Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Removing a member from an org leaves their policies on disabled projects and groups

Aperta
#1,980 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
62/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
go
Ambito
authorization

Direzione di ricerca

Start in cascadeRemovePrincipal in core/membership/org.go, where the project and group id sets are built from projectService.List and groupService.List with only the org filter. Mirror the organization delete path, which lists enabled and disabled rows separately, so disabled projects and groups are included in the classification. Done when a test covering a disabled project and a disabled group shows their policies and SpiceDB tuples removed on member removal.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

What happens

When a member, service user or group is removed from an organization, or a user is deleted, the policies of that principal in the org are supposed to be removed. Policies on disabled projects and disabled groups of the org are skipped. The principal keeps them.

Why

cascadeRemovePrincipal in core/membership/org.go sorts the principal's policies into org, project and group policies. It first builds sets of the org's project ids and group ids:

  • s.projectService.List(ctx, project.Filter{OrgID: orgID})
  • s.groupService.List(ctx, group.Filter{OrganizationID: orgID})

Both lists return only enabled rows when no state is set. A policy on a disabled project or group is not in either set, so it is never classified and never deleted.

Failure case

  1. A user has a role on a project in the org.
  2. The project is disabled.
  3. The user is removed from the org, or the user is deleted.
  4. The policy on the disabled project stays live, with its SpiceDB tuples.
  5. If the project is enabled again, the removed user has access again.

The same applies to a disabled group.

Expected

The cascade covers disabled projects and groups. List them in every state, the same way the organization delete now does (list enabled and disabled separately). Add a test with a disabled project and a disabled group.

Notes

  • Same behavior on main today. It is not new.
  • Found while reviewing the organization soft delete work. The org delete itself is not affected, because it removes every child project and group first.
Lingua principale
Go
Stelle
344
Fork
48
Merge medio
1g 22h
PR unite (30g)
38

Preparare l'ambiente

  • Include un Dockerfile o un file Docker Compose
  • Ha un modello di pull request
  • Nessuna guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di raystack/frontier

Tutte le issue di raystack/frontier

Issue simili

Altre issue su Go

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.