New Issue Checklist
Issue Description
If the Parse Server option masterKey is set to a function that returns undefined or null, for example because a secret store lookup returns no value instead of throwing an error, requests without a master key are authenticated as master.
resolveKeyAuth in src/middlewares.js compares the master key of the request with the value returned by the function (keyValue === masterKey), without checking that the function returned a key. A request without master key has the key null in handleParseAuth, which matches a function that returns null, and the key undefined in handleParseHeaders, which matches a function that returns undefined. If the function returns an empty string, a request with an empty X-Parse-Master-Key header is authenticated as master. The read-only master key and maintenance key checks in the same function require the key of the request to be set, the master key check does not. FilesRouter._earlyHeadersMiddleware compares the master key in the same way.
The request is then authenticated as master if its IP address is allowed by masterKeyIps, which by default allows 127.0.0.1 and ::1, and rejected with 403 otherwise. So depending on the IP address, either every request is authenticated as master, or every request without master key is rejected.
This affects Parse Server since 8.0.0, which added support for setting masterKey to a function in #9582.
Steps to reproduce
- Start Parse Server with
masterKey: () => undefined.
- From
localhost, send GET /parse/schemas with the X-Parse-Application-Id header, but without X-Parse-Master-Key header.
Actual Outcome
The request succeeds with status 200 and returns the schemas. Likewise, a query without master key returns objects with an empty ACL. The same happens with masterKey: () => null.
With masterKeyIps: ['10.0.0.1'], every request without master key from localhost is rejected with 403 unauthorized.
Expected Outcome
A request is only authenticated as master if it contains the master key. If the masterKey function returns no key, it is treated as an error, and requests without master key are not authenticated as master.
Environment
Server
- Parse Server version:
9.10.2-alpha.4 (alpha branch); since 8.0.0
- Operating system: any
- Local or remote host: any
Database
- System: any
- Database version: any
- Local or remote host: any
Client
- SDK: any
- SDK version: any
Logs
Not applicable
New Issue Checklist
Issue Description
If the Parse Server option
masterKeyis set to a function that returnsundefinedornull, for example because a secret store lookup returns no value instead of throwing an error, requests without a master key are authenticated as master.resolveKeyAuthinsrc/middlewares.jscompares the master key of the request with the value returned by the function (keyValue === masterKey), without checking that the function returned a key. A request without master key has the keynullinhandleParseAuth, which matches a function that returnsnull, and the keyundefinedinhandleParseHeaders, which matches a function that returnsundefined. If the function returns an empty string, a request with an emptyX-Parse-Master-Keyheader is authenticated as master. The read-only master key and maintenance key checks in the same function require the key of the request to be set, the master key check does not.FilesRouter._earlyHeadersMiddlewarecompares the master key in the same way.The request is then authenticated as master if its IP address is allowed by
masterKeyIps, which by default allows127.0.0.1and::1, and rejected with 403 otherwise. So depending on the IP address, either every request is authenticated as master, or every request without master key is rejected.This affects Parse Server since 8.0.0, which added support for setting
masterKeyto a function in #9582.Steps to reproduce
masterKey: () => undefined.localhost, sendGET /parse/schemaswith theX-Parse-Application-Idheader, but withoutX-Parse-Master-Keyheader.Actual Outcome
The request succeeds with status 200 and returns the schemas. Likewise, a query without master key returns objects with an empty ACL. The same happens with
masterKey: () => null.With
masterKeyIps: ['10.0.0.1'], every request without master key fromlocalhostis rejected with 403unauthorized.Expected Outcome
A request is only authenticated as master if it contains the master key. If the
masterKeyfunction returns no key, it is treated as an error, and requests without master key are not authenticated as master.Environment
Server
9.10.2-alpha.4(alphabranch); since8.0.0Database
Client
Logs
Not applicable