Description
User-specific values from web requests or sessions can be shared across requests and instances when stored in a class variable.
Values may remain in shared state even when a process handles requests sequentially. Multiple threads are not required for this problem to occur.
Potential impact
- One user's identifier or permission-related values may be exposed to another user.
- State carried between requests may cause incorrect authorization decisions.
Remediation
- Keep request data in isolated scopes, such as local variables, a new instance for each request, or a per-user session store.
- Do not store user-specific authentication, session or personal data in class variables or module globals.
Examples
Before
python
class UserDescription:
user_name = ""
def update_description(request):
UserDescription.user_name = request.POST.get("name")
After
python
class UserDescription:
def __init__(self, user_name):
self.user_name = user_name
def update_description(request):
return UserDescription(request.POST.get("name"))
Explanation:
- Before: The class variable shares user-specific request data across the process.
- After: Each request creates a new instance with its own value. Instance variables do not provide isolation if the same instance is shared among users.