mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-08-29 19:57:12 +00:00
feat(rbac): make stack-scoped grants node-specific (#1727)
* feat(rbac): make stack-scoped grants node-specific Qualify stack role assignments as (nodeId, stackName), migrate legacy rows to the default node, and forward bound multi-action evidence on Proxy/Pilot hops so scoped users keep least-privilege remote access without shipping the full grant table. * fix: mirror scoped-stack-auth-evidence capability to frontend, sanitize node id in role assignment log Backend added the scoped-stack-auth-evidence capability without the matching frontend entry, failing the capability parity test. The role assignment log also interpolated the node id without sanitizeForLog, unlike the rest of the line. * fix(rbac): honor node-wide scopes and fix proxied DELETE cleanup Node-scoped grants now authorize that role's stack actions on the same node in the backend resolver, frontend can(), and remote evidence. Proxied DELETE cleanup uses the gate-stashed route because pathRewrite mutates req.path before proxyRes. Add proxy integration coverage and drop the stale scoped-permissions screenshot. * fix(rbac): preserve node-qualified grants during repair
This commit is contained in:
@@ -62,6 +62,7 @@ export const CAPABILITIES = [
|
||||
'guided-external-network-preflight',
|
||||
'service-scoped-update',
|
||||
'service-scoped-stack-alert',
|
||||
'scoped-stack-auth-evidence',
|
||||
] as const;
|
||||
|
||||
/**
|
||||
@@ -103,6 +104,15 @@ export const SERVICE_SCOPED_UPDATE_CAPABILITY = 'service-scoped-update' as const
|
||||
export const SERVICE_SCOPED_STACK_ALERT_CAPABILITY =
|
||||
'service-scoped-stack-alert' as const satisfies Capability;
|
||||
|
||||
/**
|
||||
* Remotes that consume hub-bound scoped stack auth evidence headers
|
||||
* (`x-sencho-scoped-stack-name` / `x-sencho-scoped-stack-actions`) under
|
||||
* machine auth. Hubs fail closed when scoped elevation is needed and the
|
||||
* remote lacks this flag.
|
||||
*/
|
||||
export const SCOPED_STACK_AUTH_EVIDENCE_CAPABILITY =
|
||||
'scoped-stack-auth-evidence' as const satisfies Capability;
|
||||
|
||||
/** Returns true when the string is a usable semver version. */
|
||||
export function isValidVersion(v: string | null | undefined): v is string {
|
||||
return !!v && v !== 'unknown' && v !== '0.0.0-dev' && !!semver.valid(v);
|
||||
|
||||
Reference in New Issue
Block a user