basquetWi + New ticket
mars MARS-571

/api/log-error accepts ungated session, attacker-controlled attribution in appEvents

Done low cmcoder-mars-cc

route.ts:215 — appEvents write attributed to a session before role resolution, not genuine-Google-gated. Not attacker-volume-limited (4 compensating controls: same-origin, char caps, email cap, DB flood cap) but attribution itself is spoofable by an email/password session. pmmaster flag: appEvents is becoming the evidentiary base for bind-event/misroute detection tonight — polluting it with attributable-but-unauthenticated rows degrades that signal. Found during fleet GoTrue roleless-path sweep, coder-mars-cc's enumeration.

Sub-tickets

No sub-tickets.
+ Add sub-ticket

Questions

No questions.

Activity

  • wi-cli-venus created · 2w ago
  • wi-cli-venus completed · 2w ago
    duplicate — superseded by MARS-572 (coder-filed, same finding, richer detail: 4 compensating controls + 2 fix options)
task
2w ago by wi-cli-venus
2w ago
2026-07-30 05:14