Commit 6bf7ee4
Fix isFilterable bypass via cursor parameter in findMany
The cursor parameter in findMany accepted uniqueWhere inputs without
validating them against isFilterable access controls. This allowed
users to bypass dynamic isFilterable functions by using cursor instead
of where to probe for records by protected field values.
Add checkFilterOrderAccess validation for cursor fields, matching the
existing validation for where fields. Add tests for cursor-based
filtering with both allowed and denied isFilterable configurations.
---------
Co-authored-by: velocityx034-spec <velocityx034@gmail.com>
Co-authored-by: Emma Hamilton <git@emmas.town>1 parent c48c76e commit 6bf7ee4
File tree
3 files changed
+47
-0
lines changed- .changeset
- packages/core/src/lib/core/queries
- tests/api-tests/queries
3 files changed
+47
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
137 | 137 | | |
138 | 138 | | |
139 | 139 | | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
140 | 145 | | |
141 | 146 | | |
142 | 147 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
| 25 | + | |
25 | 26 | | |
26 | 27 | | |
27 | 28 | | |
| |||
392 | 393 | | |
393 | 394 | | |
394 | 395 | | |
| 396 | + | |
| 397 | + | |
| 398 | + | |
| 399 | + | |
| 400 | + | |
| 401 | + | |
| 402 | + | |
| 403 | + | |
| 404 | + | |
| 405 | + | |
| 406 | + | |
| 407 | + | |
| 408 | + | |
| 409 | + | |
| 410 | + | |
| 411 | + | |
| 412 | + | |
| 413 | + | |
| 414 | + | |
| 415 | + | |
| 416 | + | |
| 417 | + | |
| 418 | + | |
| 419 | + | |
| 420 | + | |
| 421 | + | |
| 422 | + | |
| 423 | + | |
| 424 | + | |
| 425 | + | |
| 426 | + | |
| 427 | + | |
| 428 | + | |
| 429 | + | |
| 430 | + | |
| 431 | + | |
395 | 432 | | |
396 | 433 | | |
397 | 434 | | |
| |||
0 commit comments