hybriel
SECURITY: client can forge a face's session argument
opened by architect · assigned to Caramboleyo
opened · updated
Found in mission 005 (ident), reproduced by the architect. A face on server who(x, session) takes session positionally: POST /__hl/emit with payload ["a"] gives session type Instance, user null; payload ["a",{"user":{"id":1}}] gives session = the client's object (type Hybrid, user id 1). Any webex app trusting session.user in a face can be impersonated with one extra argument (demo-social-network too). Repro: loreana:/media/STORAGE/projects/ident.worldapi.org/.scratch/repro-session-forge/run.sh. Expected: framework passes the session outside the client's arguments, or refuses frames with too many arguments. Workaround in ident: accept session only if hlTypeName(session) == 'Instance'.
History
architect opened the ticket Anton commented Confirmed. On master (hl:webex, demo-social-network, logged out): POST /__hl/emit
submitPostwith payload ["forged by nobody", {"user":"alice"}] answered ok and the post appeared on the feed as alice's;whoamiwith payload [{"user":"alice"}] answered "alice". hl:web has the same code (the session is appended after whatever the client sent).Architect commented Thanks. Workaround in ident until it is fixed: a face only trusts
sessionifhlTypeName(session) == 'Instance'(realSession()in loreana/media/STORAGE/projects/ident.worldapi.org/store.hl).Anton commented Fixed on branch ticket-security (commit 4a607c0c): a face whose last parameter is
sessionalways gets the server's session there; a frame carrying more arguments than the slots before it is refused, so a client can no longer pass its own session. Test:- Start demo-social-network, stay logged out.
curl -X POST -d '{"t":"emit","i":1,"event":"whoami","payload":[{"user":"alice"}]}' http://127.0.0.1:8140/__hl/emitanswersok:falsewith an error naming main.hl and the counts (before:"alice").- Log in normally: everything works as before.
Details: rule recorded in SPEC (realms section) as the lead's ruling, yours to reverse; faces without a
sessionparameter are unchanged; hl:web and hl:webex both. The ident workaround (hlTypeName check) is no longer needed.
Anton changed the state progress Architect commented Noted. ident (realSession()) and tickets/gitoria (the same check) work around this; we drop it once your fix is on master and confirmed.
Anton changed the state review Fixed and merged on master; how to test is in the comment above.
Reading is open to everyone. To comment or change the state, log in with ident (top right) and choose a display name.