Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[PM-6794] block legacy users from authN #4088

Open
wants to merge 10 commits into
base: main
Choose a base branch
from

Conversation

jlf0dev
Copy link
Member

@jlf0dev jlf0dev commented May 15, 2024

Type of change

- [ ] Bug fix
- [x] New feature development
- [ ] Tech debt (refactoring, code cleanup, dependency upgrades, etc)
- [ ] Build/deploy pipeline (DevOps)
- [ ] Other

Objective

Blocks legacy users (users who use their master key as their encryption key) from logging in. Directing them to the web vault for migration.

Code changes

  • file.ext: Description of what was changed and why

Before you submit

  • Please check for formatting errors (dotnet format --verify-no-changes) (required)
  • If making database changes - make sure you also update Entity Framework queries and/or migrations
  • Please add unit tests where it makes sense to do so (encouraged but not required)
  • If this change requires a documentation update - notify the documentation team
  • If this change has particular deployment requirements - notify the DevOps team

@jlf0dev jlf0dev requested a review from a team as a code owner May 15, 2024 18:28
@jlf0dev jlf0dev requested a review from rr-bw May 15, 2024 18:28
Copy link
Contributor

github-actions bot commented May 15, 2024

Logo
Checkmarx One – Scan Summary & Details223b5a8f-234b-4fab-929e-d3daac3a9f82

New Issues

Severity Issue Source File / Package Checkmarx Insight
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: [641](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Auth/Controllers/AccountsController.cs# L641) Attack Vector
MEDIUM Path_Traversal /src/Api/Tools/Controllers/SendsController.cs: [193](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Tools/Controllers/SendsController.cs# L193) Attack Vector
MEDIUM Path_Traversal /src/Api/Tools/Controllers/SendsController.cs: [193](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Tools/Controllers/SendsController.cs# L193) Attack Vector
MEDIUM Privacy_Violation /src/Api/AdminConsole/Controllers/OrganizationsController.cs: [428](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationsController.cs# L428) Attack Vector
MEDIUM Privacy_Violation /src/Api/AdminConsole/Controllers/OrganizationsController.cs: [375](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationsController.cs# L375) Attack Vector
MEDIUM SSRF /src/Billing/Controllers/FreshsalesController.cs: [50](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Billing/Controllers/FreshsalesController.cs# L50) Attack Vector
MEDIUM SSRF /src/Billing/Controllers/FreshsalesController.cs: [50](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Billing/Controllers/FreshsalesController.cs# L50) Attack Vector
LOW Log_Forging /src/Api/AdminConsole/Controllers/OrganizationsController.cs: [403](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationsController.cs# L403) Attack Vector
LOW Log_Forging /src/Api/AdminConsole/Controllers/OrganizationsController.cs: [340](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationsController.cs# L340) Attack Vector
LOW Missing_CSP_Header /src/Core/MailTemplates/Handlebars/InitiateDeleteOrganzation.html.hbs: [10](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Core/MailTemplates/Handlebars/InitiateDeleteOrganzation.html.hbs# L10) Attack Vector

Fixed Issues

Severity Issue Source File / Package
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [628](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L628)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [628](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L628)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [628](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L628)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [628](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L628)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/ProvidersController.cs: [82](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/ProvidersController.cs# L82)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [607](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L607)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [607](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L607)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [607](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L607)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [607](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L607)
MEDIUM CSRF /src/Api/Public/Controllers/CollectionsController.cs: [87](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Public/Controllers/CollectionsController.cs# L87)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/GroupsController.cs: [132](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/GroupsController.cs# L132)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/ProvidersController.cs: [143](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/ProvidersController.cs# L143)
MEDIUM CSRF /src/Api/SecretsManager/Controllers/AccessPoliciesController.cs: [229](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/SecretsManager/Controllers/AccessPoliciesController.cs# L229)
MEDIUM CSRF /src/Admin/AdminConsole/Controllers/ProvidersController.cs: [319](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Admin/AdminConsole/Controllers/ProvidersController.cs# L319)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/GroupsController.cs: [163](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/GroupsController.cs# L163)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/GroupsController.cs: [163](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/GroupsController.cs# L163)
MEDIUM CSRF /src/Api/Billing/Controllers/ProviderClientsController.cs: [28](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Billing/Controllers/ProviderClientsController.cs# L28)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: [205](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationUsersController.cs# L205)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: [348](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationUsersController.cs# L348)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: [348](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationUsersController.cs# L348)
MEDIUM CSRF /src/Api/Controllers/CollectionsController.cs: [270](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Controllers/CollectionsController.cs# L270)
MEDIUM CSRF /src/Api/Controllers/CollectionsController.cs: [270](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Controllers/CollectionsController.cs# L270)
MEDIUM CSRF /src/Api/Controllers/CollectionsController.cs: [212](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Controllers/CollectionsController.cs# L212)
MEDIUM CSRF /src/Api/Controllers/CollectionsController.cs: [212](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Controllers/CollectionsController.cs# L212)
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: [665](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Auth/Controllers/AccountsController.cs# L665)
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: [707](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Auth/Controllers/AccountsController.cs# L707)
MEDIUM CSRF /src/Api/Vault/Controllers/FoldersController.cs: [45](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/FoldersController.cs# L45)
MEDIUM CSRF /src/Api/Controllers/SelfHosted/SelfHostedOrganizationLicensesController.cs: [51](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Controllers/SelfHosted/SelfHostedOrganizationLicensesController.cs# L51)
MEDIUM CSRF /src/Api/Controllers/UsersController.cs: [22](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Controllers/UsersController.cs# L22)
MEDIUM CSRF /src/Api/Controllers/DevicesController.cs: [70](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Controllers/DevicesController.cs# L70)
MEDIUM CSRF /src/Api/Controllers/DevicesController.cs: [57](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Controllers/DevicesController.cs# L57)
MEDIUM CSRF /src/Api/AdminConsole/Public/Controllers/PoliciesController.cs: [69](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Public/Controllers/PoliciesController.cs# L69)
MEDIUM CSRF /src/Api/AdminConsole/Public/Controllers/PoliciesController.cs: [49](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Public/Controllers/PoliciesController.cs# L49)
MEDIUM CSRF /src/Api/AdminConsole/Public/Controllers/OrganizationController.cs: [42](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Public/Controllers/OrganizationController.cs# L42)
MEDIUM CSRF /src/Api/AdminConsole/Public/Controllers/GroupsController.cs: [92](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Public/Controllers/GroupsController.cs# L92)
MEDIUM CSRF /src/Api/AdminConsole/Public/Controllers/GroupsController.cs: [49](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Public/Controllers/GroupsController.cs# L49)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/ProviderUsersController.cs: [142](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/ProviderUsersController.cs# L142)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/PoliciesController.cs: [148](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/PoliciesController.cs# L148)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/PoliciesController.cs: [78](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/PoliciesController.cs# L78)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/PoliciesController.cs: [61](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/PoliciesController.cs# L61)
MEDIUM CSRF /bitwarden_license/src/Sso/Controllers/AccountController.cs: [163](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//bitwarden_license/src/Sso/Controllers/AccountController.cs# L163)
MEDIUM CSRF /bitwarden_license/src/Sso/Controllers/AccountController.cs: [96](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//bitwarden_license/src/Sso/Controllers/AccountController.cs# L96)
MEDIUM CSRF /bitwarden_license/src/Scim/Controllers/v2/UsersController.cs: [50](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//bitwarden_license/src/Scim/Controllers/v2/UsersController.cs# L50)
MEDIUM CSRF /src/Api/AdminConsole/Public/Controllers/GroupsController.cs: [161](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Public/Controllers/GroupsController.cs# L161)
MEDIUM CSRF /src/Api/Auth/Controllers/EmergencyAccessController.cs: [159](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Auth/Controllers/EmergencyAccessController.cs# L159)
MEDIUM CSRF /bitwarden_license/src/Scim/Controllers/v2/GroupsController.cs: [98](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//bitwarden_license/src/Scim/Controllers/v2/GroupsController.cs# L98)
MEDIUM CSRF /bitwarden_license/src/Scim/Controllers/v2/GroupsController.cs: [88](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//bitwarden_license/src/Scim/Controllers/v2/GroupsController.cs# L88)
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: [308](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Auth/Controllers/AccountsController.cs# L308)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: [87](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationUsersController.cs# L87)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: [233](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationUsersController.cs# L233)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: [315](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationUsersController.cs# L315)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: [333](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationUsersController.cs# L333)
MEDIUM CSRF /src/Api/AdminConsole/Public/Controllers/OrganizationController.cs: [42](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Public/Controllers/OrganizationController.cs# L42)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [778](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L778)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [1130](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L1130)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: [301](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationUsersController.cs# L301)
MEDIUM CSRF /src/Api/Controllers/CollectionsController.cs: [411](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Controllers/CollectionsController.cs# L411)
MEDIUM CSRF /src/Api/Public/Controllers/CollectionsController.cs: [64](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Public/Controllers/CollectionsController.cs# L64)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: [261](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationUsersController.cs# L261)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [657](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L657)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [657](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L657)
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: [428](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Auth/Controllers/AccountsController.cs# L428)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/GroupsController.cs: [277](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/GroupsController.cs# L277)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [961](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L961)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [1047](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L1047)
MEDIUM CSRF /src/Api/Tools/Controllers/ImportCiphersController.cs: [48](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Tools/Controllers/ImportCiphersController.cs# L48)
