User-controlled role assignment

User-controlled role assignment in C#

Description

Accepting permission fields such as Role, IsAdmin, or IsPrivileged from registration or profile-update requests and saving them to an account can let users elevate their own privileges.

Potential impact

  • Ordinary users may assign themselves administrator or other privileged roles.
  • Bypassed access checks can expose administrative functions, sensitive data, and internal operations.

Remediation

Remove role and permission fields from client request models. Handle role changes in a separate administrative function and verify on the server that the caller may grant the requested role.

Examples

Before

csharp
var user = new User
{
    Email = request.Email,
    Role = request.Role ?? "User"
};

After

csharp
var user = new User
{
    Email = request.Email,
    Role = "User"
};

Explanation:

  • Before: Assigning role or permission fields from a request to an account can let users grant themselves elevated privileges.
  • After: Do not bind roles or permission flags from client input.

References