summary:
In Flowise, DELETE /api/v1/chatflows/:id authorizes requests with checkAnyPermission('chatflows:delete,agentflows:delete'). Possession of either permission is sufficient to reach the delete path. The delete logic does not validate the target resource type, allowing a caller with only agentflows:delete to delete a CHATFLOW, and a caller with only chatflows:delete to delete an AGENTFLOW.
details:
The delete route accepts either chatflows:delete or agentflows:delete. The subsequent logic only resolves the target record by id and workspaceId, then deletes by id without checking whether the target resource type matches the granted permission domain.
As a result, there is no binding between permission scope and flow type:
agentflows:delete can be used to delete CHATFLOW
chatflows:delete can be used to delete AGENTFLOW
This breaks the intended RBAC separation between Chatflows and Agentflows.
impact:
Users authorized to manage only one flow type can delete the other flow type within the same workspace, resulting in unauthorized deletion and configuration loss.
reproduction steps:
- Log in as a user who can create API keys.
- Create a normal
CHATFLOW and record its id.
- Create an API key with only
agentflows:delete.
- Use that API key to send:
curl -i -X DELETE \
-H 'Authorization: Bearer <agentflows_delete_only_key>' \
http://localhost:8080/api/v1/chatflows/<chatflow_id>
- Observe a
200 OK response, for example:
- Read the same
id again and observe 404 Not Found.
References
summary:
In Flowise,
DELETE /api/v1/chatflows/:idauthorizes requests withcheckAnyPermission('chatflows:delete,agentflows:delete'). Possession of either permission is sufficient to reach the delete path. The delete logic does not validate the target resourcetype, allowing a caller with onlyagentflows:deleteto delete aCHATFLOW, and a caller with onlychatflows:deleteto delete anAGENTFLOW.details:
The delete route accepts either
chatflows:deleteoragentflows:delete. The subsequent logic only resolves the target record byidandworkspaceId, then deletes byidwithout checking whether the target resource type matches the granted permission domain.As a result, there is no binding between permission scope and flow type:
agentflows:deletecan be used to deleteCHATFLOWchatflows:deletecan be used to deleteAGENTFLOWThis breaks the intended RBAC separation between Chatflows and Agentflows.
impact:
Users authorized to manage only one flow type can delete the other flow type within the same workspace, resulting in unauthorized deletion and configuration loss.
reproduction steps:
CHATFLOWand record itsid.agentflows:delete.200 OKresponse, for example:{"raw":[],"affected":1}idagain and observe404 Not Found.References