Bug: CreateGroup via PAT creates an orphan group row
I maintainer di solito rispondono entro 1 giorno
@AmanGIT07 ci sta già lavorando.
Dal 25/5/2026.
Valutazione
Questa issue non è ancora stata valutata.
Descrizione
Summary
When CreateGroup is called by a PAT-authenticated principal, the Postgres groups row is written but the SpiceDB hierarchy links and owner policy are never wired. The row is left as an orphan.
Reproduction
- Authenticate as a PAT scoped to an org with the create-group permission.
- Call
CreateGroup. - Observe: response carries an error; a row exists in
groupsfor the requested name; SpiceDB has nogroup#org/org#member@grouprelations and no owner policy inpolicies.
Root cause
core/group/service.go:72-74—s.repository.Create(ctx, grp)writes the Postgres row first.core/group/service.go:77—s.membershipService.OnGroupCreated(ctx, newGroup.ID, newGroup.OrganizationID, principal.ID, principal.Type)passes the raw principal. For PAT auth this is(<pat-id>, "app/pat").core/membership/service.go:1302—OnGroupCreatedcallsSetGroupMemberRole(..., creatorID, creatorType, schema.GroupOwnerRole).core/membership/service.go:1402-1420—validateGroupPrincipalswitches on principal type and accepts onlyapp/user; everything else returnsErrInvalidPrincipalType.- The error propagates back to the group
Createcaller, butrepository.Createis not rolled back.
Impact
- Orphan rows accumulate in
groupson each failed PAT-drivenCreateGroupcall. - The orphan has no hierarchy in SpiceDB, no owner policy in Postgres, and is unreachable through normal listing (membership-based listing won't surface it either, since there's no policy row).
Suggested fix
Resolve the PAT to its underlying user before invoking OnGroupCreated, mirroring the pattern in CreateProject at core/project/service.go:113:
principal, err := s.authnService.GetPrincipal(ctx)
if err != nil {
return Group{}, fmt.Errorf("%w: %s", authenticate.ErrInvalidID, err.Error())
}
...
subjectID, subjectType := principal.ResolveSubject() // PAT → user
if err = s.membershipService.OnGroupCreated(ctx, newGroup.ID, newGroup.OrganizationID, subjectID, subjectType); err != nil {
return Group{}, err
}
Two-line change. Independent of the ListByUser → List migration in #1643 (this bug pre-dates that work).
Cleanup
Existing orphan rows should be identified and either backfilled with hierarchy + owner or deleted. Candidate query: groups whose id has no matching row in policies with resource_type = 'app/group'.
How surfaced
Found while testing the group listing migration in #1643 with PAT-authenticated calls. The listing bug there was fixed in 42a5c508; this write-side bug is independent.
- Lingua principale
- Go
- Stelle
- 344
- Fork
- 48
- Merge medio
- 1g 22h
- PR unite (30g)
- 38
Preparare l'ambiente
- Include un Dockerfile o un file Docker Compose
- Ha un modello di pull request
- Nessuna guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di raystack/frontier
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 62/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 62/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 52/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 58/100
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di raystack/frontier
Issue simili
-
bug triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
FairwindsOps/nova#484 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
I maintainer di solito rispondono entro 1 giorno
-
automated-analysis code-quality cookie
Difficoltà 2/5 1-3 ore Idoneità per principianti 66/100
github/gh-aw#67517 · 3 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
[otelcol] print-config help text still requires the removed otelcol.printInitialConfig feature gateForse già presa @girishkvs l’ha presa oggi. Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
open-telemetry/opentelemetry-collector#16143 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
bug good first issue load-balancing
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
ktrubilo9/edge-proxy#53 ·