UpdateProjectResource: title wipe, 403-vs-404 on missing resource, 500 on bad project_id, unguarded cross-org move
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 45/100
- issue の種類
- バグ
- 明瞭さ
- おおむね明確
- 活発さ
- 静か
- 技術スタック
- go
- 領域
- authorization, backend
調査の方向性
まず、UpdateProjectResource handler、その GetProject lookup、および認可の事前チェックを追跡し、タイトル、存在しないリソース、無効なプロジェクト、組織間の移動、カスタム namespaces について、列挙された更新リクエストを再現します。各ケースに意図した文書化済みの結果があり、リソースのタイトルと組織階層が正しい状態に保たれていれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Summary
While verifying PR #1686 (UpdateProjectResource now reconciles #project/#owner relations) end-to-end against a local server, a few pre-existing issues surfaced in UpdateProjectResource and the resource authorization path. The PR's own behavior is correct — these are separate, and most predate it. Filing together.
1. UpdateProjectResource silently wipes the resource title
The handler builds the resource.Resource it passes to the service without reading body.title, so Title is always empty. Combined with the repository now persisting title, any update blanks the title — even if the request body sets one.
Repro
CreateProjectResourcewithtitle: "Original Title".UpdateProjectResourcefor it (with or withouttitlein the body).- Read the resource.
Actual: stored title becomes "".
Expected: title is preserved, or updated to the value sent in the body.
Note: this lives in the same RPC PR #1686 reworks, so it may be worth addressing there.
2. Updating a nonexistent resource returns 403 PermissionDenied instead of 404 NotFound
The authorization interceptor runs CheckAuthz(caller, <resource>, "update") before the service checks existence. For a resource id that doesn't exist there are no #project/#owner/org relations to resolve authority through, so even a platform superuser is denied — and the handler's ErrNotExist → NotFound mapping is effectively unreachable.
Repro: UpdateProjectResource with a random (valid-UUID) id in an existing namespace.
Actual: 403 permission_denied. Expected: 404 NotFound (or a deliberate not-leak-existence decision, documented).
3. UpdateProjectResource with a bad project_id returns 500 Internal
The handler resolves the parent project up front and wraps any GetProject error as CodeInternal, so a non-existent/invalid project_id surfaces as a 500.
Repro: UpdateProjectResource with project_id set to a random UUID.
Actual: 500 internal. Expected: 400 InvalidArgument or 404 NotFound.
4. Resources can be moved across organizations with no guard
UpdateProjectResource lets you move a resource to a project that belongs to a different organization; the #project relation is repointed to the other org's project and the move succeeds. PR #1686 makes project moves actually take effect, so this is now reachable.
Repro: create a resource under a project in org A, then UpdateProjectResource with project_id of a project in org B.
Actual: 200, resource now lives under org B's project.
Question: is a cross-org move intended? If not, it should be rejected; the resource otherwise ends up under a different org's hierarchy.
5. Resource-mutation RPCs require the namespace to define the matching verb (related to #1693)
UpdateProjectResource/DeleteProjectResource/GetProjectResource run an authz precheck for update/delete/get on the resource type. A custom namespace created via CreatePermission only has the verbs you defined, so if it lacks (say) update, the precheck fails at schema-compile time:
IsAuthorized.CheckAuthz ... FailedPrecondition: relation/permission `update` not found under definition `<namespace>`
and the call 500s. This is the same family as the DeleteProjectResource 500 in #1693 (finding 1); noting here for completeness as it affects update/get too.
Found while manually testing PR #1686. The reconcile behavior in that PR works correctly.
- 主要言語
- Go
- スター
- 344
- フォーク
- 48
- 平均マージ
- 1日 22時間
- マージ済み PR(30日)
- 38
環境構築
- Dockerfile または Docker Compose ファイルあり
- プルリクエストのテンプレートあり
- コントリビューションガイドなし
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
raystack/frontier のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 62/100
メンテナーはふだん 1 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 62/100
メンテナーはふだん 1 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 52/100
メンテナーはふだん 1 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 58/100
メンテナーはふだん 1 日以内に返信
raystack/frontier の issue をすべて見る
似ている issue
-
bug go
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
genkit-ai/genkit#6761 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信
-
ready
難易度 2/5 1〜3時間 初心者へのやさしさ 92/100
kubeflow/pipelines#14784 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信
-
bug frontend good first issue
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100
メンテナーはふだん 1 日以内に返信
-
trust: update-propagation-directive requires developer mode while add and remove do not対応中かも @bhuvan-somisetty が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
メンテナーはふだん 2 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 82/100
oalders/clodhopper#133 ·