Skip to content

refactor: Enforce per-org RBAC via organization member roles - #104

Merged
m-t-a97 merged 1 commit into
mainfrom
refactor/organizations-rbac
Aug 6, 2026
Merged

refactor: Enforce per-org RBAC via organization member roles#104
m-t-a97 merged 1 commit into
mainfrom
refactor/organizations-rbac

Conversation

@m-t-a97

@m-t-a97 m-t-a97 commented Aug 6, 2026

Copy link
Copy Markdown
Member

Make organization_members.role the single source of truth for tenant permissions, closing the cross-tenant privilege escalation (BOLA/IDOR) vectors in the organizations and api-key plugins.

  • Access control service: add GetRolePermissionsByName/GetRoleWeightByName; remove ValidateRoleAssignment from the interface.
  • Org auth: export AuthorizeOrganizationAccess and enforce organization_id claim equality for machines and users; fail closed when no member row exists.
  • Org use cases: authorize per-request via the actor's membership role permissions (wildcard-aware) or token scopes for machine actors.
  • Purge org handlers' writes to global access_control_user_roles; keep the assign-role hook for platform-level use only.
  • Member/invitation writes are machine-forbidden and gated by role weight (heavier target => 403, missing target => 400); RemoveMember gains weight and owner-protection guards.
  • Add RequireActor(ActorUser) to member/invitation write routes.
  • api-key: org-owned key Create/Update require the requester's membership in the org and requested key perms to be a subset of their per-org perms.
  • Tests: coverage for claim binding, per-role permission gating, machine restrictions, RemoveMember guards, and the new access-control methods.

Make `organization_members.role` the single source of truth for tenant
permissions, closing the cross-tenant privilege escalation (BOLA/IDOR)
vectors in the organizations and api-key plugins.

- Access control service: add GetRolePermissionsByName/GetRoleWeightByName;
  remove ValidateRoleAssignment from the interface.
- Org auth: export AuthorizeOrganizationAccess and enforce organization_id
  claim equality for machines and users; fail closed when no member row exists.
- Org use cases: authorize per-request via the actor's membership role
  permissions (wildcard-aware) or token scopes for machine actors.
- Purge org handlers' writes to global access_control_user_roles; keep the
  assign-role hook for platform-level use only.
- Member/invitation writes are machine-forbidden and gated by role weight
  (heavier target => 403, missing target => 400); RemoveMember gains weight
  and owner-protection guards.
- Add RequireActor(ActorUser) to member/invitation write routes.
- api-key: org-owned key Create/Update require the requester's membership
  in the org and requested key perms to be a subset of their per-org perms.
- Tests: coverage for claim binding, per-role permission gating, machine
  restrictions, RemoveMember guards, and the new access-control methods.
@m-t-a97 m-t-a97 self-assigned this Aug 6, 2026
@m-t-a97
m-t-a97 merged commit 9da2394 into main Aug 6, 2026
6 checks passed
@m-t-a97
m-t-a97 deleted the refactor/organizations-rbac branch August 6, 2026 05:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant