Skip to content

fix(api): gate listAvailableRegions behind ORGANIZATION_INFRASTRUCTURE flag - #8

Closed
G4614 wants to merge 1 commit into
mainfrom
fix/pol-331-regions-fail-closed
Closed

G4614 wants to merge 1 commit into
mainfrom
fix/pol-331-regions-fail-closed

Conversation

@G4614

@G4614 G4614 commented Sep 1, 2026

Copy link
Copy Markdown
Owner

Before

GET /regions → 500 (all orgs without infrastructure flag)
GET /runners → 403 (correctly fail-closed)

OrganizationRegionController had @RequireFlagsEnabled on every method (POST, DELETE, PATCH, POST regenerate-key) except the @Get() list handler, which hit DB joins that require infrastructure tables and returned 500.

After

GET /regions → 403 (flag disabled) | 200 (flag enabled)

Call graph

Before:
GET /regions → OrganizationRegionController.listAvailableRegions ← BUG: no @RequireFlagsEnabled
→ OrganizationService.listAvailableRegions → DB query → 500

After:
GET /regions → @RequireFlagsEnabled guard → 403 when flag off → listAvailableRegions → 200

Fixes POL-331.

🤖 Generated with Claude Code

…E flag

GET /v1/regions returned 500 for orgs without the flag because it hit a
DB join that requires infrastructure tables to exist. Every other method
on OrganizationRegionController (POST, DELETE, PATCH, POST regenerate-key)
already carried the @RequireFlagsEnabled guard; the GET (list) was the
only one missing it.

Fixes POL-331.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@G4614 G4614 closed this Sep 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant