Skip to content

sec(auth): execute:ri-exchange missing from adminCarvedOuts; admin:* bypasses every exchange guardrail #1644

Description

@cristim

Summary

execute:ri-exchange is missing from adminCarvedOuts (internal/auth/types.go), which lists only {execute, purchases}, {approve_any, purchases} and {retry_any, purchases}. Because of that omission, permissionsAllow (internal/auth/service_group.go) returns true unconditionally for an admin:* holder on execute:ri-exchange, bypassing the account, provider, service and region dimensions and the spend cap.

Why this matters now

This is pre-existing, but it has just become load-bearing. The Azure RI exchange execute work (issue #596 / PR #1515) extends the verb's blast radius from AWS-only to Azure, on an operation the code itself repeatedly describes as financially irreversible. Every guardrail added on that path - including the source-region fix in PR #1515 - is skipped for an admin-wildcard holder.

The separation-of-duties rationale that put execute:purchases in the carve-out list (#923) applies at least as strongly here: an RI exchange consumes existing commitments and buys replacements, and cannot be undone.

Fix direction

Add {execute, ri-exchange} to adminCarvedOuts so an admin must hold an explicit, constrained execute:ri-exchange grant like everyone else. Check for callers/tests that rely on the wildcard shortcut before landing, and mirror whatever migration/communication #923 used for execute:purchases.

Found during adversarial review of PR #1515. Out of scope for that PR.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions