Repository navigation
Commit 44daf2e
authored
fix(auth): honor admin carve-outs on bearer-session permission checks (#1492)
Service.HasPermission (the bearer-session auth path) granted the three
money-spending verbs carved out for separation of duties (execute,
approve-any, and retry-any on purchases; issue #923) to any admin:*
holder, unconditionally. AuthContext.HasPermission already enforced
the carve-out, so the two paths disagreed: a bare Administrators-group
member could execute or approve-any purchases through the bearer path
while being correctly denied through the auth-context path.
Wire permissionsAllow through the same adminCarvedOuts map so admin
falls through to the explicit-permission check for the carved-out
verbs instead of short-circuiting, mirroring AuthContext.HasPermission.
Also updates TestGroupOnlyAuthz_AdminEquivalence, which asserted the
pre-fix (buggy) behavior for execute:purchases and approve-any:purchases,
to match the intended carve-out semantics.
Closes #1454.1 parent f646dca commit 44daf2e
1 file changed
Lines changed: 121 additions & 0 deletions
0 commit comments