AOSSIE-Org / AOSSIE-Org/InPactAI

BUG:Security Vulnerability in User Signup

Aperta
#99 0 commenti 1 reazione 1 assegnatario Rivendicata da @Aditya30ag Vedi su GitHub
Lingua principale
TypeScript
Stelle
102
Fork
144
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

### Is there an existing issue for this?

- [x] I have searched the existing issues

### What happened?

## Issue Summary
**Critical security vulnerability** in the user signup process that allows email enumeration and potential account lockouts.

## Location
`Frontend/src/pages/Signup.tsx` (lines 44-50)

## Bug Description
The signup form attempts to check if a user already exists by making an authentication request with a dummy password:

```typescript
// Check if user already exists
const { data: existingUser } = await supabase.auth.signInWithPassword({
email,
password: "dummy-password-to-check-existence",
});
```

## Why This Is a Problem

### 🔒 **Security Issues**
- **Email Enumeration**: Attackers can determine which email addresses are registered
- **Account Lockouts**: Multiple failed login attempts may trigger security measures
- **Information Disclosure**: Reveals user existence without proper authorization

### 🚫 **Wrong Approach**
- Using authentication endpoints for existence checks
- Hardcoded dummy passwords in code
- No rate limiting on existence checks

## Expected Behavior
User existence should be checked through:
- Dedicated API endpoints
- Admin-level operations
- Proper authorization checks

## Impact
- **Severity**: High
- **Affects**: All new user registrations
- **Risk**: Information disclosure and potential DoS

## Suggested Fix
Replace the current check with proper Supabase admin API or dedicated endpoint:

```typescript

// Option 1: Handle during signup process
const { data, error } = await supabase.auth.signUp({
email,
password,
options: { data: { name } },
});

if (error?.message?.includes('already registered')) {
setError("An account with this email already exists. Please sign in instead.");
return;
}
```

## Priority
**High** - Should be fixed before production deployment.

---

### Record

- [x] I agree to follow this project's Code of Conduct
- [x] I want to work on this issue

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.