Skip to content

Extend user serializer validation to identity and permission fields#15191

Open
devGregA wants to merge 1 commit into
DefectDojo:bugfixfrom
devGregA:devgrega/user-serializer-field-guards
Open

Extend user serializer validation to identity and permission fields#15191
devGregA wants to merge 1 commit into
DefectDojo:bugfixfrom
devGregA:devgrega/user-serializer-field-guards

Conversation

@devGregA

@devGregA devGregA commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

Description

Extends UserSerializer.validate() to cover the email and username fields and the configuration_permissions assignment, applying the same kind of validation it already performs for the is_superuser and is_staff fields. This keeps the serializer's validation consistent across its sensitive fields: only superusers may change another account's identity fields or an account's configuration permissions.

Users editing their own non-sensitive fields are unaffected, and superusers retain full control.

Test results

Adds unittests/test_apiv2_user_identity_authz.py covering the identity-field and configuration-permission validation paths.

@devGregA
devGregA force-pushed the devgrega/user-serializer-field-guards branch from 94d44e5 to d24d456 Compare July 8, 2026 20:20
@devGregA devGregA added this to the 3.1.100 milestone Jul 8, 2026
@devGregA

devGregA commented Jul 8, 2026

Copy link
Copy Markdown
Contributor Author

/test all

@devGregA
devGregA force-pushed the devgrega/user-serializer-field-guards branch from d24d456 to dc5fc07 Compare July 9, 2026 01:05
@devGregA devGregA changed the title Extend user serializer validation to identity fields Extend user serializer validation to identity and permission fields Jul 9, 2026
@devGregA
devGregA force-pushed the devgrega/user-serializer-field-guards branch from dc5fc07 to 1b9f54f Compare July 9, 2026 04:00
@github-actions github-actions Bot added settings_changes Needs changes to settings.py based on changes in settings.dist.py included in this PR apiv2 ui parser labels Jul 9, 2026
@Maffooch Maffooch modified the milestones: 3.1.100, 3.1.200 Jul 13, 2026
@github-actions

Copy link
Copy Markdown
Contributor

This pull request has conflicts, please resolve those before we can evaluate the pull request.

@Maffooch Maffooch modified the milestones: 3.1.200, 3.1.300 Jul 20, 2026
valentijnscholten added a commit that referenced this pull request Jul 21, 2026
v3 security-parity review of three open v2 hardening PRs (#15300,
#15296, #15191): #15300 IMMUNE (v3 locations read-only, no reference-
write surface); #15296 IMMUNE (configuration_permissions not on the v3
user write surface); #15191 identity half was a REAL GAP now fixed.

Gap: get_authorized_users returns co-members, so a non-superuser with
view_user+change_user could PATCH/PUT a visible co-member's email or
username -> account takeover via password reset. Adds
_enforce_identity_field_rules (mirrors UserSerializer.validate()):
superuser unrestricted, self-edit allowed, email/username change to
another account -> 400; create is a no-op. Wired into PATCH and PUT
after the superuser/staff gate; deny-by-default sweep unchanged.

+6 tests. (API_V3_PLAN.md also carries the examples-refresh §12 row
committed next.)
Only superusers may change the username or email of another account.
Prevents account takeover via changing a victim's email then triggering
password reset. Users may still edit their own identity fields.

Config-permission guards already landed via DefectDojo#15296; this adds the
remaining identity-field guard PR DefectDojo#15191 intended.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@Maffooch
Maffooch force-pushed the devgrega/user-serializer-field-guards branch from 1b9f54f to 30eae24 Compare July 23, 2026 03:26
@Maffooch
Maffooch requested a review from blakeaowens as a code owner July 23, 2026 03:26
@github-actions github-actions Bot removed settings_changes Needs changes to settings.py based on changes in settings.dist.py included in this PR apiv2 ui parser conflicts-detected labels Jul 23, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Conflicts have been resolved. A maintainer will review the pull request shortly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants