Skip to content

Request without master key is authenticated as master if masterKey function returns undefined or null #10709

Description

@mtrezza

New Issue Checklist

Issue Description

If the Parse Server option masterKey is set to a function that returns undefined or null, for example because a secret store lookup returns no value instead of throwing an error, requests without a master key are authenticated as master.

resolveKeyAuth in src/middlewares.js compares the master key of the request with the value returned by the function (keyValue === masterKey), without checking that the function returned a key. A request without master key has the key null in handleParseAuth, which matches a function that returns null, and the key undefined in handleParseHeaders, which matches a function that returns undefined. If the function returns an empty string, a request with an empty X-Parse-Master-Key header is authenticated as master. The read-only master key and maintenance key checks in the same function require the key of the request to be set, the master key check does not. FilesRouter._earlyHeadersMiddleware compares the master key in the same way.

The request is then authenticated as master if its IP address is allowed by masterKeyIps, which by default allows 127.0.0.1 and ::1, and rejected with 403 otherwise. So depending on the IP address, either every request is authenticated as master, or every request without master key is rejected.

This affects Parse Server since 8.0.0, which added support for setting masterKey to a function in #9582.

Steps to reproduce

  1. Start Parse Server with masterKey: () => undefined.
  2. From localhost, send GET /parse/schemas with the X-Parse-Application-Id header, but without X-Parse-Master-Key header.

Actual Outcome

The request succeeds with status 200 and returns the schemas. Likewise, a query without master key returns objects with an empty ACL. The same happens with masterKey: () => null.

With masterKeyIps: ['10.0.0.1'], every request without master key from localhost is rejected with 403 unauthorized.

Expected Outcome

A request is only authenticated as master if it contains the master key. If the masterKey function returns no key, it is treated as an error, and requests without master key are not authenticated as master.

Environment

Server

  • Parse Server version: 9.10.2-alpha.4 (alpha branch); since 8.0.0
  • Operating system: any
  • Local or remote host: any

Database

  • System: any
  • Database version: any
  • Local or remote host: any

Client

  • SDK: any
  • SDK version: any

Logs

Not applicable

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions