BUG: Overly restrictive admin check in /api/dashboard/blocklist-search blocks non-admin users from using the blocklist feature #34
Closed
opened 2026-05-22 18:53:44 +01:00 by Gandalf
·
1 comment
No Branch/Tag Specified
main
release/1.7.38
develop
release/1.7.37
release/1.7.36
release/1.7.35
release/1.7.34
release/1.7.33
release/1.7.32
release/1.7.31
release/1.7.30
release/1.7.29
release/1.7.28
release/1.7.27
release/1.7.26
release/1.7.25
release/1.7.24
release/1.7.23
release/1.7.22
release/1.7.21
release/1.7.20
release/1.7.19
release/1.7.18
release/1.7.17
release/1.7.16
release/1.7.15
release/1.7.14
release/1.7.13
release/1.7.12
release/1.7.11
release/1.7.10
release/1.7.9
release/1.7.8
release/1.7.7
release/1.7.6
release/1.7.5
release/1.7.4
release/1.7.3
release/1.6.0
release/1.5.5
release/1.5.3
release/1.5.2
release/1.5.0a
release/1.4.0
release/1.3.1a
release/1.3.1
release/1.3.0
release/v1.2.2
release/v1.2.1
release/v1.2.0
release/1.1.2
release/1.1.1
release/1.1.0
release/1.0.0
release/0.2.0
release/v0.1.5
release/0.1.4
release/0.1.3
release/0.1
v1.7.38
v1.7.37
v1.7.36
v1.7.35
v1.7.34
v1.7.33
v1.7.32
v1.7.31
v1.7.30
v1.7.29
v1.7.28
v1.7.27
v1.7.26
v1.7.25
v1.7.24
v1.7.23
v1.7.22
v1.7.21
v1.7.20
v1.7.19
v1.7.18
v1.7.17
v1.7.16
v1.7.15
v1.7.14
v1.7.13
v1.7.12
v1.7.11
v1.7.10
v1.7.9
v1.7.8
v1.7.7
v1.7.6
v1.7.5
v1.7.4
v1.7.3
v1.6.0
v1.5.5
v1.5.3
v1.5.2
v1.5.1
v1.5.0a
v1.4.0
v1.3.1a
v1.3.1
v1.2.2
v1.2.1
v1.2.0
v1.1.2
v1.1.1
v1.1.0
v1.0.0
v0.2.0
v0.1.5
v0.1.4
v0.1.3
v0.1.2
v0.1.1
v0.1.0
Labels
Clear labels
Area/Docker
Area/Download Clients
Area/Frontend
Area/History
Area/Logging
Area/Matching
Area/Proxy
Area/SSE
Area/Webhooks
Compat/Breaking
Compat/Non-Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Docker image and container packaging
Download client integrations
Client-side UI and build tooling
History and completed downloads views
Log streaming, file handling, and debug infrastructure
Matching and correlation logic
Upstream service proxy routes
Server-Sent Events and real-time streaming
Webhook processing and reliability
Breaking change that won't be backward compatible
Non-breaking compatibility change
Something is not working
Documentation changes
Improve existing functionality
New functionality
This is security issue
Issue or pull request related to testing
Priority
Critical
1
The priority is critical
Priority
High
2
The priority is high
Priority
Low
4
The priority is low
Priority
Medium
3
The priority is medium
Reviewed
Confirmed
1
Issue has been confirmed
Reviewed
Duplicate
2
This issue or pull request already exists
Reviewed
Invalid
3
Invalid issue
Reviewed
Won't Fix
3
This issue won't be fixed
Status
Abandoned
3
Somebody has started to work on this but abandoned work
Status
Blocked
1
Something is blocking this issue or pull request
Status
Need More Info
2
Feedback is required to reproduce issue or to continue work
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: Gandalf/sofarr#34
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
The authorization checks inside
server/routes/dashboard.jsfor the/blocklist-searchendpoint are overly restrictive. WhileDownloadAssembler.canBlocklistcalculates if a specific download can be blocklisted by a regular user (e.g., when it has import issues or if it is a torrent over 1 hour old with <100% availability), the route handlerPOST /api/dashboard/blocklist-searchunconditionally rejects any non-admin request with a403 Forbiddenstatus.Root Cause
In
server/routes/dashboard.js(lines 675-678), the router includes an explicit admin-only gate:This check completely overrides the granular permissions evaluated by
DownloadAssembler.canBlocklist(download, isAdmin), which are used byDownloadMatcher.jsto expose the "Blocklist + Re-search" button to non-admin users.Impact
When a non-admin user has a download that qualifies for blocklisting (e.g., it has an import issue), they are correctly shown the "Blocklist + Re-search" button in their dashboard interface. However, clicking the button triggers a request to
POST /api/dashboard/blocklist-search, which immediately fails with a403 Forbiddenerror. This creates a severe mismatch between UI capability states and backend enforcement, resulting in a broken user experience.Steps to Reproduce
DownloadAssembler.canBlocklistevaluates to true)./api/dashboard/blocklist-searchfails with a403 Forbidden: Admin access requiredstatus code.Proposed Fix
Modify
POST /api/dashboard/blocklist-searchto dynamically authorize non-admin users:DownloadAssembler.canBlocklist(download, false)to verify if they are authorized to blocklist it.403 Forbiddenerror.Fixed the overly restrictive admin check in the blocklist-search endpoint. Non-admin users can now use the blocklist feature when they meet qualifying conditions (import issues or stale low-availability torrents). Changes:
All integration tests pass.