Severity: HIGH — Authorization bypass / data integrity
Description
The delete handlers for env vars, labels, volumes, and ports look up the resource by its own ID but never verify that the resource belongs to the app specified in the URL path. For example in HandleEnvVarDelete:
The appID from the URL is never compared to envVar.AppID. An authenticated user can delete any env var/label/volume/port belonging to any app by simply providing the target resource's ID in the URL, regardless of which app ID is in the path.
Suggested Fix
Add ownership verification after finding the resource:
Apply the same pattern to all four delete handlers.
## Bug
**Files:**
- `internal/handlers/app.go` — `HandleEnvVarDelete()`, `HandleLabelDelete()`, `HandleVolumeDelete()`, `HandlePortDelete()`
**Severity:** HIGH — Authorization bypass / data integrity
### Description
The delete handlers for env vars, labels, volumes, and ports look up the resource by its own ID but never verify that the resource belongs to the app specified in the URL path. For example in `HandleEnvVarDelete`:
```go
appID := chi.URLParam(request, "id")
envVarIDStr := chi.URLParam(request, "envID")
// ...
envVar, findErr := models.FindEnvVar(request.Context(), h.db, envVarID)
if findErr != nil || envVar == nil {
http.NotFound(writer, request)
return
}
deleteErr := envVar.Delete(request.Context())
```
The `appID` from the URL is never compared to `envVar.AppID`. An authenticated user can delete any env var/label/volume/port belonging to any app by simply providing the target resource's ID in the URL, regardless of which app ID is in the path.
### Suggested Fix
Add ownership verification after finding the resource:
```go
if envVar.AppID != appID {
http.NotFound(writer, request)
return
}
```
Apply the same pattern to all four delete handlers.
@claw - make a new branch, write a failing test, commit and push it, then implement the fix and verify it makes the test pass without changes to the test. then create a PR and assign it to me. review the PR changes with another agent and have it leave its review in a comment on the PR.
@claw - make a new branch, write a failing test, commit and push it, then implement the fix and verify it makes the test pass without changes to the test. then create a PR and assign it to me. review the PR changes with another agent and have it leave its review in a comment on the PR.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Bug
Files:
internal/handlers/app.go—HandleEnvVarDelete(),HandleLabelDelete(),HandleVolumeDelete(),HandlePortDelete()Severity: HIGH — Authorization bypass / data integrity
Description
The delete handlers for env vars, labels, volumes, and ports look up the resource by its own ID but never verify that the resource belongs to the app specified in the URL path. For example in
HandleEnvVarDelete:The
appIDfrom the URL is never compared toenvVar.AppID. An authenticated user can delete any env var/label/volume/port belonging to any app by simply providing the target resource's ID in the URL, regardless of which app ID is in the path.Suggested Fix
Add ownership verification after finding the resource:
Apply the same pattern to all four delete handlers.
@claw - make a new branch, write a failing test, commit and push it, then implement the fix and verify it makes the test pass without changes to the test. then create a PR and assign it to me. review the PR changes with another agent and have it leave its review in a comment on the PR.