Request data stored in class variables

User-specific request data is stored in class variables.

Description

User-specific values from web requests or sessions can be shared across requests and instances when stored in a class variable.

Values may remain in shared state even when a process handles requests sequentially. Multiple threads are not required for this problem to occur.

Potential impact

  • One user's identifier or permission-related values may be exposed to another user.
  • State carried between requests may cause incorrect authorization decisions.

Remediation

  • Keep request data in isolated scopes, such as local variables, a new instance for each request, or a per-user session store.
  • Do not store user-specific authentication, session or personal data in class variables or module globals.

Examples

Before

python
class UserDescription:
    user_name = ""

def update_description(request):
    UserDescription.user_name = request.POST.get("name")

After

python
class UserDescription:
    def __init__(self, user_name):
        self.user_name = user_name

def update_description(request):
    return UserDescription(request.POST.get("name"))

Explanation:

  • Before: The class variable shares user-specific request data across the process.
  • After: Each request creates a new instance with its own value. Instance variables do not provide isolation if the same instance is shared among users.

References