Skip to content

fix(rbac): filter single-resource reads by row for guests - #3536

Merged
adityathebe merged 2 commits into
mainfrom
claude/guest-resource-reads
Oct 6, 2026
Merged

adityathebe merged 2 commits into
mainfrom
claude/guest-resource-reads

Conversation

@adityathebe

Copy link
Copy Markdown
Member

Implements specs/authorization/collection-access.md (#3515), §2: a guest opening one resource is checked against their grants only, never passed by the built-in read.

Problem

Guests pass whole-type read checks as viewers so that their listings can be filtered by row. These routes were authorized only by that whole-type check and didn't run under row-level security, so a guest could open any resource by id:

  • GET /snapshot/topology/:id, /snapshot/incident/:id, /snapshot/config/:id
  • GET /application/:namespace/:name and /export
  • GET /playbook/run/:id and /:id/status

/db, /resources/:id and /catalog/* already run under row-level security.

Change

Add RLSMiddleware to those routes. For subjects whose rows aren't filtered, the middleware is a no-op. For a guest, a resource outside their grants is now not found, the same as an id that doesn't exist.

Tests

tests/permissions/playbook_list_test.go "opening a run": a run of a playbook outside the caller's row filters returns 404, and one inside returns 200. The permissions suite passes locally (199/199).


Generated by Claude Code

@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 13 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: b40d5470-d9b1-4c87-9b67-73248deb4821
📥 Commits

Reviewing files that changed from the base of the PR and between 44fec21 and 6a654fd.

📒 Files selected for processing (4)
  • application/controller.go
  • playbook/controllers.go
  • snapshot/controllers.go
  • tests/permissions/playbook_list_test.go
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

claude added 2 commits October 6, 2026 19:57
Snapshots, application specs and playbook runs were authorized only
by a whole-type read, which guests pass so that their listings can be
filtered by row. They didn't run under row-level security, so a guest
could open any config, component or playbook run by id.

They now run under row-level security, so a resource outside a guest's
grants isn't found, as specs/authorization/collection-access.md §2
requires.
@adityathebe
adityathebe force-pushed the claude/guest-resource-reads branch from 819e05c to 6a654fd Compare October 6, 2026 14:12
@adityathebe
adityathebe enabled auto-merge (squash) October 6, 2026 14:13
@adityathebe
adityathebe merged commit 1f252da into main Oct 6, 2026
10 of 11 checks passed
@adityathebe
adityathebe deleted the claude/guest-resource-reads branch October 6, 2026 14:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants