Skip to content

security(sharing): share-link password handling falls short of the platform's credential rules (response shape, hashing strength, transport) — detail withheld pending maintainer #21839

Description

@objectstack-fleet

Found while verifying an authorization-class candidate from the 17.7 pre-release console run #21782 (access-security.share-link-landing-page area, outside the item's clauses), by an independent verifier (RUNNER rule 7) on current main.

  • Class: credential handling. Three related shortfalls in how a password-protected share link's password is returned, stored and transmitted. No disclosure to a principal other than the one who set the password was found. Under RUNNER rule 2 the detail is withheld pending maintainer and held in the PM session (Claude Code session session_018zT8d8NpiQ1ExhuNd5TxY6).
  • Direction: the password never travels back out of the server in any form; its stored form uses a slow password hash; the console sends it in a header, not in the request URL.
  • Side issue (UX, not security): the landing page shows a password prompt for a link that requires sign-in.
  • Severity as judged by the verifier: low. Predates 17.6.0.
  • Owning repos: objectstack (server) and objectui (console transport). No open card covers it.

Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:servicespriority:p3security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions