server icon indicating copy to clipboard operation
server copied to clipboard

Auth/pm 20532/tech breakdown poc token based send authn and authz

Open JaredSnider-Bitwarden opened this issue 7 months ago â€ĸ 1 comments

đŸŽŸī¸ Tracking

📔 Objective

📸 Screenshots

⏰ Reminders before review

  • Contributor guidelines followed
  • All formatters and local linters executed and passed
  • Written new unit and / or integration tests where applicable
  • Protected functional changes with optionality (feature flags)
  • Used internationalization (i18n) for all UI strings
  • CI builds passed
  • Communicated to DevOps any deployment requirements
  • Updated any necessary documentation (Confluence, contributing docs) or informed the documentation team

đŸĻŽ Reviewer guidelines

  • 👍 (:+1:) or similar for great changes
  • 📝 (:memo:) or â„šī¸ (:information_source:) for notes or general info
  • ❓ (:question:) for questions
  • 🤔 (:thinking:) or 💭 (:thought_balloon:) for more open inquiry that's not quite a confirmed issue and could potentially benefit from discussion
  • 🎨 (:art:) for suggestions / improvements
  • ❌ (:x:) or âš ī¸ (:warning:) for more significant problems or concerns needing attention
  • 🌱 (:seedling:) or â™ģī¸ (:recycle:) for future improvements or indications of technical debt
  • ⛏ (:pick:) for minor or nitpick changes

JaredSnider-Bitwarden avatar May 16 '25 02:05 JaredSnider-Bitwarden

Logo Checkmarx One – Scan Summary & Details – 7c3d6cfc-46bd-41fc-8c39-b4b35b92170e

New Issues (3)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
MEDIUM CSRF /src/Api/Controllers/CollectionsController.cs: 143
detailsMethod Post at line 143 of /src/Api/Controllers/CollectionsController.cs gets a parameter from a user request from orgId. This parameter value fl...
ID: W5s%2FSNe54CPP1CxzYuVqrn9v0%2Fk%3D
Attack Vector
MEDIUM CSRF /src/Api/AdminConsole/Controllers/GroupsController.cs: 135
detailsMethod Post at line 135 of /src/Api/AdminConsole/Controllers/GroupsController.cs gets a parameter from a user request from orgId. This parameter ...
ID: Qs417oLwYMuJ1g8cUCMHpbUJ9d0%3D
Attack Vector
LOW Missing_CSP_Header /src/Core/MailTemplates/Handlebars/Layouts/Full.html.hbs: 164
detailsA Content Security Policy is not explicitly defined within the web-application.
ID: iDkz8rv3w1QoR%2BKANf%2FBdTS52Xc%3D
Attack Vector
Fixed Issues (2)

Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
MEDIUM ~~CSRF~~ /src/Billing/Controllers/PayPalController.cs: 52
MEDIUM ~~CSRF~~ /src/Api/SecretsManager/Controllers/SecretsController.cs: 201

github-actions[bot] avatar May 16 '25 03:05 github-actions[bot]

Closing this as it's purpose as a POC has been served.

JaredSnider-Bitwarden avatar Sep 23 '25 14:09 JaredSnider-Bitwarden