Skip to content

any remittance can be read by id - #1444

Open
bakarezainab wants to merge 4 commits into
LabsCrypt:mainfrom
bakarezainab:ID-remittance
Open

any remittance can be read by id#1444
bakarezainab wants to merge 4 commits into
LabsCrypt:mainfrom
bakarezainab:ID-remittance

Conversation

@bakarezainab

Copy link
Copy Markdown

Pull Request Checklist

Please ensure your PR follows these steps, mirroring our CONTRIBUTING.md guidelines.

  • I have read the CONTRIBUTING.md document.
  • My code follows the code style of this project.
  • I have added tests to cover my changes.
  • All new and existing tests passed.
  • I have updated the documentation accordingly.
  • I have verified the changes locally

Closes #1374

return {
...old,
totalOwed: newOwed,
totalRepaid: newRepaid,
}

const [whole = "0", fraction = ""] = value.split(".");
const normalizedFraction = fraction.padEnd(decimals, "0").slice(0, decimals);
}

const [whole = "0", fraction = ""] = value.split(".");
const normalizedFraction = fraction.padEnd(decimals, "0").slice(0, decimals);

@ogazboiz ogazboiz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you found a genuine live auth bypass (the tautological ownership checks in remittanceController), thank you. heads up though: #1578 fixes the same two tautologies with a minimal diff and is being merged now, so please rebase on current main first and see what is left. beyond that, this branch carries a lot of unrelated stale-base noise that cannot be merged:

  1. rebase onto current main and drop everything except the remittance controller changes still needed after #1578, your new remittanceController.test.ts (the sender/recipient/forbidden coverage is genuinely valuable and #1578 has no tests), and the security-issues.test.ts update. no package-lock, contract snapshots, indexer, gamification or transactionController changes.
  2. re-run CI after the rebase; the contracts red comes from the stale snapshots in this branch.
  3. consider retitling to make clear it adds the regression coverage for the read-by-id IDOR.

if you want to keep contributing, join us on Telegram: https://t.me/+DOylgFv1jyJlNzM0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Backend] IDOR: any remittance can be read by id

3 participants