Skip to content

fix: require Django staff to call set_course_mode_price endpoint - #99

Merged
johanseto merged 1 commit into
open-release/teak.nelpfrom
jlc/course-mode-security-backport
Oct 1, 2026
Merged

johanseto merged 1 commit into
open-release/teak.nelpfrom
jlc/course-mode-security-backport

Conversation

@johanseto

Copy link
Copy Markdown

Description

Backports the authorization fix from openedx/openedx-platform@fd93ef5 to address GHSA-rqq6-w4pv-7pjv.

The  set_course_mode_price  endpoint now requires Django staff permissions, preventing authenticated non-staff users from changing honor-mode prices for arbitrary courses. This affects Operators and any external consumers of this legacy endpoint.

Supporting information

• Upstream fix: openedx@fd93ef5
• Security advisory: GHSA-rqq6-w4pv-7pjv

Testing instructions

  1. Authenticate as a non-staff user and submit a POST request to  set_course_mode_price ; verify that the request is rejected.
  2. Authenticate as a Django staff user and submit the same request; verify that authorized behavior is preserved.

Deadline

None.

Other information

This is a targeted security backport with no configuration or database migration changes.Description

Backports the authorization fix from openedx/openedx-platform@fd93ef5 to address GHSA-rqq6-w4pv-7pjv.

The  set_course_mode_price  endpoint now requires Django staff permissions, preventing authenticated non-staff users from changing honor-mode prices for arbitrary courses. This affects Operators and any external consumers of this legacy endpoint.

Supporting information

• Upstream fix: openedx@fd93ef5
• Security advisory: GHSA-rqq6-w4pv-7pjv

Testing instructions

  1. Authenticate as a non-staff user and submit a POST request to  set_course_mode_price ; verify that the request is rejected.
  2. Authenticate as a Django staff user and submit the same request; verify that authorized behavior is preserved.

Deadline

None.

Other information

This is a targeted security backport with no configuration or database migration changes.

@johanseto
johanseto requested a review from andrey-canon October 1, 2026 20:14
@andrey-canon
andrey-canon force-pushed the open-release/teak.nelp branch from fa870d0 to e57b2e4 Compare October 1, 2026 20:57
The set_course_mode_price view had no authorization check beyond
@login_required, meaning any authenticated user could POST to it and
rewrite the honor-mode price for any course — a privilege escalation
vulnerability.

Ideally this endpoint would be removed: it has no known callers in the
UI (no templates or JS reference it), no tests, and targets the legacy
'honor' mode. However, it is publicly routed and external consumers may
depend on it, so removal requires going through the DEPR process before
we can act. In the meantime, this commit closes the security hole
regardless of how active the endpoint is.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@johanseto
johanseto force-pushed the jlc/course-mode-security-backport branch from 3a80e8f to 134d9c6 Compare October 1, 2026 21:04
@johanseto
johanseto merged commit 0ed4de6 into open-release/teak.nelp Oct 1, 2026
47 checks passed
@johanseto
johanseto deployed to open-release/teak.nelp October 1, 2026 21:48 — with GitHub Actions Active
@johanseto
johanseto deployed to open-release/teak.nelp October 1, 2026 21:48 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
open-release/teak.nelp — 134d9c61 Deployed Oct 1, 2026 by johanseto via create-jira-issue / create_jira_issue #37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants