fix(auth): enforce marketplace permission constraints - #460
Merged
Merged
Conversation
Bind mixed credentials to one owner and retain the effective key's selected sell action. Check stored purchase scope and allowed accounts before listing claims or provider calls, including constrained admins. Verify real HTTP, auth, and PostgreSQL behavior with isolated EC2 fixtures. Refs #404 (marketplace portion; revoke remains).
Contributor
|
Warning Review limit reached
This review includes 5 billable files and costs up to $1.25.
Reviews can continue after your included limit without a manual trigger. An admin must approve usage-based billing. Or wait 23 minutes for your next included review. View limit detailsLimit details: You’ve used the included review currently available. Your 70 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Review configuration: ⚙️ Run configurationConfiguration used: Repository: LeanerCloud/cloud-commitments-platform/.coderabbit.yaml Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (5)
Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Marketplace list and cancel could ignore permission constraints, let
sell-anybypass account scope, and use a bearer session's broader permissions despite a narrower API key. Both routes now select the effective principal's sell action and check the stored purchase's account, provider, service, and region before provider calls or listing writes.Mixed key and bearer credentials must have the same owner. Existing session-only eligibility remains, and a selected action's constraint denial cannot fall back to a broader identity or another action. Missing record metadata requires an unrestricted grant for that dimension. No sale-price limit is inferred from purchase-amount constraints.
Validation:
HandleRequestand the production router, backed by real auth service and PostgreSQL stores. The baseline reproduced 34 unauthorized successful mutations across both routes; positive controls passed. The fixed matrix verifies persisted success, unchanged denied rows, and zero provider-factory calls on denial.a3ec6f6c7ed2858403ce52500cebc3bfb0f0b3f1with no actionable findings. The reviewer independently reproduced all 34 baseline violations, then passed the committed HTTP, lookup-error, and action-selection tests with the race detector in 3.844s on a fresh PostgreSQL database.Refs #404. Depends on merged #456. This is part 2: scheduled/completed revoke and Azure refund quote enforcement remain required, so #404 stays open.