Summary
GetUserPermissions / collectGroupsAndAccounts in internal/auth/service_group.go (around lines 69-78 and 113-122) swallow per-group fetch errors: on a transient DB error fetching one of the user's groups they logging.Warnf(...); continue, then return the permission union of the remaining groups.
Consequences:
- For a multi-group user, a transient failure loading one group silently under-grants (computes the union of a subset), producing inconsistent authorization decisions.
- A real DB outage is masked as a permission denial with no error surfaced to the caller — there is no way to distinguish "user genuinely lacks permission" from "lookup degraded."
It is technically fail-closed (good for safety), but the permission union is not computed correctly under partial failure, and the degraded state is invisible.
Surfaced by the post-merge security review of #912 (2026-06-02), finding MEDIUM-1.
Fix
Propagate the error from GetUserPermissions on any per-group fetch failure (do not continue), so callers fail closed with an error rather than silently with a smaller permission set. At minimum do this for the Administrators-group lookup. Add a test that a per-group fetch error returns an error (not a partial union).
Location
internal/auth/service_group.go:69-78, :113-122.
Summary
GetUserPermissions/collectGroupsAndAccountsininternal/auth/service_group.go(around lines 69-78 and 113-122) swallow per-group fetch errors: on a transient DB error fetching one of the user's groups theylogging.Warnf(...); continue, then return the permission union of the remaining groups.Consequences:
It is technically fail-closed (good for safety), but the permission union is not computed correctly under partial failure, and the degraded state is invisible.
Surfaced by the post-merge security review of #912 (2026-06-02), finding MEDIUM-1.
Fix
Propagate the error from
GetUserPermissionson any per-group fetch failure (do notcontinue), so callers fail closed with an error rather than silently with a smaller permission set. At minimum do this for the Administrators-group lookup. Add a test that a per-group fetch error returns an error (not a partial union).Location
internal/auth/service_group.go:69-78,:113-122.