Repository navigation
fix(security): enforce drive access checks in mentions search - #265
Conversation
The mentions search endpoint loaded drives by ID without verifying the requester had access, allowing cross-drive data enumeration. Replace the local getUserAccessibleDrives (which only returned owned drives) with getDriveIdsForUser for cross-drive search and add getUserDriveAccess gating for within-drive search. Unauthorized requests now receive 403. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Code reviewFound 1 issue:
PageSpace/apps/web/src/app/api/mentions/search/route.ts Lines 258 to 260 in 3c959c0 PageSpace/apps/web/src/app/api/mentions/search/route.ts Lines 322 to 325 in 3c959c0 🤖 Generated with Claude Code - If this code review was useful, please react with 👍. Otherwise, react with 👎. |
Replace plain text error responses with NextResponse.json() to match the format used by all other error responses in the same file. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
|
Fixed in 54dadbd. Both plain-text error responses (lines 259 and 324) now use
Tests: 15/15 passing. No new type errors. |
📝 WalkthroughWalkthroughAdds comprehensive test coverage and access control enhancements to the mentions search route. Implements input validation via Zod, introduces permission service integrations (getUserDriveAccess, getDriveIdsForUser) for authorization checks, and restructures cross-drive and within-drive search logic with improved error handling patterns. Changes
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 2 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (2 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing touches
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
/api/mentions/search) loaded drives by ID without verifying the requester had access, enabling cross-drive data enumerationgetUserDriveAccessgating — unauthorized requests now return 403 instead of leaking datagetUserAccessibleDrives(which only returned owned drives) withgetDriveIdsForUser, which correctly includes owned, member, and page-permission drivesdriveIdparameterTest plan
apps/web/src/app/api/mentions/search/__tests__/route.test.ts)🤖 Generated with Claude Code
Summary by CodeRabbit
Release Notes
Bug Fixes
Tests
✏️ Tip: You can customize this high-level summary in your review settings.