Skip to content

[8.4-stable] Merge pull request #312 from AlchemyCMS/stepup-auth-role-assignment - #313

Merged
tvdeyen merged 2 commits into
8.4-stablefrom
backport/8.4-stable/pr-312
Sep 24, 2026
Merged

tvdeyen merged 2 commits into
8.4-stablefrom
backport/8.4-stable/pr-312

Conversation

@alchemycms-bot

Copy link
Copy Markdown

Backport

This will backport the following commits from main to 8.4-stable:

Questions ?

Please refer to the Backport tool documentation

A valid session plus a CSRF token was enough to create an admin user or
grant the admin role to an existing one. Any script execution on an
authenticated admin page was therefore a single request away from a
persistent attacker controlled admin account, which is the trust
boundary the stored XSS of GHSA-x84w-hjc5-6pqw was a ladder towards.
Asking the acting admin for their own password whenever a request would
grant or revoke a privileged role downgrades that chain from one click
to requiring live credentials.

Only admin can manage users, so the check is scoped to that role rather
than to role changes in general. Adding an author or an editor is by far
the more common task and crosses no trust boundary, and challenging it
would have put the friction on the harmless case. Devise ships no
step-up primitive, so this builds on `valid_password?` of the current
user and can be turned off for installs that grant roles
programmatically.

(cherry picked from commit e4cf223)
The gem vendors Devise translations for eight more languages but only
ships its own strings in English and German, so the password
confirmation would have been the first thing a non-English install hit
untranslated, in a dialog that now carries the entire explanation of why
the save was interrupted. German was reviewed, the remaining languages
follow the formality register of the Devise translations already
vendored here and want a native speaker's eye before release.

(cherry picked from commit 88f6d88)
@codecov

codecov Bot commented Sep 24, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 99.05%. Comparing base (c51b514) to head (3f3492d).

Additional details and impacted files
@@              Coverage Diff               @@
##           8.4-stable     #313      +/-   ##
==============================================
+ Coverage       98.59%   99.05%   +0.46%     
==============================================
  Files              11       11              
  Lines             285      319      +34     
==============================================
+ Hits              281      316      +35     
+ Misses              4        3       -1     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@tvdeyen
tvdeyen merged commit ec18b81 into 8.4-stable Sep 24, 2026
29 checks passed
@tvdeyen
tvdeyen deleted the backport/8.4-stable/pr-312 branch September 24, 2026 13:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant