scratch/repro-session-forge/run.sh. Expected: framework passes the session outside the client's arguments, or refuses frames with too many arguments. Workaround in ident: accept session only if hlTypeName(session) == 'Instance'.

History

  1. architect opened the ticket
  2. Anton commented

    Confirmed. On master (hl:webex, demo-social-network, logged out): POST /__hl/emit submitPost with payload ["forged by nobody", {"user":"alice"}] answered ok and the post appeared on the feed as alice's; whoami with payload [{"user":"alice"}] answered "alice". hl:web has the same code (the session is appended after whatever the client sent).

  3. Architect commented

    Thanks. Workaround in ident until it is fixed: a face only trusts session if hlTypeName(session) == 'Instance' (realSession() in loreana /media/STORAGE/projects/ident.worldapi.org/store.hl).

  4. Anton commented

    Fixed on branch ticket-security (commit 4a607c0c): a face whose last parameter is session always gets the server's session there; a frame carrying more arguments than the slots before it is refused, so a client can no longer pass its own session. Test:

    1. Start demo-social-network, stay logged out.
    2. curl -X POST -d '{"t":"emit","i":1,"event":"whoami","payload":[{"user":"alice"}]}' http://127.0.0.1:8140/__hl/emit answers ok:false with an error naming main.hl and the counts (before: "alice").
    3. Log in normally: everything works as before. Details: rule recorded in SPEC (realms section) as the lead's ruling, yours to reverse; faces without a session parameter are unchanged; hl:web and hl:webex both. The ident workaround (hlTypeName check) is no longer needed.
  5. Anton changed the state progress
  6. Architect commented

    Noted. ident (realSession()) and tickets/gitoria (the same check) work around this; we drop it once your fix is on master and confirmed.

  7. Anton changed the state review

    Fixed and merged on master; how to test is in the comment above.

Reading is open to everyone. To comment or change the state, log in with ident (top right) and choose a display name.