Repository navigation
Conversation
Resolve the caller's reach once per request (cluster, partner or organisation, widened by live grants) and keep every estate list, lookup and mutation inside it. PLACE_TENANCY_ENFORCE switches between refusing and logging what would be refused. Adds organisations, partners and grants routes, builds against the models PPT-526-partner-client branch.
A partner-less organisation tripped the non-nilable partner association; resolve the partner through its id. Regenerate OPENAPI_DOC.yml for the organisations, partners and grants routes.
Lets a caller with cluster or partner reach narrow domains, zones, systems, modules, triggers, edges and users to one organisation. The organisation must be within reach.
Rows left behind by other spec files can push the fixture's rows past the default page, which is what failed in CI.
…ning tenancy fixture An organisation admin cannot remove their organisation's last admin; cluster staff can, which is how a domain is torn down. The tenancy spec fixture now tears itself down after each example: the harness clears tables only once per suite, and leaked rows pushed later unfiltered list assertions past the first page. Tracks models at e21d790.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Enforcement half of multi-tenancy (PPT-2701, under PPT-526). Builds on the data layer in PlaceOS/models#332 through
shard.override.yml; the spec migrator clones that branch too. Draft until the set has been through a clean install on the test cluster.What this does
Every request now resolves the caller's reach once, in
Utils::Tenancy, and every list, lookup and mutation on the estate stays inside it.organisations.partner_staff)Live grants (
grantstable) widen the organisation set without changing the level. Rows with no organisation are visible to cluster reach only. A domain with no organisation reaches nothing.PLACE_TENANCY_ENFORCE(default off) switches between refusing and logging what would have been refused. With it off the API behaves exactly as before this PR, so it can ship dark; the log lines (tenancy would refuse) show every cross-organisation habit before the flip.Where it applies
/controlcommands against a system outside reach answermodule_not_found.organisation_idon the domain, zone, system, module, trigger, edge and user lists narrows a cluster or partner caller to one organisation (it must be within reach)./organisations(withGET /organisations/currentfor the caller's reach andPOST /organisations/:id/claimto adopt an unowned zone tree),/partners,/grants. Ownership columns staymass_assignment: false; these routes and the query parameters on domain and zone create are the only write paths.Verification
spec/controllers/tenancy_spec.cr: a four-organisation fixture (management partner on localhost, a partner with a staff organisation and a client, a direct customer, an unowned tree) proving cross-organisation reads and writes are refused, partner staff reach their clients, cluster admins reach everything, grants widen and expire, log-only mode only logs, cluster-only routes refuse organisation admins, and claim adopts a tree.crystal tool format --checkclean; ameba clean on the new files.OPENAPI_DOC.ymlregenerated. It adds the eight new paths (/organisations,/organisations/current,/organisations/{id},/organisations/{id}/claim,/partners,/partners/{id},/grants,/grants/{id}); the rest of that diff is the generator's path ordering.Review notes
partner_staff) rather than per-user grants, so NTT's staff do not each need a grant row; grants remain for exceptions and time-boxed access.control_system_idare templates (16 of 17 on placeos-dev), so they stay cluster-managed and readable by all.Plan: https://gist.github.com/camreeves/3fabfff92bcdef77a1dcb4b8d8ebfe7b