{"id":2041,"date":"2021-04-22T09:59:27","date_gmt":"2021-04-22T09:59:27","guid":{"rendered":"https:\/\/sdf-docs.mansystems.com\/docs\/acr-rules\/security\/entity-access-via-xpaths-should-only-be-using-attributes-associations-with-read-only-access\/"},"modified":"2021-07-30T09:09:53","modified_gmt":"2021-07-30T09:09:53","slug":"securityentityaccessxpath","status":"publish","type":"docs","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/securityentityaccessxpath","title":{"rendered":"Entity access rules should be using attributes\/associations with at most read access in XPath constraints"},"content":{"rendered":"\n<p>Introduced in version 2.5 (released May 2021), extended in version 2.7 (release September 2021)<\/p>\n\n\n\n<p>In an entity object, you can configure access rules for specific module roles. If the access rule uses an XPath constraint, the XPath should only refer to attributes and associations with <em>read<\/em> or <em>none<\/em> access. If the XPath uses attributes or associations with&nbsp;<em>read, write&nbsp;<\/em>access, it may cause a security breach.&nbsp;<\/p>\n\n\n\n<p>In the examples below, we have a Tenant entity and six entities with (non-)compliant XPaths that are associations of the Tenant entity.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"857\" height=\"648\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image.png\" alt=\"\" class=\"wp-image-2043\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image.png 857w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-480x363.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 857px, 100vw\" \/><\/figure>\n\n\n\n<p><strong>Non-compliant examples<\/strong><\/p>\n\n\n\n<p><strong>Case 1: <\/strong>EntityNOK has an attribute with r<em>ead, write<\/em>&nbsp;access rights.<br>The XPath constraint of EntityNOK refers to this attribute. <\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"609\" height=\"152\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-2.png\" alt=\"\" class=\"wp-image-2045\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-2.png 609w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-2-480x120.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 609px, 100vw\" \/><\/figure>\n\n\n\n<p><strong>Case 2: <\/strong>One Tenant object is associated with multiple EntityNOK_2 objects. The Tenant object has one&nbsp;<em>Read, Write<\/em>&nbsp;attribute.<br>Via the XPath constraint of EntityNOK2, the user has access to the read, write attribute of Tenant.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"106\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-5-1024x106.png\" alt=\"\" class=\"wp-image-2048\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-5-1024x106.png 1024w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-5-980x101.png 980w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-5-480x50.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/figure>\n\n\n\n<p><strong>Case 3: <\/strong>EntityNOK_3 has both an attribute and the association to the Tenant entity with&nbsp;<em>read, write<\/em>&nbsp;access.<br>The XPath constraint uses the association path to go to the current user.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"113\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-6-1024x113.png\" alt=\"\" class=\"wp-image-2049\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-6-1024x113.png 1024w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-6-980x108.png 980w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-6-480x53.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/figure>\n\n\n\n<p><strong>Case 4: <\/strong>EntityNOK_4 has both an attribute and the association to the Tenant entity with&nbsp;<em>read, write<\/em>&nbsp;access. One Tenant object is associated with multiple EntityNOK_2 objects. The Tenant object has one&nbsp;<em>Read, Write<\/em>&nbsp;attribute.&nbsp;<br>Via the XPath constraint, it uses the association, and it has access to the&nbsp;<em>read, write<\/em>&nbsp;attribute of the Tenant entity, resulting in two violations.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"55\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-7-1024x55.png\" alt=\"\" class=\"wp-image-2050\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-7-1024x55.png 1024w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-7-980x52.png 980w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-7-480x26.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/figure>\n\n\n\n<p><strong>Case 5: <\/strong>One Tenant object is associated with one EntityNOT_5 object. Tenant has&nbsp;<em>read, write&nbsp;<\/em>access on its association with EntityNOK_5. EntityNOK_5 has read-only access on its association with Tenant.<br>EntityNOK_5 uses an XPath constraint over the Tenant association.<br>Even though the access rights over the association are read-only from EntityNOT_5, since the access rule for this association in the Tenant object is&nbsp;<em>read, write,<\/em>&nbsp;this XPath violates this security rule.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"140\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-8-1024x140.png\" alt=\"\" class=\"wp-image-2051\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-8-1024x140.png 1024w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-8-980x134.png 980w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-8-480x66.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/figure>\n\n\n\n<p><strong>Compliant example<\/strong><\/p>\n\n\n\n<p>EntityOK only uses attributes and associations that have&nbsp;<em>read<\/em>&nbsp;or&nbsp;<em>none<\/em>&nbsp;access in its Xpath constraint.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"146\" src=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-9-1024x146.png\" alt=\"\" class=\"wp-image-2052\" srcset=\"https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-9-980x140.png 980w, https:\/\/sdf-docs.clevr.com\/wp-content\/uploads\/2021\/04\/image-9-480x68.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/figure>\n\n\n\n<p><strong>How to solve a violation<\/strong><\/p>\n\n\n\n<p>Ensure that all the direct and indirect attributes and associations you use in an XPath have read-only access.<\/p>\n","protected":false},"featured_media":0,"parent":96,"menu_order":7,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-2041","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2041"}],"collection":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2041"}],"version-history":[{"count":8,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2041\/revisions"}],"predecessor-version":[{"id":2115,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2041\/revisions\/2115"}],"up":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/96"}],"next":[{"title":"Hash Algorithm should be BCrypt or SSHA256","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/securityhashalgorithm","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1600"}],"prev":[{"title":"Entity access default rights for new members should be None or Read","link":"https:\/\/sdf-docs.clevr.com\/?docs=acr-rules\/security\/securityentitydefaultmemberaccess","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/1473"}],"wp:attachment":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2041"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=2041"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}