Skip to content

Fix missing ownership check on GetShortcutAnalytics - #507

Open
carfeii wants to merge 1 commit into
yourselfhosted:mainfrom
carfeii:fix/shortcut-analytics-missing-ownership-check
Open

carfeii wants to merge 1 commit into
yourselfhosted:mainfrom
carfeii:fix/shortcut-analytics-missing-ownership-check

Conversation

@carfeii

@carfeii carfeii commented Sep 16, 2026

Copy link
Copy Markdown

Fixes #506

Summary

GetShortcutAnalytics returned any shortcut's referrer/device analytics given only its numeric id, with no check that the caller is the shortcut's creator or an admin, unlike the sibling UpdateShortcut/DeleteShortcut methods which both enforce that check.

Fix

Add the same creator-or-admin check used by UpdateShortcut and DeleteShortcut.

Testing

Verified against a from-source build with a real end-to-end scenario: two independent users, one shortcut, a simulated click, and a cross-user analytics request. Before the fix, an unrelated authenticated user received the full analytics; after the fix, the identical request returns PermissionDenied, while the shortcut's actual creator is unaffected.

GetShortcutAnalytics returned a shortcut's click analytics (referrer
URLs, device/browser breakdown) given only its numeric id, with no
check that the caller is the shortcut's creator or an admin, unlike
the sibling UpdateShortcut/DeleteShortcut methods which both enforce
shortcut.CreatorId == user.ID || user.Role == RoleAdmin. Any
authenticated user of the instance could view any other user's
shortcut analytics by iterating shortcut ids.

Add the same creator-or-admin check used by UpdateShortcut and
DeleteShortcut.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Missing Ownership Check on GetShortcutAnalytics Discloses Any User's Shortcut Referrer and Device Data

1 participant