Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 4 included reviews per hour; 3 remain after this review. 📝 SummarySummary
Changed files
API/CRD surface
Tests
Risk hotspots
Review finding severity counts: unavailable from the supplied evidence. WalkthroughThe authorization registry adds ChangesPortal assistant authorization
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix · Severity of issue fixed: Low Merge Risk: ⚪ Minimal · up to The portal assistant permission is registered as a public cluster-scoped action, and bootstrap-role configuration is checked against the action registry. No merge-blocking risk was identified. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
5de73a3 to
fa658c7
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
|
@kavix There are some conflicts. Can you resolve those and push again? |
fa658c7 to
98e6e07
Compare
|
@mevan-karu Done! |
There was a problem hiding this comment.
Any reason for the file name? We have to have files for code and the test which follows name_test.go.
There was a problem hiding this comment.
Moved into actions_test.go to match convention and removed chart_roles_test.go.
…ation test (openchoreo#4683) Signed-off-by: Kavindu Sachinthe <[email protected]>
98e6e07 to
2f2b51f
Compare
|
Hi @LakshanSS can you look into this thank you |
Purpose
Resolves #4683 (codebase portion).
During the authorization audit in #4683,
portal-assistant:invokewas found to be granted toplatform-engineeranddeveloperroles in Helm chart values (install/helm/openchoreo-control-plane/values.yaml), and actively enforced byAuthRuntimeinagents/portal-assistant/src/auth.pyandagent_routes.py. However, it was missing from the registry ininternal/authz/core/actions.go.This PR formally registers
ActionInvokePortalAssistantand introduces an automated drift-guard test to prevent future divergence between Helm bootstrap roles and the core action registry.Approach
ActionInvokePortalAssistant = "portal-assistant:invoke"ininternal/authz/core/actions.gowith lowest scopeScopeClusterandIsInternal: false.internal/authz/core/chart_roles_test.go(TestBootstrapRoles_ActionValidity) which parsesinstall/helm/openchoreo-control-plane/values.yamland validates that every action granted across all bootstrap roles exists incore.ConcretePublicActions().Related Issues
Checklist
backport/<release-branch>label if this should be backported (e.g.,backport/release-v1.0)Remarks
Documentation updates bringing the 165 actions and 11 default roles up to date are submitted in companion PR: openchoreo/openchoreo.github.io#857