Skip to content

Commit

Permalink
[Security Solution][Endpoint] Adds RBAC API checks for Blocklist (#14…
Browse files Browse the repository at this point in the history
…4047)

* Adds RBAC API checks for Blocklist

* Change privilege to read for export method in all artifacts
  • Loading branch information
dasansol92 authored Oct 27, 2022
1 parent 1858444 commit 15748c6
Show file tree
Hide file tree
Showing 4 changed files with 19 additions and 11 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -213,10 +213,18 @@ export class BlocklistValidator extends BaseValidator {
return item.listId === ENDPOINT_BLOCKLISTS_LIST_ID;
}

protected async validateHasWritePrivilege(): Promise<void> {
return super.validateHasPrivilege('canWriteBlocklist');
}

protected async validateHasReadPrivilege(): Promise<void> {
return super.validateHasPrivilege('canReadBlocklist');
}

async validatePreCreateItem(
item: CreateExceptionListItemOptions
): Promise<CreateExceptionListItemOptions> {
await this.validateCanManageEndpointArtifacts();
await this.validateHasWritePrivilege();

item.entries = removeDuplicateEntryValues(item.entries as BlocklistConditionEntry[]);

Expand All @@ -228,27 +236,27 @@ export class BlocklistValidator extends BaseValidator {
}

async validatePreDeleteItem(): Promise<void> {
await this.validateCanManageEndpointArtifacts();
await this.validateHasWritePrivilege();
}

async validatePreGetOneItem(): Promise<void> {
await this.validateCanManageEndpointArtifacts();
await this.validateHasReadPrivilege();
}

async validatePreMultiListFind(): Promise<void> {
await this.validateCanManageEndpointArtifacts();
await this.validateHasReadPrivilege();
}

async validatePreExport(): Promise<void> {
await this.validateCanManageEndpointArtifacts();
await this.validateHasReadPrivilege();
}

async validatePreSingleListFind(): Promise<void> {
await this.validateCanManageEndpointArtifacts();
await this.validateHasReadPrivilege();
}

async validatePreGetListSummary(): Promise<void> {
await this.validateCanManageEndpointArtifacts();
await this.validateHasReadPrivilege();
}

async validatePreUpdateItem(
Expand All @@ -257,7 +265,7 @@ export class BlocklistValidator extends BaseValidator {
): Promise<UpdateExceptionListItemOptions> {
const updatedItem = _updatedItem as ExceptionItemLikeOptions;

await this.validateCanManageEndpointArtifacts();
await this.validateHasWritePrivilege();

_updatedItem.entries = removeDuplicateEntryValues(
_updatedItem.entries as BlocklistConditionEntry[]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -116,7 +116,7 @@ export class EventFilterValidator extends BaseValidator {
}

async validatePreExport(): Promise<void> {
await this.validateHasWritePrivilege();
await this.validateHasReadPrivilege();
}

async validatePreSingleListFind(): Promise<void> {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -105,7 +105,7 @@ export class HostIsolationExceptionsValidator extends BaseValidator {
}

async validatePreExport(): Promise<void> {
await this.validateHasWritePrivilege();
await this.validateHasReadPrivilege();
}

async validatePreSingleListFind(): Promise<void> {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -207,7 +207,7 @@ export class TrustedAppValidator extends BaseValidator {
}

async validatePreExport(): Promise<void> {
await this.validateHasWritePrivilege();
await this.validateHasReadPrivilege();
}

async validatePreSingleListFind(): Promise<void> {
Expand Down

0 comments on commit 15748c6

Please sign in to comment.