Skip to content

[P2][security] Consent grants are not bound to repository or package identity #29

Description

@jdevera

Summary

Persisted command consent is keyed only by group_name. It does not include repository, package, version, or a digest of the command definition.

Affected code

  • cmd/consent/consent.go:81 — getConsentKey returns only group and command name

Trigger and impact

If command resolution later selects a same-named command from another repository/package, or an installed package is replaced, that different implementation can inherit the old command's grants until expiry. It may receive credential-related environment values the user approved for a different code identity.

Suggested correction

Bind consent to a stable source identity: repository ID, package identity, command name, and preferably a digest/version of the security-relevant command definition. Invalidate and re-prompt when that identity or its requested capabilities change.

Acceptance criteria

  • Same-named commands from different sources cannot share grants.
  • Updating or replacing a command invalidates consent when executable identity or requested capabilities change.
  • Tests cover source precedence changes, package upgrades, and command replacement.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingpriority: mediumP2: important but not release-blockingsecuritySecurity vulnerability or hardening issueupstreamAlso affects the upstream project

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions