Removing a member from an org leaves their policies on disabled projects and groups
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 62/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- go
- Área
- authorization
Línea de trabajo
Start in cascadeRemovePrincipal in core/membership/org.go, where the project and group id sets are built from projectService.List and groupService.List with only the org filter. Mirror the organization delete path, which lists enabled and disabled rows separately, so disabled projects and groups are included in the classification. Done when a test covering a disabled project and a disabled group shows their policies and SpiceDB tuples removed on member removal.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
What happens
When a member, service user or group is removed from an organization, or a user is deleted, the policies of that principal in the org are supposed to be removed. Policies on disabled projects and disabled groups of the org are skipped. The principal keeps them.
Why
cascadeRemovePrincipal in core/membership/org.go sorts the principal's policies into org, project and group policies. It first builds sets of the org's project ids and group ids:
s.projectService.List(ctx, project.Filter{OrgID: orgID})s.groupService.List(ctx, group.Filter{OrganizationID: orgID})
Both lists return only enabled rows when no state is set. A policy on a disabled project or group is not in either set, so it is never classified and never deleted.
Failure case
- A user has a role on a project in the org.
- The project is disabled.
- The user is removed from the org, or the user is deleted.
- The policy on the disabled project stays live, with its SpiceDB tuples.
- If the project is enabled again, the removed user has access again.
The same applies to a disabled group.
Expected
The cascade covers disabled projects and groups. List them in every state, the same way the organization delete now does (list enabled and disabled separately). Add a test with a disabled project and a disabled group.
Notes
- Same behavior on
maintoday. It is not new. - Found while reviewing the organization soft delete work. The org delete itself is not affected, because it removes every child project and group first.
- Lenguaje dominante
- Go
- Estrellas
- 344
- Forks
- 48
- Merge medio
- 1 d 22 h
- PR fusionados (30 d)
- 38
Preparar el entorno
- Incluye un Dockerfile o un archivo de Docker Compose
- Tiene una plantilla de pull request
- Sin guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de raystack/frontier
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 1 día
-
Dificultad 3/5 1-2 días Aptitud para principiantes 62/100
Los mantenedores suelen responder en 1 día
-
Dificultad 4/5 3-5 días Aptitud para principiantes 52/100
Los mantenedores suelen responder en 1 día
-
Dificultad 3/5 1-2 días Aptitud para principiantes 58/100
Los mantenedores suelen responder en 1 día
-
Dificultad 4/5 3-5 días Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día
Todos los issues de raystack/frontier
Issues similares
-
tag renaming / editing is brokenAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 73/100
Los mantenedores suelen responder en 1 día
-
bug go
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
genkit-ai/genkit#6761 · 1 comentario ·
Los mantenedores suelen responder en 2 días
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 87/100
Los mantenedores suelen responder en 2 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
github/github-mcp-server#3475 ·
Los mantenedores suelen responder en 4 días