Prevent service instance sharers from attempting to share with themselves - #992
Merged
elenasharma merged 14 commits intoNov 16, 2017
Conversation
|
Hey deniseyu! Thanks for submitting this pull request! I'm here to inform the recipients of the pull request that you and the commit authors have already signed the CLA. |
|
We have created an issue in Pivotal Tracker to manage this: https://www.pivotaltracker.com/story/show/152842690 The labels on this github issue will be updated when the story is started. |
4 tasks
Contributor
|
Maybe moving all the checks in |
* The broker can return a shareable field as part of the service metadata response to /v2/catalog. [#152540454] Signed-off-by: Sam Gunaratne <sgunaratne@pivotal.io>
[#151909779]
… instance * This behaviour already existed, this commit just adds additional tests [#150973376] Signed-off-by: Denise Yu <dyu@pivotal.io>
* Only developers who have write access to the service instance can perform an update. [#150973390] Signed-off-by: Derik Evangelista <devangelista@pivotal.io>
or unshare [#151441010] Signed-off-by: Denise Yu <dyu@pivotal.io>
* The intended behavior is that users who have access to a shared service instance, but not developer access to the originating space of the instance may not create service keys from the instance. * This behavior was already correct. This commit simply adds tests to lock down the behavior. [#152592943] Signed-off-by: Jen Spinney <jennifer.spinney@suse.com>
* The intended behavior is that users who have access to a shared service instance, but not developer access to the originating space of the instance may not list service keys for the instance. * This behavior was already correct. This commit simply adds tests to lock down the behavior. [#151950132] Signed-off-by: Denise Yu <dyu@pivotal.io>
* The intended behavior is that users who have access to a shared service instance, but not developer access to the originating space of the instance may not delete service key associated with the instance. * This behavior was already correct. This commit simply adds tests to lock down the behavior. [#152721273] Signed-off-by: Jen Spinney <jennifer.spinney@suse.com>
* The intended behavior is that users who have access to a shared service instance, but not developer access to the originating space of the instance may not GET specific service keys for the instance. * This behavior was already correct. This commit simply adds tests to lock down the behavior. [#152721273] Signed-off-by: Denise Yu <dyu@pivotal.io>
* Add explicit check in ServiceInstanceShare.create * Add new API error type [#151997784] Signed-off-by: Denise Yu <dyu@pivotal.io>
* Add explicit check in ServiceInstanceShare.create * Add new API error type [#152036417] Signed-off-by: Denise Yu <dyu@pivotal.io>
* Raise 422 when source space is included in list of target spaces [#152109683] Signed-off-by: Denise Yu <dyu@pivotal.io>
deniseyu
force-pushed
the
pr-service-instance-sharing-no-sharing-to-own-space
branch
from
November 16, 2017 16:50
293f3b7 to
d6c3299
Compare
Contributor
|
Hi @deniseyu - we accidentally merged this PR. Could you please open a new PR with the same changes? |
5 tasks
deniseyu
deleted the
pr-service-instance-sharing-no-sharing-to-own-space
branch
November 28, 2017 16:48
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
As an app dev (sharer), I cannot share service instances with myself. #152109683
NOTE: This PR builds on top of #989, which should be merged first. The actual changes on top of #989 can be viewed in this diff.
What
This PR closes a loophole in the validation logic when a service instance share is created. If the service instance's own space GUID is in the body of the request to the sharing service instances endpoint, a 422 will be returned and no service instance shares will be recorded (or audited). This approach is consistent with the pattern of failing a request if any GUIDs in the body of the request do not correspond to valid spaces that the user can read.
Changes:
PR
masterbranchbundle exec rakeThanks, sapi