Skip to content

fix(auth): propagate per-group permission-fetch errors in GetUserPermissions (no silent under-grant) #918

Description

@cristim

Summary

GetUserPermissions / collectGroupsAndAccounts in internal/auth/service_group.go (around lines 69-78 and 113-122) swallow per-group fetch errors: on a transient DB error fetching one of the user's groups they logging.Warnf(...); continue, then return the permission union of the remaining groups.

Consequences:

  • For a multi-group user, a transient failure loading one group silently under-grants (computes the union of a subset), producing inconsistent authorization decisions.
  • A real DB outage is masked as a permission denial with no error surfaced to the caller — there is no way to distinguish "user genuinely lacks permission" from "lookup degraded."

It is technically fail-closed (good for safety), but the permission union is not computed correctly under partial failure, and the degraded state is invisible.

Surfaced by the post-merge security review of #912 (2026-06-02), finding MEDIUM-1.

Fix

Propagate the error from GetUserPermissions on any per-group fetch failure (do not continue), so callers fail closed with an error rather than silently with a smaller permission set. At minimum do this for the Administrators-group lookup. Add a test that a per-group fetch error returns an error (not a partial union).

Location

internal/auth/service_group.go:69-78, :113-122.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    effort/sHoursimpact/all-usersAffects every userpr-createdA PR has been opened for this issue (dedup guard for the auto-PR loop)pr-mergedThe PR for this issue has been mergedpriority/p3Polish / idea / may never shipseverity/mediumModerate harmtriagedItem has been triagedtype/bugDefecturgency/this-sprintWithin the current sprint

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions