fix(notification-actions): Better access control for org-wide actions#113718
Merged
fix(notification-actions): Better access control for org-wide actions#113718
Conversation
saponifi3d
approved these changes
Apr 22, 2026
Contributor
saponifi3d
left a comment
There was a problem hiding this comment.
lgtm - just the question about if this should support org:write & alerts:write
| # If the action has no projects, skip the project access check | ||
| # Notification actions not scoped to a particular project require org-level write access for mutations. | ||
| if not action_projects: | ||
| if request.method != "GET" and not request.access.has_scope("org:write"): |
Contributor
There was a problem hiding this comment.
🤔 should we also check for the alerts:write scope here? that's meant to allow users to have access to these permissions separately from the org scopes; but not sure if we want to enforce that on actions as well?
Member
Author
There was a problem hiding this comment.
It's a bit confusing, but these notification actions are not related to workflow engine at all. These models are used for spike protection notifications
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes ISWF-2503
Tightens up the access control for actions not scoped to a particular project.