Skip to content

Parameter for fetch sample secured - #410

Merged
ESapenaVentura merged 5 commits into
BU-ISCIII:developfrom
ESapenaVentura:esv-vuln-fix
Sep 16, 2026
Merged

ESapenaVentura merged 5 commits into
BU-ISCIII:developfrom
ESapenaVentura:esv-vuln-fix

Conversation

@ESapenaVentura

Copy link
Copy Markdown
Member

Patch a potential vulnerability.

@ESapenaVentura ESapenaVentura added the bug Something isn't working label Sep 9, 2026

@Daniel-VM Daniel-VM left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

good job! just a comment to address

Comment thread wetlab/api/views.py Outdated
return Response(error_data, status=status.HTTP_406_NOT_ACCEPTABLE)
try:
eval("sample_objs[0]." + param)
getattr(sample_objs[0], param)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code injection fix! well done

Comment thread wetlab/api/views.py Outdated
Comment on lines +454 to +456
if param not in wetlab.config.ALLOWED_SAMPLE_FETCH_FIELDS:
error_data = wetlab.config.ERROR_PARAMETER_NOT_DEFINED
return Response(error_data, status=status.HTTP_406_NOT_ACCEPTABLE)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you move this check above sample_objs = core.models.Samples.objects.all() ?

@ESapenaVentura ESapenaVentura changed the title Parameter for fetch sample whitelisted and secured Parameter for fetch sample secured Sep 15, 2026
@ESapenaVentura
ESapenaVentura merged commit fe0ff22 into BU-ISCIII:develop Sep 16, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants