Repository navigation
Block viewer workspace mutations; enforce tenant ownership references - #175
Merged
Merged
Conversation
Creating and deleting teams, deployments and infrastructure rows, the AWS cost sync, and POST /api/services/discover checked only that the caller was authenticated, so a viewer could do all of them. They now require owner, admin or member (requireMember, on the caller's current membership role). Nothing changes for those three roles. POST /api/services/discover also takes the existing discoveryRateLimiter, so it shares the per-organization discovery budget with POST /api/aws-resources/discover instead of being unlimited. POST /api/infrastructure/sync-aws gets a per-organization limit of its own: a sync whose result is not already cached makes a billed Cost Explorer call. The GitHub webhook and the scheduled discovery job carry no user and do not pass through these checks. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
POST /api/services stored whatever team_id it was given, and POST /api/infrastructure whatever service_id: the foreign key only proved the row existed somewhere, so a service could point at another organization's team and a resource at another organization's service. Both inserts now select from the referenced row with the caller's organization in the predicate, in the same statement as the insert (the shape the deployments insert already uses). An id that belongs to another organization is answered exactly like one that exists nowhere: 404, same body, nothing written. The organization still comes only from the authenticated request. An id that exists nowhere used to surface as a foreign-key 500; it is now the same 404. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two commits. (1) requireMember on POST/DELETE /api/teams, POST/DELETE /api/deployments, POST/DELETE /api/infrastructure, POST /api/infrastructure/sync-aws and POST /api/services/discover, so viewers get 403 while member/admin/owner behavior is unchanged; /api/services/discover shares the existing per-organization discovery limiter, and sync-aws gets its own 10/hour/org limiter. (2) team_id on POST /api/services and service_id on POST /api/infrastructure are validated against the caller's organization in the same statement as the insert; foreign and nonexistent ids return the same 404. No policy changes, no frontend, schema, webhook or IAM changes.