Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions db/migrations/20260725120000_add-rbac-indexes.sql
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
-- 2026-07-25 12:00:00 : add-rbac-indexes

CREATE INDEX IF NOT EXISTS "IX_RbacGroupMember_UserId" ON "RbacGroupMember" ("UserId");
CREATE INDEX IF NOT EXISTS "IX_RbacPermissionGrants_AssignedEntityId_Lower" ON "RbacPermissionGrants" (lower("AssignedEntityId"));
CREATE INDEX IF NOT EXISTS "IX_RbacRoleGrants_AssignedEntityId_Lower" ON "RbacRoleGrants" (lower("AssignedEntityId"));
CREATE INDEX IF NOT EXISTS "IX_RbacRoleGrants_AssignedEntityId" ON "RbacRoleGrants" ("AssignedEntityId");
CREATE INDEX IF NOT EXISTS "IX_RbacRole_Name_Lower" ON "RbacRole" (lower("Name"));
1 change: 1 addition & 0 deletions db/seed/RbacPermissionGrants.csv
Original file line number Diff line number Diff line change
Expand Up @@ -138,5 +138,6 @@ BE05A459-AA3A-4A74-B300-62BA19B50618;2026-07-23T09:15:35.802676;Role;5E32EE6A-1A
B908B85B-8489-4E5F-8130-BFA4FAA7A631;2026-07-23T09:15:35.802680;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;get-user-emails;Global;
FAABC901-C540-4FDD-9408-16812B3683E3;2026-07-23T09:15:35.802684;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;delete-membership-application-as-admin;Global;
708B2C75-2CDD-4545-A717-D5BBDE8C9884;2026-07-23T09:15:35.802688;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;retry-creating-message-contract;Global;
77763D1C-2D3A-426F-BB4B-CDBFC48BDC3D;2026-07-23T09:15:35.802690;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;manage-json-schemas;Global;
7E6A90BB-9E8C-4F11-AFE8-F53D97B4B803;2026-07-23T09:15:35.802693;Role;6A2EE52C-6A9B-4A2A-B9C8-5851DD2D9A6F;capability-management;batch-create-capabilities;Global;
213F793E-3048-427E-863C-D359BBA7D9CA;2026-07-23T09:15:35.802697;Role;A983CF2E-772E-437D-B9D8-5DDF769339D3;service-catalogue;read;Global;
Original file line number Diff line number Diff line change
Expand Up @@ -127,6 +127,9 @@ public async Task submit_membership_application_auto_finalizes_when_capability_h

Assert.NotNull(added);
Assert.True(added!.IsFinalized);
rbacService.Verify(x => x.GrantRoleGrant(userId.ToString(), It.IsAny<RbacRoleGrant>()), Times.Once);
rbacService.Verify(
x => x.GrantRoleGrant(userId.ToString(), It.IsAny<RbacRoleGrant>(), It.IsAny<bool>()),
Times.Once
);
}
}
135 changes: 135 additions & 0 deletions src/SelfService.Tests/Application/TestRbacApplicationService.cs
Original file line number Diff line number Diff line change
Expand Up @@ -758,4 +758,139 @@ await rbacSvc.IsUserPermitted(
);
*/
}

private static RbacPermissionGrant UserGrant(RbacAccessType type, string resource) =>
new(
id: RbacPermissionGrantId.New(),
createdAt: DateTime.Now,
assignedEntityType: AssignedEntityType.User,
assignedEntityId: "test01@dfds.cloud",
@namespace: RbacNamespace.Rbac,
permission: "create",
type: type,
resource: resource
);

private static Permission RbacCreate(RbacAccessType accessType) =>
new()
{
Namespace = RbacNamespace.Rbac,
Name = "create",
AccessType = accessType,
};

[Fact]
public async Task CapabilityScopedGrantDoesNotSatisfyGlobalCheck()
{
var fixture = await RbacTestData.NewInMemoryFixture(
true,
new List<RbacPermissionGrant> { UserGrant(RbacAccessType.Capability, "test01") },
new List<RbacRoleGrant>()
);
var rbacSvc = fixture.ApiApplication.Services.GetService<IRbacApplicationService>()!;

// The object id matches the grant's resource exactly — before the fix that alone was enough.
Assert.False(
(
await rbacSvc.IsUserPermitted("test01@dfds.cloud", [RbacCreate(RbacAccessType.Global)], "test01")
).Permitted()
);

// The same grant still answers the capability-scoped question it was issued for.
Assert.True(
(
await rbacSvc.IsUserPermitted("test01@dfds.cloud", [RbacCreate(RbacAccessType.Capability)], "test01")
).Permitted()
);
}

[Fact]
public async Task GlobalGrantSatisfiesBothCapabilityAndGlobalChecks()
{
var fixture = await RbacTestData.NewInMemoryFixture(
true,
new List<RbacPermissionGrant> { UserGrant(RbacAccessType.Global, "") },
new List<RbacRoleGrant>()
);
var rbacSvc = fixture.ApiApplication.Services.GetService<IRbacApplicationService>()!;

Assert.True(
(
await rbacSvc.IsUserPermitted("test01@dfds.cloud", [RbacCreate(RbacAccessType.Global)], "test01")
).Permitted()
);

// This is how the CloudEngineers group keeps working: its role grant is Global, and the
// routes it reaches are largely capability-scoped.
Assert.True(
(
await rbacSvc.IsUserPermitted("test01@dfds.cloud", [RbacCreate(RbacAccessType.Capability)], "test01")
).Permitted()
);
}

[Fact]
public async Task RoleDerivedGrantsFollowTheSameScopeHierarchy()
{
// GetPermissionGrantsForRoleGrants stamps the role grant's type/resource onto every
// permission of the role, so the second FindAll pass needs its own coverage.
var capabilityRoleId = RbacRoleId.New();
var globalRoleId = RbacRoleId.New();

RbacPermissionGrant RolePermission(RbacRoleId roleId) =>
new(
id: RbacPermissionGrantId.New(),
createdAt: DateTime.Now,
assignedEntityType: AssignedEntityType.Role,
assignedEntityId: roleId.ToString(),
@namespace: RbacNamespace.Rbac,
permission: "create",
type: RbacAccessType.Global,
resource: ""
);

RbacRoleGrant RoleGrant(RbacRoleId roleId, string user, RbacAccessType type, string resource) =>
new(
id: RbacRoleGrantId.New(),
roleId: roleId,
createdAt: DateTime.Now,
assignedEntityType: AssignedEntityType.User,
assignedEntityId: user,
type: type,
resource: resource
);

var fixture = await RbacTestData.NewInMemoryFixture(
true,
new List<RbacPermissionGrant> { RolePermission(capabilityRoleId), RolePermission(globalRoleId) },
new List<RbacRoleGrant>
{
RoleGrant(capabilityRoleId, "owner@dfds.cloud", RbacAccessType.Capability, "test01"),
RoleGrant(globalRoleId, "admin@dfds.cloud", RbacAccessType.Global, ""),
}
);
var rbacSvc = fixture.ApiApplication.Services.GetService<IRbacApplicationService>()!;

Assert.False(
(
await rbacSvc.IsUserPermitted("owner@dfds.cloud", [RbacCreate(RbacAccessType.Global)], "test01")
).Permitted()
);
Assert.True(
(
await rbacSvc.IsUserPermitted("owner@dfds.cloud", [RbacCreate(RbacAccessType.Capability)], "test01")
).Permitted()
);

Assert.True(
(
await rbacSvc.IsUserPermitted("admin@dfds.cloud", [RbacCreate(RbacAccessType.Global)], "test01")
).Permitted()
);
Assert.True(
(
await rbacSvc.IsUserPermitted("admin@dfds.cloud", [RbacCreate(RbacAccessType.Capability)], "test01")
).Permitted()
);
}
}
Loading
Loading