[8.4-stable] Merge pull request #312 from AlchemyCMS/stepup-auth-role-assignment - #313
Merged
Merged
Conversation
A valid session plus a CSRF token was enough to create an admin user or grant the admin role to an existing one. Any script execution on an authenticated admin page was therefore a single request away from a persistent attacker controlled admin account, which is the trust boundary the stored XSS of GHSA-x84w-hjc5-6pqw was a ladder towards. Asking the acting admin for their own password whenever a request would grant or revoke a privileged role downgrades that chain from one click to requiring live credentials. Only admin can manage users, so the check is scoped to that role rather than to role changes in general. Adding an author or an editor is by far the more common task and crosses no trust boundary, and challenging it would have put the friction on the harmless case. Devise ships no step-up primitive, so this builds on `valid_password?` of the current user and can be turned off for installs that grant roles programmatically. (cherry picked from commit e4cf223)
The gem vendors Devise translations for eight more languages but only ships its own strings in English and German, so the password confirmation would have been the first thing a non-English install hit untranslated, in a dialog that now carries the entire explanation of why the save was interrupted. German was reviewed, the remaining languages follow the formality register of the Devise translations already vendored here and want a native speaker's eye before release. (cherry picked from commit 88f6d88)
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## 8.4-stable #313 +/- ##
==============================================
+ Coverage 98.59% 99.05% +0.46%
==============================================
Files 11 11
Lines 285 319 +34
==============================================
+ Hits 281 316 +35
+ Misses 4 3 -1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
tvdeyen
approved these changes
Sep 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Backport
This will backport the following commits from
mainto8.4-stable:Questions ?
Please refer to the Backport tool documentation