github / github/codeql

False positive 'User-controlled bypass of sensitive method' for C# API endpoint that requires authorization

Open
#13,826 0 comments 0 reactions 0 assignees View on GitHub
false-positive
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

**Description of the false positive**

In one of my controllers I have an endpoint that requires a user to the authorized.
That endpoint has a parameter - a list of files that will be uploaded to the API (List files).
In the first lines I check if the list is not null and not empty.
Later in code I use the "User.Identity.Name" which is detected as a sensitive method.
The combination of that NotEmpty validation and checking the UserName gives me a security threat warning
"User-controlled bypass of sensitive method"

I am not sure if adding a simple NotEmpty validation should create a thread security warning with high severity.
Especially since in the same controller I have methods that check the UserName in the same way but without any prior validation of input and they are "fine". The simplest way of fixing that issue would be deleting the lines with validation which is counter-productive 😃

Thanks in advance for looking into that 😄 .

**Code samples or links to source code**

[Authorize(Policy = AuthorizationConstants.AdministratorsPolicy)]
[Route("Multiple")]
[HttpPost]
public async Task UploadMultipleStructureDocuments(List files)
{
if (files == null || !files.Any() )
{
return BadRequest("No files added to request");
}

(..... some code)

var userName = User.Identity?.Name ?? "NotAuthorizedUser";

(..... some code)
}

**URL to the alert on GitHub code scanning (optional)**

Contributor guide

Open the contributing guide

Research direction

Reproduce the alert from the provided C# controller example, including the [Authorize] endpoint, file-list validation, and User.Identity.Name access. Then trace the CodeQL query that reports “User-controlled bypass of sensitive method” and add or adjust coverage so this authorized pattern is not flagged while genuine findings remain detected.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.