You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The daemon log paths combined the daemon flag with the authorizer result as isDaemon || allowed, so the configured logs.users/logs.groups result was discarded for daemon files.
The three daemon log paths (page, download, search) now evaluate the same lists the worker log paths already use. Extends ResourceAuthorizerTest and the three handler tests.
Disclaimer: this comment was drafted with the help of an LLM.
Thanks for tightening up the daemon-log authorization here — the per-endpoint deny tests are a nice addition.
One small suggestion on coverage: both ResourceAuthorizer tests stub getUserGroups(...) to return an empty set, so the group-based path (logs.groups / nimbus.admins.groups) isn't actually exercised. A case where a user is authorized purely via group membership would close that gap. Separately, the three handler tests assert the 403 deny path but not the authorized 200 path — a positive case could guard against accidentally over-blocking.
Neither is a blocker — just an additional safeguard for a security-sensitive change.
Disclaimer: this comment was drafted with the help of an LLM.
Thanks for tightening up the daemon-log authorization here — the per-endpoint deny tests are a nice addition.
One small suggestion on coverage: both ResourceAuthorizer tests stub getUserGroups(...) to return an empty set, so the group-based path (logs.groups / nimbus.admins.groups) isn't actually exercised. A case where a user is authorized purely via group membership would close that gap. Separately, the three handler tests assert the 403 deny path but not the authorized 200 path — a positive case could guard against accidentally over-blocking.
Neither is a blocker — just an additional safeguard for a security-sensitive change.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The daemon log paths combined the daemon flag with the authorizer result as
isDaemon || allowed, so the configuredlogs.users/logs.groupsresult was discarded for daemon files.The three daemon log paths (page, download, search) now evaluate the same lists the worker log paths already use. Extends
ResourceAuthorizerTestand the three handler tests.