Skip to content

fix(users): prevent IDOR on stellar payout address updates (#39) - #477

Open
Proxima84-code wants to merge 1 commit into
MergeFi:mainfrom
Proxima84-code:fix/users-set-stellar-address-auth-39
Open

Proxima84-code wants to merge 1 commit into
MergeFi:mainfrom
Proxima84-code:fix/users-set-stellar-address-auth-39

Conversation

@Proxima84-code

Copy link
Copy Markdown

Summary

Fixes an IDOR vulnerability in UsersController.setStellarAddress where any authenticated caller could overwrite another user's Stellar payout wallet address.

Root Cause

While PATCH /users/:id/stellar-address was protected by JwtAuthGuard, the handler trusted the :id URL parameter unconditionally and never cross-checked it against req.user.userId. Because BountiesService.markMergedAndRelease resolves recipient addresses dynamically upon PR merge, an attacker could hijack rewards belonging to other contributors.

Changes

  • Injected @Req() req: Request into setStellarAddress.
  • Enforced caller ownership check: throws ForbiddenException if callerId !== id.
  • Added unit test suite in src/users/users.controller.spec.ts asserting self-updates succeed while cross-user requests and missing session contexts are rejected with HTTP 403.

Closes #39

@vercel

vercel Bot commented Sep 30, 2026

Copy link
Copy Markdown

@Proxima84-code is attempting to deploy a commit to the chonilius' projects Team on Vercel.

A member of the Team first needs to authorize it.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

UsersController.setStellarAddress is authenticated but not authorized: any logged-in user can overwrite another user's payout address

1 participant