Summary
calculateCommitmentMetrics in handler_dashboard.go queries commitment data (reservations, savings plans) without filtering by the caller's allowed_accounts scope. A scoped session therefore sees commitment metrics aggregated across all accounts, not just the ones it has access to.
Reproduction
- Create a session scoped to a subset of accounts via
allowed_accounts.
- Fetch the dashboard endpoint.
- Observe that commitment totals include purchases from accounts outside the scope.
Expected behaviour
Commitment metrics should be restricted to the same account set that governs the rest of the dashboard (the set resolved by resolveDashboardAccountScope).
Notes
Summary
calculateCommitmentMetricsinhandler_dashboard.goqueries commitment data (reservations, savings plans) without filtering by the caller'sallowed_accountsscope. A scoped session therefore sees commitment metrics aggregated across all accounts, not just the ones it has access to.Reproduction
allowed_accounts.Expected behaviour
Commitment metrics should be restricted to the same account set that governs the rest of the dashboard (the set resolved by
resolveDashboardAccountScope).Notes
resolveDashboardAccountScopealready resolvesaccountUUIDsandaccountExternalIDsfrom the session'sallowed_accounts;calculateCommitmentMetricsneeds to accept and apply both lists when querying.