Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Removing a member from an org leaves their policies on disabled projects and groups

Abierto
#1,980 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
3/5
Tiempo estimado
1-2 días
Aptitud para principiantes
62/100
Tipo de issue
Error
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
go

Línea de trabajo

Start in cascadeRemovePrincipal in core/membership/org.go, where the project and group id sets are built from projectService.List and groupService.List with only the org filter. Mirror the organization delete path, which lists enabled and disabled rows separately, so disabled projects and groups are included in the classification. Done when a test covering a disabled project and a disabled group shows their policies and SpiceDB tuples removed on member removal.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

What happens

When a member, service user or group is removed from an organization, or a user is deleted, the policies of that principal in the org are supposed to be removed. Policies on disabled projects and disabled groups of the org are skipped. The principal keeps them.

Why

cascadeRemovePrincipal in core/membership/org.go sorts the principal's policies into org, project and group policies. It first builds sets of the org's project ids and group ids:

  • s.projectService.List(ctx, project.Filter{OrgID: orgID})
  • s.groupService.List(ctx, group.Filter{OrganizationID: orgID})

Both lists return only enabled rows when no state is set. A policy on a disabled project or group is not in either set, so it is never classified and never deleted.

Failure case

  1. A user has a role on a project in the org.
  2. The project is disabled.
  3. The user is removed from the org, or the user is deleted.
  4. The policy on the disabled project stays live, with its SpiceDB tuples.
  5. If the project is enabled again, the removed user has access again.

The same applies to a disabled group.

Expected

The cascade covers disabled projects and groups. List them in every state, the same way the organization delete now does (list enabled and disabled separately). Add a test with a disabled project and a disabled group.

Notes

  • Same behavior on main today. It is not new.
  • Found while reviewing the organization soft delete work. The org delete itself is not affected, because it removes every child project and group first.
Lenguaje dominante
Go
Estrellas
344
Forks
48
Merge medio
1 d 22 h
PR fusionados (30 d)
38

Preparar el entorno

  • Incluye un Dockerfile o un archivo de Docker Compose
  • Tiene una plantilla de pull request
  • Sin guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de raystack/frontier

Todos los issues de raystack/frontier

Issues similares

Más issues de Go

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.