False positive: missing-function-level-access-control with custom Authorize attribute
- Dominant language
- CodeQL
- Stars
- 10.1k
- Forks
- 2.1k
- Avg merge
- 2d 15h
- Merged PRs (30d)
- 141
Description
**Description of the false positive**
We are using .NET and C# code scanning.
The issue raised is 'cs/web/missing-function-level-access-control'
We have a custom attribute 'RequirePermission' on the action methods (or sometimes on the controller) that inherits from [Authorize] attribute. This is providing the access control.
**e.g. Action Method**
```
[RequirePermission(OnSendPermissions.ManagePricing)]
[HttpDelete("{extraId:int:min(1)}/rates/{rateId:int:min(1)}")]
public async Task DeleteDeliveryExtraRate(int extraId, int rateId)
```
**e.g. Custom Authorize Attribute that checks permissions**
```
public class RequirePermissionAttribute : AuthorizeAttribute
```
Presumably you are not checking attribute inheritance.
Contributor guide
Research direction
Start with the cs/web/missing-function-level-access-control query and review how it recognizes Authorize attributes. Use the RequirePermissionAttribute examples in this issue to check inherited authorization handling. Done means these action methods or controllers are no longer reported as missing function-level access control.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- csharp
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 42/100