Skip to content

Security fixes: September 2026 batch - #3280

Merged
kelvin-muchiri merged 3 commits into
mainfrom
publish/security-2026-09
Oct 6, 2026
Merged

kelvin-muchiri merged 3 commits into
mainfrom
publish/security-2026-09

Conversation

@kelvin-muchiri

@kelvin-muchiri kelvin-muchiri commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Changes / Features implemented

Three security fixes:

  • Organization team pages now require authority over the organization or project before teams can be viewed, changed, or granted project access.
  • Changing who a form is shared with now requires the form's owner or a manager.
  • Deleting submissions and exports through the legacy web pages is now limited to the form they belong to, and only to the people allowed to delete them.

Steps taken to verify this change does what is intended

  • Included tests
  • Updated documentation

Side effects of implementing this change

The delete button on the legacy export list page is still shown to everyone who can view the page, but deletion now fails for those without manager access.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

The legacy form permissions page only checked that the caller could view the form, so anonymous users on forms with shared data, public link visitors and read-only collaborators could grant roles or turn on the public link. 

Require the form owner or the add_xform object permission, matching the API form share action.
Two pages in the older web interface, one for deleting a submission and one for deleting an export, only checked that the caller could see the form named in the address. They then deleted whichever submission or export was requested, without checking that it belonged to that form. Because of this:

any logged-in user could delete another person's submissions or exports by naming a form of their own; and
read-only collaborators, and anyone viewing a form whose data is public, could delete that form's submissions.
Now:

a submission or export is only deleted if it belongs to the form in the address (and, for exports, the export type in the address); otherwise the page responds "not found";
deleting a submission requires the form's owner or someone allowed to delete its submissions (Editors and above), the same rule the API uses; and
deleting an export requires the form's owner or a Manager, the same rule the API uses.
@kelvin-muchiri
kelvin-muchiri merged commit 3a38d7f into main Oct 6, 2026
17 of 18 checks passed
@kelvin-muchiri
kelvin-muchiri deleted the publish/security-2026-09 branch October 6, 2026 11:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants