github / github/codeql

False positive: missing-function-level-access-control with custom Authorize attribute

Ouverte
#19,279 4 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
false-positive
Langage dominant
CodeQL
Étoiles
10.1k
Forks
2.1k
Merge moyen
2 j 15 h
PR mergées (30 j)
141

Description

**Description of the false positive**

We are using .NET and C# code scanning.

The issue raised is 'cs/web/missing-function-level-access-control'

We have a custom attribute 'RequirePermission' on the action methods (or sometimes on the controller) that inherits from [Authorize] attribute. This is providing the access control.

**e.g. Action Method**
```
[RequirePermission(OnSendPermissions.ManagePricing)]
[HttpDelete("{extraId:int:min(1)}/rates/{rateId:int:min(1)}")]
public async Task DeleteDeliveryExtraRate(int extraId, int rateId)
```
**e.g. Custom Authorize Attribute that checks permissions**
```
public class RequirePermissionAttribute : AuthorizeAttribute
```

Presumably you are not checking attribute inheritance.

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Start with the cs/web/missing-function-level-access-control query and review how it recognizes Authorize attributes. Use the RequirePermissionAttribute examples in this issue to check inherited authorization handling. Done means these action methods or controllers are no longer reported as missing function-level access control.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
csharp
Domaine
security
Type d'issue
Bug
Difficulté
4/5
Temps estimé
3-5 jours
Activité
À l'abandon
Clarté
Plutôt claire
Accessibilité débutants
42/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.