Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Bug: CreateGroup via PAT creates an orphan group row

Aperta
#1,645 0 commenti 0 reazioni 1 assegnatario Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@AmanGIT07 ci sta già lavorando.

Dal 25/5/2026.

Valutazione

Questa issue non è ancora stata valutata.

Descrizione

bug

Summary

When CreateGroup is called by a PAT-authenticated principal, the Postgres groups row is written but the SpiceDB hierarchy links and owner policy are never wired. The row is left as an orphan.

Reproduction

  1. Authenticate as a PAT scoped to an org with the create-group permission.
  2. Call CreateGroup.
  3. Observe: response carries an error; a row exists in groups for the requested name; SpiceDB has no group#org / org#member@group relations and no owner policy in policies.

Root cause

  1. core/group/service.go:72-74 — s.repository.Create(ctx, grp) writes the Postgres row first.
  2. core/group/service.go:77 — s.membershipService.OnGroupCreated(ctx, newGroup.ID, newGroup.OrganizationID, principal.ID, principal.Type) passes the raw principal. For PAT auth this is (<pat-id>, "app/pat").
  3. core/membership/service.go:1302 — OnGroupCreated calls SetGroupMemberRole(..., creatorID, creatorType, schema.GroupOwnerRole).
  4. core/membership/service.go:1402-1420 — validateGroupPrincipal switches on principal type and accepts only app/user; everything else returns ErrInvalidPrincipalType.
  5. The error propagates back to the group Create caller, but repository.Create is not rolled back.

Impact

  • Orphan rows accumulate in groups on each failed PAT-driven CreateGroup call.
  • The orphan has no hierarchy in SpiceDB, no owner policy in Postgres, and is unreachable through normal listing (membership-based listing won't surface it either, since there's no policy row).

Suggested fix

Resolve the PAT to its underlying user before invoking OnGroupCreated, mirroring the pattern in CreateProject at core/project/service.go:113:

principal, err := s.authnService.GetPrincipal(ctx)
if err != nil {
    return Group{}, fmt.Errorf("%w: %s", authenticate.ErrInvalidID, err.Error())
}
...
subjectID, subjectType := principal.ResolveSubject()  // PAT → user
if err = s.membershipService.OnGroupCreated(ctx, newGroup.ID, newGroup.OrganizationID, subjectID, subjectType); err != nil {
    return Group{}, err
}

Two-line change. Independent of the ListByUser → List migration in #1643 (this bug pre-dates that work).

Cleanup

Existing orphan rows should be identified and either backfilled with hierarchy + owner or deleted. Candidate query: groups whose id has no matching row in policies with resource_type = 'app/group'.

How surfaced

Found while testing the group listing migration in #1643 with PAT-authenticated calls. The listing bug there was fixed in 42a5c508; this write-side bug is independent.

Lingua principale
Go
Stelle
344
Fork
48
Merge medio
1g 22h
PR unite (30g)
38

Preparare l'ambiente

  • Include un Dockerfile o un file Docker Compose
  • Ha un modello di pull request
  • Nessuna guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di raystack/frontier

Tutte le issue di raystack/frontier

Issue simili

Altre issue su Go

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.