Skip to content

security: enforce per-printer ACL scope on printer-detail read endpoints (list/tape/queue) #146

Description

@strausmann

Summary

Follow-up from the review of PR #145. Several printer-detail read endpoints require a valid read credential but do not enforce the caller key's allowed_printer_ids restriction via check_printer_access(_auth, printer_id) — so a key scoped to printer A can still read another printer's data (including the connection dict: host/port/SNMP community).

GET /api/printers/{id} is being fixed in #145 itself. The following have the same pre-existing gap and are out of that PR's scope:

  • GET /api/printers (list_printers) — should filter the returned list to the key's allowed_printer_ids (list-filtering, not a single check_printer_access).
  • GET /api/printers/{id}/tape (get_printer_tape) — add check_printer_access(_auth, printer_id) if it exposes scoped/sensitive data.
  • GET /api/printers/{id}/queue (get_printer_queue) — same.

Acceptance

  • A read-key scoped to printer A gets 403 (or filtered output) on the above endpoints for printer B.
  • Regression tests per endpoint.
  • Consider extending test_route_auth_coverage_guardrail.py (or a sibling guardrail) to also assert per-printer ACL enforcement, not just auth presence.

Context: the connection dict disclosure was empirically reproduced in the #145 review with a scoped key.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions