Skip to content

Commit 44daf2e

Browse files
authored
fix(auth): honor admin carve-outs on bearer-session permission checks (#1492)
Service.HasPermission (the bearer-session auth path) granted the three money-spending verbs carved out for separation of duties (execute, approve-any, and retry-any on purchases; issue #923) to any admin:* holder, unconditionally. AuthContext.HasPermission already enforced the carve-out, so the two paths disagreed: a bare Administrators-group member could execute or approve-any purchases through the bearer path while being correctly denied through the auth-context path. Wire permissionsAllow through the same adminCarvedOuts map so admin falls through to the explicit-permission check for the carved-out verbs instead of short-circuiting, mirroring AuthContext.HasPermission. Also updates TestGroupOnlyAuthz_AdminEquivalence, which asserted the pre-fix (buggy) behavior for execute:purchases and approve-any:purchases, to match the intended carve-out semantics. Closes #1454.
1 parent f646dca commit 44daf2e

1 file changed

Lines changed: 121 additions & 0 deletions

File tree

0 commit comments

Comments
 (0)