The API That Returned More Than the Profile — JavaScript Bug Hunt
Modelled on the Google+ API bug (disclosed October 2018): an endpoint meant to return a user's public profile fields also returned fields the user had…
- Language: JavaScript
- Layer: Backend
- Difficulty: Medium
- Concepts: Security, API Design
- Modelled on: Google+ · 2018
- Visible tests: public fields are returned; a non-public field is omitted
- Reward: 50 XP for a complete fix
Briefing
Modelled on the Google+ API bug (disclosed October 2018): an endpoint meant to return a user's public profile fields also returned fields the user had shared only with friends. Around 500,000 accounts were affected, and Google shut the consumer product down.
api.js serialises the whole record and lets the caller pick fields.
Fix publicProfile so it emits only the fields declared public, whatever the caller asks for.
Bug report
BUG-GPLUS · Priority: High (privacy) · Reported by: security
publicProfile(user, requestedFields) must return an object containing only the requested fields that are ALSO in user.publicFields — anything else is omitted silently. The result's keys must be in the order given by requestedFields.
Observed: requesting "email" on an account that shares it only with friends returns the email anyway.
Logs
[api] fields=[name,email] publicFields=[name] -> returned email
[api] 496,951 profiles affectedThe code as shipped
src/api/api.js (editable)
// Returns the caller-requested subset of a profile.
exports.publicProfile = function (user, requestedFields) {
var out = {};
for (var i = 0; i < requestedFields.length; i++) {
var f = requestedFields[i];
if (user.data.hasOwnProperty(f)) out[f] = user.data[f];
}
return out;
};
Read-only context: src/api/MODEL.js.
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.