A04: scrub streaming responses in the SanitizeInterceptor #21

Closed
opened 2026-08-13 09:35:05 +00:00 by nalum · 0 comments
Owner

WrapStreamingHandler returns next untouched (internal/services/svc/sanitize.go:88-90), so the structural scrub guarantee is unary-only. Currently benign: the only streams are Watch (entity-name strings) and Subscribe (Notification — no scrub-map fields). But a future streaming RPC that emits a User would leak password_hash/pin_hash with nothing failing.

Fix: scrub per-send in a wrapped conn, or add a test that pins "no streamed message type embeds a scrub-map type" so the gap cannot open silently.


Source: OWASP Top 10 (2025) audit of v1.1.0, 2026-08-13. File references point at the v1.1.0 tree.

`WrapStreamingHandler` returns `next` untouched (`internal/services/svc/sanitize.go:88-90`), so the structural scrub guarantee is unary-only. Currently benign: the only streams are `Watch` (entity-name strings) and `Subscribe` (`Notification` — no scrub-map fields). But a future streaming RPC that emits a `User` would leak `password_hash`/`pin_hash` with nothing failing. **Fix**: scrub per-send in a wrapped conn, or add a test that pins "no streamed message type embeds a scrub-map type" so the gap cannot open silently. --- Source: OWASP Top 10 (2025) audit of `v1.1.0`, 2026-08-13. File references point at the `v1.1.0` tree.
nalum added reference refs/tags/v1.1.0 2026-08-13 09:37:48 +00:00
nalum closed this issue 2026-08-13 11:38:48 +00:00
Sign in to join this conversation.
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app#21
No description provided.