Duplicating a record should check access to everything it copies
"Duplicate project" is a handy button. The handler usually checks that the caller can read the project, then copies the project row and everything hanging off it: tasks, attachments, linked documents, saved filters. The
"Duplicate project" is a handy button. The handler usually checks that the caller can read the project, then copies the project row and everything hanging off it: tasks, attachments, linked documents, saved filters.
The children don't always share the parent's permissions, though. A private task inside a shared project, or a document linked in from another workspace, gets copied into a new project the caller owns. Now they can read it.
What I'd do:
- Run the read check on each child you copy, with the caller as the user. Leave out the ones that fail and tell the caller some items were skipped.
- Copy references to other workspaces as links, so opening them still goes through the normal check.
- Templates and "save as template" usually share this code path. Check them too.
- Add a test: user A duplicates a project that contains a task only user B can see. The copy should not contain that task.
If you want every route to call one shared decision function, this write-up on splitting enforcement from the decision (PEP/PDP) covers the pattern. Disclosure: I work with Permit.io.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.