Summary
Follow-up from the review of PR #145. Several printer-detail read endpoints require a valid read credential but do not enforce the caller key's allowed_printer_ids restriction via check_printer_access(_auth, printer_id) — so a key scoped to printer A can still read another printer's data (including the connection dict: host/port/SNMP community).
GET /api/printers/{id} is being fixed in #145 itself. The following have the same pre-existing gap and are out of that PR's scope:
GET /api/printers (list_printers) — should filter the returned list to the key's allowed_printer_ids (list-filtering, not a single check_printer_access).
GET /api/printers/{id}/tape (get_printer_tape) — add check_printer_access(_auth, printer_id) if it exposes scoped/sensitive data.
GET /api/printers/{id}/queue (get_printer_queue) — same.
Acceptance
Context: the connection dict disclosure was empirically reproduced in the #145 review with a scoped key.
Summary
Follow-up from the review of PR #145. Several printer-detail read endpoints require a valid read credential but do not enforce the caller key's
allowed_printer_idsrestriction viacheck_printer_access(_auth, printer_id)— so a key scoped to printer A can still read another printer's data (including theconnectiondict: host/port/SNMP community).GET /api/printers/{id}is being fixed in #145 itself. The following have the same pre-existing gap and are out of that PR's scope:GET /api/printers(list_printers) — should filter the returned list to the key'sallowed_printer_ids(list-filtering, not a singlecheck_printer_access).GET /api/printers/{id}/tape(get_printer_tape) — addcheck_printer_access(_auth, printer_id)if it exposes scoped/sensitive data.GET /api/printers/{id}/queue(get_printer_queue) — same.Acceptance
test_route_auth_coverage_guardrail.py(or a sibling guardrail) to also assert per-printer ACL enforcement, not just auth presence.Context: the
connectiondict disclosure was empirically reproduced in the #145 review with a scoped key.