Skip to content

Corrupt authorization stores silently fail open and are overwritten on mutation #326

Description

@Calmingstorm

Failure scenario

Start Odin with one of its authorization stores truncated, malformed, or wrong-shaped:

  • A corrupt permissions.json is ignored, so every runtime override disappears and users fall back to configured/default tiers. In a deployment where an override demoted a user, that user regains the broader fallback tier.
  • A corrupt or wrong-shaped host_access.json is ignored, leaving the default allowed_hosts=None; users regain access to every configured host.
  • A corrupt or wrong-shaped api_tokens.json loads an empty token set. The next successful token mutation writes that partial/empty in-memory set over the damaged file, permanently losing valid entries that could have been recovered.

The loaders neither fail startup nor mark their stores read-only/corrupt. Subsequent mutations overwrite the only live file, converting a transient/truncated read into silent authorization loss or privilege broadening.

Sites

  • src/permissions/manager.py:55-70 treats corrupt/wrong-shaped permission data as empty and allows later overwrite.
  • src/permissions/host_access.py:59-81 treats corrupt/wrong-shaped host policy as allow-all defaults and allows later overwrite.
  • src/permissions/token_manager.py:38-104 treats corrupt/wrong-shaped token storage as empty and allows later overwrite.

Expected result

Use corruption-safe strict loading for authorization mutation paths: preserve the damaged bytes, surface an unhealthy/fail-closed state, and refuse writes until repaired. Effective fallback policy on unreadable host/RBAC data must not broaden access.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions