Skip to content

Scope run lookup in RunsController to the nested task - #1564

Merged
andrewn617 merged 1 commit into
mainfrom
scope-run-lookup-to-task
Sep 28, 2026
Merged

andrewn617 merged 1 commit into
mainfrom
scope-run-lookup-to-task

Conversation

@andrewn617

Copy link
Copy Markdown
Member

RunsController#set_run looked up the Run by id alone and ignored the task_id in the URL, so POST /tasks/:task_id/runs/:id/{pause,cancel,resume} could act on a Run that belongs to a different Task. Apps that use MaintenanceTasks.parent_controller to authorize per Task based on params[:task_id] could be bypassed this way: a user allowed one Task could pause, cancel or resume another Task's Run by putting its id in the URL.

This PR looks up the Run by both id and task_name, so a Task/Run mismatch now responds with 404, the same scoping TaskDataShow#runs already uses to list a Task's Runs. It adds controller tests for all three actions, and the cross-task tests fail without the fix. It also adds a note to the README's parent controller section saying authorization logic can rely on params[:task_id] for run actions.

RunsController#set_run loaded the Run by id alone, ignoring the task_id
route segment. Applications using MaintenanceTasks.parent_controller to
authorize access per Task based on params[:task_id] could be bypassed by
pairing an allowed task_id with the id of another Task's Run, allowing
that Run to be paused, cancelled or resumed.

Look up the Run by both id and task_name so that mismatched requests
respond with 404, and document that params[:task_id] can be relied upon.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@andrewn617
andrewn617 merged commit 6394654 into main Sep 28, 2026
37 checks passed
@andrewn617
andrewn617 deleted the scope-run-lookup-to-task branch September 28, 2026 19:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants