Repository navigation
api(bounties): aggregates ignore repo visibility, exposing private-repo activity #477
Copy link
Copy link
Labels
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:mediumDegraded but workaround existsDegraded but workaround existssubsystem:apiNode REST API request/response surfaceNode REST API request/response surfacesubsystem:visibilityPath-scoped visibility and content withholdingPath-scoped visibility and content withholding
Description
Activity
- addedcrate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundMajor break or real security/trust risk, no easy workaroundsubsystem:apiNode REST API request/response surfaceNode REST API request/response surfacesubsystem:visibilityPath-scoped visibility and content withholdingPath-scoped visibility and content withholding
on Sep 26, 2026 - addedsev:mediumDegraded but workaround existsDegraded but workaround existsand removedsev:highMajor break or real security/trust risk, no easy workaroundMajor break or real security/trust risk, no easy workaround
on Sep 26, 2026 I've opened PR #495 to resolve this.
Approach & Differentiators:
- Zero N+1 DB Queries / No Table Walks: Mirrors the canonical
stats()pattern (Unauthenticated GET /api/v1/stats leaks the count of private/mode-A repos (count oracle) #104,server.rs:546-570) by batch-loading repos and visibility rules once, evaluatinglistable_at_rootin memory, and performing aggregation in PostgreSQL viaunnest. - Fails Closed: Database errors collapse the visible set to empty, returning 0/empty without leaking private repo existence.
- Includes Deny-Probe Tests: Added integration tests in
crates/gitlawb-node/src/test_support.rsverifying anonymous probes cannot observe private repo bounties in global stats, leaderboard, or per-agent earnings.
PR: #495
- Zero N+1 DB Queries / No Table Walks: Mirrors the canonical
- added 3 commits that reference this issue
on Sep 27, 2026
Metadata
Metadata
Assignees
Labels
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:mediumDegraded but workaround existsDegraded but workaround existssubsystem:apiNode REST API request/response surfaceNode REST API request/response surfacesubsystem:visibilityPath-scoped visibility and content withholdingPath-scoped visibility and content withholding
Summary
bounty_statsandagent_bounty_stats(crates/gitlawb-node/src/api/bounties.rs:460-502) run unfiltered aggregates over all bounties (crates/gitlawb-node/src/db/mod.rs:4530-4565) with no repo-read gating. The sibling stats endpoint was deliberately scoped to anonymously listable repos (#104,server.rs:546-570), and row-level bounty routes are visibility-gated; these two aggregates were not updated.Impact
An anonymous caller can infer private-repo bounty activity from aggregate deltas and read per-agent earnings totals. No repo identity is disclosed; aggregate-granularity signal only.
Remediation
Proposed labels: kind:security, crate:node, subsystem:api.