Skip to content

Fix demo auth privilege escalation and approval attribution - #8

Open
wesmacdonald wants to merge 1 commit into
mainfrom
wesmacdonald-fix-demo-auth-reviewer-attribution
Open

wesmacdonald wants to merge 1 commit into
mainfrom
wesmacdonald-fix-demo-auth-reviewer-attribution

Conversation

@wesmacdonald

Copy link
Copy Markdown
Owner

The demo API defaults previously allowed a well-known bearer token and caller-selected role headers, while approval records trusted reviewer identity from the request body. These defaults could expose privileged actions and undermine audit attribution.

This change requires explicitly configured demo tokens with fixed Developer and SecurityReviewer roles, binds the Compose port to loopback, and derives approval/rejection identity and role from authenticated claims. It also adds regression tests and upgrades Microsoft.Identity.Web to 4.16.0 to remove a high-severity transitive dependency advisory.

Validation: 77 tests passed, 2 optional integration tests skipped; Docker Compose configuration validated; NuGet vulnerability scan reports no vulnerable packages.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@@ -203,7 +197,7 @@ public async Task<IActionResult> ApproveWorkflow(
/// Only SecurityReviewer role is authorized.
{
reviewer = User.FindFirstValue(ClaimTypes.NameIdentifier) ?? User.Identity?.Name ?? string.Empty;
reviewerRole = User.FindFirstValue(ClaimTypes.Role) ?? string.Empty;

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants