CJIS Security and RBAC Audit Report

Implementation report for the CJIS repository

Source: CJIS
Repository: CJIS
Component: backend/*
Completed: Sep 23, 2026 at 01:25 PM PHT

Summary

The backend architecture was comprehensively overhauled to strictly enforce Role-Based Access Control (RBAC), patch critical IDOR (Insecure Direct Object Reference) and SQL Injection vulnerabilities, and guarantee database execution integrity via MySQL transactions.

Implemented Updates

Validation

Screenshot Evidence — CJIS (Code Changes)

1. RBAC Enforcement (Example: delete_department.php)

<?php
 include("../server/cors.php");
 include("../server/connection.php");
 require_admin_state();
 
+ require_permission($conn, 'can_delete');
+
 $data = get_sanitized_input();

2. IDOR Prevention & Brand Isolation (Example: delete_employee.php)

 // User brands check
 $user_brands = $_SESSION['user_brands'];
 
- $sql = "DELETE FROM employees WHERE employee_id = '$id'";
- $conn->query($sql);
+ // 1. Verify the employee belongs to an allowed brand
+ $check_stmt = $conn->prepare("SELECT brand_id FROM employees WHERE employee_id = ?");
+ $check_stmt->bind_param("s", $id);
+ $check_stmt->execute();
+ $emp = $check_stmt->get_result()->fetch_assoc();
+ if (!in_array($emp['brand_id'], $user_brands)) { die(); }
+ 
+ // 2. Proceed with deletion
+ $del_stmt = $conn->prepare("DELETE FROM employees WHERE employee_id = ?");
+ $del_stmt->execute();

3. SQL Injection Remediation (Example: add_department.php)

- $sql = "INSERT INTO departments (department_id, department_name) VALUES ('$id', '$name')";
- $conn->query($sql);
+ $sql = "INSERT INTO departments (department_id, department_name) VALUES (?, ?)";
+ $stmt = $conn->prepare($sql);
+ $stmt->bind_param("ss", $id, $name);
+ $stmt->execute();

4. Execution Integrity & Transactions (Example: add_overtime_request.php)

+ $conn->begin_transaction();
+ try {
     if ($updateStmt->execute()) {
         overtime_refresh_request_snapshot($conn, (int)$request_id, false);
+         $conn->commit();
         $emailSent = sendOvertimeEmail(...); 
         echo json_encode(["success" => true]);
     }
+ } catch (\Throwable $e) {
+     $conn->rollback();
+     echo json_encode(["success" => false, "message" => "Transaction failed."]);
+ }