The delete handlers for env vars, labels, volumes, and ports (e.g., HandleEnvVarDelete) look up the resource by its own ID but never verify that the resource's AppID matches the {id} parameter in the URL path. This means a user can delete resources belonging to other apps by manipulating the resource ID.
Impact
Insecure Direct Object Reference (IDOR) - any authenticated user can delete env vars, labels, volumes, or ports from any app.
Location
HandleEnvVarDelete() in internal/handlers/app.go
HandleLabelDelete() in internal/handlers/app.go
HandleVolumeDelete() in internal/handlers/app.go
HandlePortDelete() in internal/handlers/app.go
Fix
After finding the resource, verify resource.AppID == appID before deleting.
## Description
The delete handlers for env vars, labels, volumes, and ports (e.g., `HandleEnvVarDelete`) look up the resource by its own ID but never verify that the resource's `AppID` matches the `{id}` parameter in the URL path. This means a user can delete resources belonging to other apps by manipulating the resource ID.
## Impact
Insecure Direct Object Reference (IDOR) - any authenticated user can delete env vars, labels, volumes, or ports from any app.
## Location
- `HandleEnvVarDelete()` in `internal/handlers/app.go`
- `HandleLabelDelete()` in `internal/handlers/app.go`
- `HandleVolumeDelete()` in `internal/handlers/app.go`
- `HandlePortDelete()` in `internal/handlers/app.go`
## Fix
After finding the resource, verify `resource.AppID == appID` before deleting.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Description
The delete handlers for env vars, labels, volumes, and ports (e.g.,
HandleEnvVarDelete) look up the resource by its own ID but never verify that the resource'sAppIDmatches the{id}parameter in the URL path. This means a user can delete resources belonging to other apps by manipulating the resource ID.Impact
Insecure Direct Object Reference (IDOR) - any authenticated user can delete env vars, labels, volumes, or ports from any app.
Location
HandleEnvVarDelete()ininternal/handlers/app.goHandleLabelDelete()ininternal/handlers/app.goHandleVolumeDelete()ininternal/handlers/app.goHandlePortDelete()ininternal/handlers/app.goFix
After finding the resource, verify
resource.AppID == appIDbefore deleting.Closing as duplicate of #19, which was fixed in PR #28 (merged).