Skip to content

Scope organization network API routes to the organization in the URL - #1021

Merged
sinamics merged 2 commits into
mainfrom
security/org-network-idor
Sep 20, 2026
Merged

sinamics merged 2 commits into
mainfrom
security/org-network-idor

Conversation

@sinamics

Copy link
Copy Markdown
Owner

SecuredOrganizationApiRoute reads orgid and nwid independently from the URL. This confirms the network belongs to the organization before invoking the handler, and scopes GET_network's own lookup by organizationId.

Adds test coverage for organization scoping on these routes.

SecuredOrganizationApiRoute reads orgid and nwid independently from the
URL, so confirm the network belongs to the organization before invoking
the handler, and scope GET_network's own lookup by organizationId.
Adds coverage for organization scoping on these routes.
Copilot AI lite review requested due to automatic review settings September 20, 2026 17:57
@github-actions github-actions Bot added the ztnet Main Application label Sep 20, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The success test fixture does not verify that the requested network ID is forwarded correctly.

Review effort: Lite
Findings: None

What changed in this PR

Scopes organization network API routes to the organization in the URL and adds access-control tests.

Changes:

  • Validates network ownership for secured organization routes.
  • Scopes GET_network lookup by organization.
  • Adds cross-organization access tests.
File Description
src/​utils/​apiRouteAuth.ts Enforces organization/network ownership.
src/​pages/​api/​v1/​org/​[orgid]/​network/​[nwid]/​index.ts Adds organization-scoped network lookup.
src/​pages/​api/​__tests__/​v1/​org/​network/​org.network.id.access.test.ts Tests authorized and cross-organization access.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@sinamics
sinamics merged commit 4bc95e1 into main Sep 20, 2026
5 checks passed
@sinamics
sinamics deleted the security/org-network-idor branch September 20, 2026 18:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ztnet Main Application

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants