Skip to content

Missing ownership checks in REST samples detected by Chanakya static analysis #411

Description

@suman101

Running Chanakya static analyzer on Spring Security
samples reveals several REST endpoints where
@PathVariable IDs flow to repository.findById()
without per-user ownership verification.

These are not Spring Security vulnerabilities —
they are common mistakes in Spring Boot REST APIs
that Spring Security samples could help document.

Example pattern flagged:
@GetMapping("/orders/{id}")
public Order getOrder(@PathVariable Long id) {
return orderRepository.findById(id); // no ownership check
}

Correct pattern:
@PreAuthorize("#id == authentication.principal.id")
OR post-fetch:
if (!order.getOwnerId().equals(currentUser.getId()))
throw new AccessDeniedException();

Would the maintainers be interested in adding a
section documenting this common mistake and its fix?

A01 precision: 0.719 on 65 labeled real-world cases
Contributed by: Suman Lamichhane and Sujana Acharya
Contact: sumanlamichhane45@gmail.com | [sujanaacharya17@gmail.com]

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions