Repository navigation
fix: role grants, admin audit and OIDC settings - #787
Merged
Merged
Conversation
data_analyst held transforms:* and infra_viewer service-surface:read, but the routes check transform:compile, transform:test and service_surface:read, so neither grant matched anything and only admin could compile or test a transform. The grants now name the catalogue's actions, and API_ENFORCED_ACTIONS drops the plural transform actions plus config:read and query:write, which no route enforces. A new test fails when a built-in grant names a domain or exact action the catalogue does not define. Account, group, API key and role writes under /api/v1/auth now each emit one audit event with the actor, the change and the target. Details carry the roles, groups, members or permissions written and the names of contact fields changed, never a password, a hash, an attribute value or the secret half of an API key. audit_role_change is new; the account, group and API key helpers take an optional details dict. auth.oidc.providers_dir, sync_enabled and sync_on_startup are removed: nothing read them, the providers directory is always <auth_dir>/oidc-providers, and oidc_group_sync_enabled already gates the background sync. A config file still carrying auth.oidc loads unchanged. DFE_AUTH_OIDC_GROUP_SYNC_ENABLED and DFE_AUTH_OIDC_GROUP_SYNC_TICK_SECONDS were named in field help but never read. Both are now routed in the env overrides and listed in the AuthSettings docstring, where the existing guard test checks them. rbac.md matches: the transform grant, the new audit events, the env vars, and the fact that an existing rbac/roles.yaml is never rewritten, so a changed built-in grant reaches a running deployment only by editing that file.
This was referenced Oct 10, 2026
|
Released in v1.22.18 -- https://github.com/hyperi-io/dfe-engine/releases/tag/v1.22.18 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Four engine defects found reading rbac.md against the code. All small, all in auth.
transforms:*, the routes checktransform:compileandtransform:test, so only admin passed. Same shape for infra_viewer'sservice-surface:readvs the catalogue'sservice_surface:read. Both grants now name the catalogue's actions.API_ENFORCED_ACTIONSalso listed the plural, plusconfig:readandquery:write, which no route enforces. Gone.API_ENFORCED_ACTIONSinside the scope constants, so the plural cannot sneak back in through it./api/v1/auth/{accounts,groups,api-keys,roles}now emits one event: actor, change, target. Details carry roles, groups, members or permissions, and contact field NAMES only. Never a password, hash, attribute value or the secret half of a key.audit_role_changeis new.auth.oidc.providers_dir,sync_enabledandsync_on_startupparsed and did nothing. Removed. The providers dir is always<auth_dir>/oidc-providersandoidc_group_sync_enabledalready gates the sync. A config file still carryingauth.oidcloads fine.DFE_AUTH_OIDC_GROUP_SYNC_ENABLEDandDFE_AUTH_OIDC_GROUP_SYNC_TICK_SECONDSwere documented and never read. Now routed, and in the docstring the env-var guard test parses.Existing deployments keep the old grants. The engine seeds
rbac/roles.yamlonce and never rewrites it, and the API refuses edits to built-in roles, so a running deployment picks up the fixed data_analyst grant only when someone edits that file. rbac.md now says so.Done when CI is green and data_analyst can hit
/api/v1/transforms/compileon a fresh deployment.