github / github/codeql

False positive: Insecure Direct Object Reference (cs/web/insecure-direct-object-reference) and Missing function level access control (cs/web/missing-function-level-access-control)

Abierto
#16,327 1 comentario 0 reacciones 0 asignados Ver en GitHub
C# false-positive
Lenguaje dominante
CodeQL
Estrellas
10.1k
Forks
2.1k
Merge medio
2 d 15 h
PR fusionados (30 d)
141

Descripción

**Description of the false positive**

In a C# project, we have dozens of potential false positives for "Insecure Direct Object Reference (cs/web/insecure-direct-object-reference)" and "Missing function level access control (cs/web/missing-function-level-access-control)" due to the custom authorization that we use via an attribute. Please see the code example below.
What would you suggest as a mitigation in this situation?

**Code samples or links to source code**

```
[Function(Functions.Event.Add)]
public void PublicFunction() {
Function1();
}

private void Function1() {
Function2();
}

private void Function2(id) {
// load object id <= Insecure Direct Object Reference (cs/web/insecure-direct-object-reference)
}
```

where the `[Function]` attribute takes the user's identity and looks if it is authorized for a specific system function. This checks for both authentication and authorization.

The "Missing function level access control (cs/web/missing-function-level-access-control)" is often reported directly on the function declaration:
```
[Function(Functions = new[] { Functions.Location.Edit })]
public async Task Edit(string name) // <= scanner reports insecure function
```

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Start with the cs/web/insecure-direct-object-reference and cs/web/missing-function-level-access-control query entry points, then compare their findings with the [Function] attribute examples in this issue. A useful outcome would be a maintainer-approved mitigation or a clearly scoped query change that accounts for the custom authentication and authorization checks.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
csharp
Área
security
Tipo de issue
Error
Dificultad
5/5
Tiempo estimado
Más de una semana
Estado de actividad
Estancado
Claridad
Necesita aclaración
Aptitud para principiantes
25/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.