Fix: unnecessary permission check in resolve_stack functions (failure in list datasets when there are shared datasets) #1205
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Feature or Bugfix
Detail
The function
get_stack_with_cfn_resources
fromStackService
is used to resolve the CFN stack details of several stacks in data.all. It is a private function that is not used directly as resolver by any GraphQL query/mutation, so the permissions are checked indirectly by applying the permissions in the main API. Better with an example:API Query:
GetNotebook
(what we want)get_notebook
decorated to check userGET_NOTEBOOK
permissions on that Notebook1get_stack_with_cfn_resources
to resolve CFN details of the NotebookAPI Query:
GetNotebook
(what we currently have)get_notebook
decorated to check userGET_NOTEBOOK
permissions on that Notebook1get_stack_with_cfn_resources
get_stack_with_cfn_resources
we call find_environment, which checks theGET_ENVIRONMENT
permissions of the userIn this PR I revert to pass the environmentUri instead of passing the environment. Instead of using the EnvironmentService, it uses the EnvironmentRepository
Relates
Security
Please answer the questions below briefly where applicable, or write
N/A
. Based onOWASP 10.
fetching data from storage outside the application (e.g. a database, an S3 bucket)?
eval
or similar functions are used?By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.