Skip to content

Denied columns skipped for OTHER request-group members (MERGE/CALL) #1102

Description

@babltiga

core.api.DeniedColumns.rejected(...) returns early when parsed.type() == QueryType.OTHER, on the premise that no permission grants OTHER. That premise is false for request groups: DefaultRequestGroupService.validatePermission admits an OTHER member (MERGE, CALL, …) for a non-admin holding only can_write (break-glass groups: can_break_glass), and verifyTableAndColumnScope then calls DeniedColumns.rejected, which skips it.

So MERGE INTO t USING (SELECT ssn FROM users) s ON … WHEN MATCHED THEN UPDATE SET x = s.ssn bypasses a denied_columns = [users.ssn] grant.

Fix: OTHER is never column-analysed by SqlParserServiceImpl, so it must fail closed like any unanalysed parse — an OTHER statement reaches every denied entry. Same approach as DeniedShapes.rejected in #1101 (#940).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    backendbugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions