All skills
getsentry avatar

/django-access-review

@3482d8d official
by Sentrygetsentry/skills1k stars
53

Django access control and IDOR security review. Use when reviewing Django views, DRF viewsets, ORM queries, or any Python/Django code handling user authorization. Trigger keywords: "IDOR", "access control", "authorization", "Django permissions", "object permissions", "tenant isolation", "broken access".

Use this Skill: https://skilld.dev/gh/getsentry/skills/django-access-review

This session only. Nothing lands on disk.

referencesdrf-permissions.md

≈509 tokens on demand. Your agent reads this file only when SKILL.md points to it.

DRF Permissions - Context for Investigation

Background on how DRF handles permissions. Use this to understand what you're seeing, not as patterns to match.

How DRF Permission Flow Works

Request → permission_classes.has_permission() → View method → get_object() → has_object_permission()

has_permission()

  • Called on EVERY request
  • Checked BEFORE the view method runs
  • Good for "is user authenticated?" or "is user admin?"
  • NOT good for "does user own this specific object?"

has_object_permission()

  • Only called when self.get_object() is called
  • NOT called for list views (no specific object)
  • This is where object-level checks can happen

Critical: If a view does Model.objects.get(pk=pk) directly instead of self.get_object(), the has_object_permission() is NEVER called.

Things to Check When Investigating

1. What's in DEFAULT_PERMISSION_CLASSES?

# settings.py
REST_FRAMEWORK = {
    'DEFAULT_PERMISSION_CLASSES': [...]
}

This applies to ALL views unless overridden.

2. What does each permission class actually do?

Don't assume from the name. Read the class:

# IsAuthenticated only checks login, not ownership
# DjangoModelPermissions checks model-level perms, not object-level
# Custom classes - read the implementation

3. How is data fetched?

# Uses get_object() - permissions apply
instance = self.get_object()

# Direct query - permissions DON'T apply
instance = Model.objects.get(pk=pk)

4. What's in get_queryset()?

This determines what objects are even reachable:

def get_queryset(self):
    return Model.objects.all()  # Everything
    return Model.objects.filter(owner=self.request.user)  # Scoped

Serializer Considerations

Serializers control what fields are readable/writable:

class Meta:
    fields = '__all__'  # What's included?
    read_only_fields = [...]  # What can't be set?

Key question: Can the client set the owner field, or is it server-controlled?

Source: SKILL.md on GitHub

1 warning1d5 checks · Risk SAFE
  • Gen Agent Trust Hub1d

    This skill is a security auditing tool for Django applications that uses search commands to identify access control vulnerabilities. It is safe for its intended use, although it has the inherent attack surface associated with reading and analyzing untrusted source code.

  • Socket1d

    No alerts

  • Snyk1d

    Risk: LOW · No issues

  • Runlayer7mo

    2/5 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 3482d8d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 days ago
All 1 allowed tools
Read Grep Glob Bash Task
  • django
  • authorization
  • idor
  • access-control
  • security-review
  • permissions
  • drf
  • vulnerability-assessment

README badge

README badge for getsentry/skills/django-access-review

Reviews Django views, DRF viewsets, and ORM queries for access control vulnerabilities and IDOR flaws by tracing authorization enforcement mechanisms. Guides investigation through understanding the codebase's ownership model, mapping attack surface, and confirming gaps between resource IDs and permission checks rather than matching against preset patterns.

Generated from the current SKILL.md.

Does this skill work with Django REST Framework?
Yes. The skill is designed to review DRF viewsets, permission classes, and has_object_permission() implementations alongside Django views and custom authorization patterns.
What kinds of access control vulnerabilities does this skill find?
The skill focuses on IDOR (Insecure Direct Object Reference) and broken access control—situations where one user can access, modify, or delete another user's data by knowing or guessing an ID. It investigates query scoping, permission checks, and ownership enforcement.
Does this skill pattern-match for vulnerabilities or require investigation?
It requires investigation. The skill is designed to understand how authorization works in the specific codebase, trace data flows, and confirm gaps rather than scan for predefined vulnerable patterns.
What authorization models can this skill review?
It handles single-user ownership, organization/tenant ownership, hierarchical ownership structures, and role-based access within contexts. It works with decorators, middleware, base classes, DRF permission classes, custom managers, and manual checks.
Does this skill suggest fixes?
Yes, but only code-based fixes that actually enforce authorization. The skill does not accept documentation or comments as fixes and will not suggest them as mitigations.

Generated from the current SKILL.md. These answers refresh after source changes.