The update/delete handlers for medications and appointments took the auth Claims but never used them — any authenticated user could update or delete any other user's records by id (an IDOR). Same gap on log_dose (could skew another's adherence stats) and get_adherence (leaked dose history). Fix: each affected handler now looks up the item first and confirms user_id == claims.sub before mutating/returning. Mismatches return 404 (not 403) to avoid leaking the existence of other users' records. Recipients of shared profiles remain read-only per the ADR — writes stay owner-only. Covered handlers: - update_medication, delete_medication, log_dose, get_adherence - update_appointment, delete_appointment health_stats update/delete were already checking user_id == claims.sub (unaffected). New ownership_tests.rs: cross-user update/delete/log-dose/adherence all 404; the legitimate owner can still do all of the above. Verification: cargo build/clippy (-D warnings)/fmt clean; existing tests unaffected (they operate as the same user that created the data). Closes #12. |
||
|---|---|---|
| .. | ||
| common | ||
| auth_tests.rs | ||
| medication_tests.rs | ||
| ownership_tests.rs | ||
| profile_tests.rs | ||
| share_tests.rs | ||
| zk_integration_tests.rs | ||