MEDIUM CSRF /src/Api/Tools/Controllers/ImportCiphersController.cs: [64](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Tools/Controllers/ImportCiphersController.cs# L64)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [111](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L111)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [125](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L125)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [1047](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L1047)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: [464](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationUsersController.cs# L464)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: [316](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationUsersController.cs# L316)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [992](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L992)
MEDIUM CSRF /src/Identity/Controllers/AccountsController.cs: [72](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Identity/Controllers/AccountsController.cs# L72)
MEDIUM CSRF /src/Identity/Controllers/AccountsController.cs: [50](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Identity/Controllers/AccountsController.cs# L50)
MEDIUM CSRF /src/Api/Controllers/CollectionsController.cs: [375](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Controllers/CollectionsController.cs# L375)
MEDIUM CSRF /src/Api/AdminConsole/Public/Controllers/MembersController.cs: [150](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Public/Controllers/MembersController.cs# L150)
MEDIUM CSRF /src/Api/AdminConsole/Public/Controllers/MembersController.cs: [150](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Public/Controllers/MembersController.cs# L150)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [144](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L144)
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: [217](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Auth/Controllers/AccountsController.cs# L217)
MEDIUM CSRF /src/Api/Controllers/CollectionsController.cs: [303](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Controllers/CollectionsController.cs# L303)
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: [283](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Auth/Controllers/AccountsController.cs# L283)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [816](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L816)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationsController.cs: [315](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationsController.cs# L315)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationsController.cs: [315](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationsController.cs# L315)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationsController.cs: [315](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationsController.cs# L315)
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: [568](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Auth/Controllers/AccountsController.cs# L568)
MEDIUM CSRF /src/Api/AdminConsole/Public/Controllers/OrganizationController.cs: [42](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Public/Controllers/OrganizationController.cs# L42)
MEDIUM CSRF /src/Api/AdminConsole/Public/Controllers/OrganizationController.cs: [42](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Public/Controllers/OrganizationController.cs# L42)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [1150](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L1150)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/ProviderUsersController.cs: [188](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/ProviderUsersController.cs# L188)
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: [357](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Auth/Controllers/AccountsController.cs# L357)
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: [526](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Auth/Controllers/AccountsController.cs# L526)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [222](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L222)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [570](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L570)
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: [770](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Auth/Controllers/AccountsController.cs# L770)
MEDIUM CSRF /src/Api/AdminConsole/Public/Controllers/GroupsController.cs: [133](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Public/Controllers/GroupsController.cs# L133)
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: [403](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Auth/Controllers/AccountsController.cs# L403)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [193](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L193)
MEDIUM CSRF /src/Api/Controllers/SettingsController.cs: [36](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Controllers/SettingsController.cs# L36)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [583](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L583)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [583](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L583)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: [261](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationUsersController.cs# L261)
MEDIUM CSRF /src/Api/Auth/Controllers/TwoFactorController.cs: [403](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Auth/Controllers/TwoFactorController.cs# L403)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [752](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L752)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: [301](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationUsersController.cs# L301)
MEDIUM CSRF /src/Api/Controllers/CollectionsController.cs: [303](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Controllers/CollectionsController.cs# L303)
MEDIUM CSRF /src/Api/Controllers/CollectionsController.cs: [411](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Controllers/CollectionsController.cs# L411)
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: [541](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Auth/Controllers/AccountsController.cs# L541)
MEDIUM CSRF /src/Api/Controllers/CollectionsController.cs: [323](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Controllers/CollectionsController.cs# L323)
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: [920](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Auth/Controllers/AccountsController.cs# L920)
MEDIUM CSRF /src/Api/Controllers/CollectionsController.cs: [375](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Controllers/CollectionsController.cs# L375)
MEDIUM CSRF /src/Admin/AdminConsole/Controllers/OrganizationsController.cs: [334](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Admin/AdminConsole/Controllers/OrganizationsController.cs# L334)
MEDIUM CSRF /src/Admin/AdminConsole/Controllers/ProvidersController.cs: [243](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Admin/AdminConsole/Controllers/ProvidersController.cs# L243)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/GroupsController.cs: [81](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/GroupsController.cs# L81)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/GroupsController.cs: [118](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/GroupsController.cs# L118)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationsController.cs: [118](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationsController.cs# L118)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationsController.cs: [315](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/OrganizationsController.cs# L315)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/ProviderOrganizationsController.cs: [48](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/ProviderOrganizationsController.cs# L48)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [1073](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L1073)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [1073](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L1073)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [159](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L159)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/GroupsController.cs: [260](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/GroupsController.cs# L260)
MEDIUM CSRF /src/Api/AdminConsole/Controllers/ProviderUsersController.cs: [175](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Controllers/ProviderUsersController.cs# L175)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [855](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L855)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [222](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L222)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [570](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L570)
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: [861](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Auth/Controllers/AccountsController.cs# L861)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [841](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L841)
MEDIUM CSRF /src/Api/AdminConsole/Public/Controllers/MembersController.cs: [59](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Public/Controllers/MembersController.cs# L59)
MEDIUM CSRF /src/Api/AdminConsole/Public/Controllers/MembersController.cs: [127](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Public/Controllers/MembersController.cs# L127)
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: [515](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Auth/Controllers/AccountsController.cs# L515)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [193](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L193)
MEDIUM CSRF /src/Api/AdminConsole/Public/Controllers/MembersController.cs: [187](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/AdminConsole/Public/Controllers/MembersController.cs# L187)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [928](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L928)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [1096](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L1096)
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: [1096](https://github.com/bitwarden/server/blob/auth/pm-6794/block-legacy-users//src/Api/Vault/Controllers/CiphersController.cs# L1096)
MEDIUM

