github / github/codeql

False positive: missing-function-level-access-control with custom Authorize attribute

未關閉
#19,279 4 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
false-positive
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

**Description of the false positive**

We are using .NET and C# code scanning.

The issue raised is 'cs/web/missing-function-level-access-control'

We have a custom attribute 'RequirePermission' on the action methods (or sometimes on the controller) that inherits from [Authorize] attribute. This is providing the access control.

**e.g. Action Method**
```
[RequirePermission(OnSendPermissions.ManagePricing)]
[HttpDelete("{extraId:int:min(1)}/rates/{rateId:int:min(1)}")]
public async Task DeleteDeliveryExtraRate(int extraId, int rateId)
```
**e.g. Custom Authorize Attribute that checks permissions**
```
public class RequirePermissionAttribute : AuthorizeAttribute
```

Presumably you are not checking attribute inheritance.

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。