[ 
https://issues.apache.org/jira/browse/ATLAS-5372?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

chaitali borole updated ATLAS-5372:
-----------------------------------
    Description: 
*PreRequisites*
Two authenticated users with permissions to use saved-search APIs (for example: 
userA, userB).

*Steps*
Login as userA and create a saved search using:

POST /api/atlas/v2/search/saved
capture the returned guid (call it G1).
Login as userB and send another create request to:

POST /api/atlas/v2/search/saved
include:
ownerName = userB
guid = G1
different name / searchParameters.

*Fetch saved searches for both users:*
GET /api/atlas/v2/search/saved?user=userB
GET /api/atlas/v2/search/saved?user=userA

*Observed Result*
The object with guid = G1 now appears under userB with updated content.
userA no longer has that saved search entry with G1.

*Expected Result*
Create API should not allow client-supplied guid to update an existing 
saved-search object owned by another user.
POST create should either reject non-empty guid or ignore it and always create 
a new object

  was:
*PreRequisites*
Two authenticated users with permissions to use saved-search APIs (for example: 
userA, userB).

*Steps*
Login as userA and create a saved search using:

POST /api/atlas/v2/search/saved
capture the returned guid (call it G1).
Login as userB and send another create request to:

POST /api/atlas/v2/search/saved
include:
ownerName = userB
guid = G1
different name / searchParameters.

*Fetch saved searches for both users:
*
GET /api/atlas/v2/search/saved?user=userB
GET /api/atlas/v2/search/saved?user=userA

*Observed Result
*
The object with guid = G1 now appears under userB with updated content.
userA no longer has that saved search entry with G1.

*Expected Result
*
Create API should not allow client-supplied guid to update an existing 
saved-search object owned by another user.
POST create should either reject non-empty guid or ignore it and always create 
a new object


> Prevent cross-user overwrite in saved search create API via caller-supplied 
> guid
> --------------------------------------------------------------------------------
>
>                 Key: ATLAS-5372
>                 URL: https://issues.apache.org/jira/browse/ATLAS-5372
>             Project: Atlas
>          Issue Type: Improvement
>            Reporter: chaitali borole
>            Assignee: chaitali borole
>            Priority: Major
>
> *PreRequisites*
> Two authenticated users with permissions to use saved-search APIs (for 
> example: userA, userB).
> *Steps*
> Login as userA and create a saved search using:
> POST /api/atlas/v2/search/saved
> capture the returned guid (call it G1).
> Login as userB and send another create request to:
> POST /api/atlas/v2/search/saved
> include:
> ownerName = userB
> guid = G1
> different name / searchParameters.
> *Fetch saved searches for both users:*
> GET /api/atlas/v2/search/saved?user=userB
> GET /api/atlas/v2/search/saved?user=userA
> *Observed Result*
> The object with guid = G1 now appears under userB with updated content.
> userA no longer has that saved search entry with G1.
> *Expected Result*
> Create API should not allow client-supplied guid to update an existing 
> saved-search object owned by another user.
> POST create should either reject non-empty guid or ignore it and always 
> create a new object



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to