More results are available on AST platform

@jlf0dev jlf0dev marked this pull request as draft May 16, 2024 13:30
@rr-bw rr-bw requested review from ike-kottlowski and removed request for rr-bw May 16, 2024 16:09
Copy link

codecov bot commented May 16, 2024

Codecov Report

Attention: Patch coverage is 60.60606% with 13 lines in your changes are missing coverage. Please review.

Project coverage is 39.36%. Comparing base (9da75fc) to head (a5b6b7f).

Files Patch % Lines
src/Core/Services/Implementations/UserService.cs 46.15% 4 Missing and 3 partials ⚠️
...tity/IdentityServer/CustomTokenRequestValidator.cs 50.00% 3 Missing and 1 partial ⚠️
...rc/Identity/IdentityServer/BaseRequestValidator.cs 83.33% 1 Missing and 1 partial ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main    #4088      +/-   ##
==========================================
+ Coverage   39.31%   39.36%   +0.04%     
==========================================
  Files        1210     1210              
  Lines       58335    58368      +33     
  Branches     5369     5376       +7     
==========================================
+ Hits        22934    22974      +40     
+ Misses      34320    34306      -14     
- Partials     1081     1088       +7     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

Copy link
Contributor

@ike-kottlowski ike-kottlowski left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good just one question.

@jlf0dev jlf0dev marked this pull request as ready for review May 20, 2024 18:56
Copy link
Contributor

LaunchDarkly flag references

🔍 1 flag added or modified

Name Key Aliases found Info
Block Legacy Users block-legacy-users

ike-kottlowski
ike-kottlowski previously approved these changes May 20, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants