refactor: Enforce per-org RBAC via organization member roles - #104
Merged
Conversation
Make `organization_members.role` the single source of truth for tenant permissions, closing the cross-tenant privilege escalation (BOLA/IDOR) vectors in the organizations and api-key plugins. - Access control service: add GetRolePermissionsByName/GetRoleWeightByName; remove ValidateRoleAssignment from the interface. - Org auth: export AuthorizeOrganizationAccess and enforce organization_id claim equality for machines and users; fail closed when no member row exists. - Org use cases: authorize per-request via the actor's membership role permissions (wildcard-aware) or token scopes for machine actors. - Purge org handlers' writes to global access_control_user_roles; keep the assign-role hook for platform-level use only. - Member/invitation writes are machine-forbidden and gated by role weight (heavier target => 403, missing target => 400); RemoveMember gains weight and owner-protection guards. - Add RequireActor(ActorUser) to member/invitation write routes. - api-key: org-owned key Create/Update require the requester's membership in the org and requested key perms to be a subset of their per-org perms. - Tests: coverage for claim binding, per-role permission gating, machine restrictions, RemoveMember guards, and the new access-control methods.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Make
organization_members.rolethe single source of truth for tenant permissions, closing the cross-tenant privilege escalation (BOLA/IDOR) vectors in the organizations and api-key plugins.