Skip to content

fix(auth): authorize project-member collections against requested project - #47

Merged
chen21019 merged 1 commit into
mainfrom
verification/orchestration-engine-authz-20260923
Sep 23, 2026
Merged

chen21019 merged 1 commit into
mainfrom
verification/orchestration-engine-authz-20260923

Conversation

@chen21019

Copy link
Copy Markdown

Root cause\nA caller could select authorized project A in X-API-Project-Id while querying projectId=B; v1/v2-beta project-member collection loaded B before checking that the token owner could access B.\n\n## Fix\nRequire project access on the requested project before loading members; use the same guard for object access, retain legitimate member/readonly reads and existing write authorization.\n\n## Verification\n- Focused ProjectMemberResourceManagerAuthorizationTest passed.\n- scripts/check-pasturestack-source passed at 0.183.320.\n- Old QA v1/v2-beta matrix reproduced HTTP 200 leaking eight B members; new QA image and browser matrix pending release.\n\nNo production deployment.

@chen21019
chen21019 requested a review from a team as a code owner September 23, 2026 14:27
@chen21019
chen21019 force-pushed the verification/orchestration-engine-authz-20260923 branch from 6d61d24 to 141d56b Compare September 23, 2026 14:35
@chen21019
chen21019 merged commit 2684691 into main Sep 23, 2026
7 checks passed
@chen21019
chen21019 deleted the verification/orchestration-engine-authz-20260923 branch September 23, 2026 14:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant