Removing a member from an org leaves their policies on disabled projects and groups
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 62/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- go
- Ambito
- authorization
Direzione di ricerca
Start in cascadeRemovePrincipal in core/membership/org.go, where the project and group id sets are built from projectService.List and groupService.List with only the org filter. Mirror the organization delete path, which lists enabled and disabled rows separately, so disabled projects and groups are included in the classification. Done when a test covering a disabled project and a disabled group shows their policies and SpiceDB tuples removed on member removal.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
What happens
When a member, service user or group is removed from an organization, or a user is deleted, the policies of that principal in the org are supposed to be removed. Policies on disabled projects and disabled groups of the org are skipped. The principal keeps them.
Why
cascadeRemovePrincipal in core/membership/org.go sorts the principal's policies into org, project and group policies. It first builds sets of the org's project ids and group ids:
s.projectService.List(ctx, project.Filter{OrgID: orgID})s.groupService.List(ctx, group.Filter{OrganizationID: orgID})
Both lists return only enabled rows when no state is set. A policy on a disabled project or group is not in either set, so it is never classified and never deleted.
Failure case
- A user has a role on a project in the org.
- The project is disabled.
- The user is removed from the org, or the user is deleted.
- The policy on the disabled project stays live, with its SpiceDB tuples.
- If the project is enabled again, the removed user has access again.
The same applies to a disabled group.
Expected
The cascade covers disabled projects and groups. List them in every state, the same way the organization delete now does (list enabled and disabled separately). Add a test with a disabled project and a disabled group.
Notes
- Same behavior on
maintoday. It is not new. - Found while reviewing the organization soft delete work. The org delete itself is not affected, because it removes every child project and group first.
- Lingua principale
- Go
- Stelle
- 344
- Fork
- 48
- Merge medio
- 1g 22h
- PR unite (30g)
- 38
Preparare l'ambiente
- Include un Dockerfile o un file Docker Compose
- Ha un modello di pull request
- Nessuna guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di raystack/frontier
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 62/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 52/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 58/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 68/100
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di raystack/frontier
Issue simili
-
bug triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
FairwindsOps/nova#484 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
I maintainer di solito rispondono entro 1 giorno
-
automated-analysis code-quality cookie
Difficoltà 2/5 1-3 ore Idoneità per principianti 66/100
github/gh-aw#67517 · 3 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
[otelcol] print-config help text still requires the removed otelcol.printInitialConfig feature gateForse già presa @girishkvs l’ha presa oggi. Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
open-telemetry/opentelemetry-collector#16143 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
bug good first issue load-balancing
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
ktrubilo9/edge-proxy#53 ·