Repository navigation
Conversation
…ed action's namespace SchedulerPermissionsResolver.forNamespace() returned undefined when no app claimed the namespace, and the use cases treated that as "no check". So listing without a namespace, or getting, listing or cancelling under a namespace no app registers permissions for, skipped the permission check completely. The scheduler.action permission this replaced always applied. The resolver now always returns permissions. When no app claims the namespace, or there is none, it falls back to one that only lets full-access identities and code running without authorization through. The use cases drop their undefined checks. api-scheduler-server lists every pending action at startup, with no namespace, to re-arm their timers. That's a system task, so it now runs without authorization and still sees every action. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
adrians5j
added a commit
that referenced
this pull request
Oct 5, 2026
…ed action's namespace SchedulerPermissionsResolver.forNamespace() returned undefined when no app claimed the namespace, and the use cases treated that as "no check". So listing without a namespace, or getting, listing or cancelling under a namespace no app registers permissions for, skipped the permission check completely. The scheduler.action permission this replaced always applied. The resolver now always returns permissions. When no app claims the namespace, or there is none, it falls back to one that only lets full-access identities and code running without authorization through. The use cases drop their undefined checks. api-scheduler-server lists every pending action at startup, with no namespace, to re-arm their timers. That's a system task, so it now runs without authorization and still sees every action. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> (cherry picked from commit c391add, #5908 on release/6.5.0) On next the api-scheduler-server part drops out, because that package doesn't exist here. The fallback test cases are written for next's scheduler test handler.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Closes a permission gap in the scheduler that came in with the permissions refactor from 6.4.9's #5593 (dd941d6 on this branch).
SchedulerPermissionsResolver.forNamespace()returnedundefinedwhen no app claimed a namespace, and the get, get-target, list and cancel use cases treatedundefinedas "skip the check". So:The
scheduler.actionpermission that the refactor removed always applied.Over GraphQL the gap is narrow, because every scheduler query requires a namespace and the resolver passes it through. A caller would have to send a namespace nobody registered, which returns nothing today. Server code calling the use cases directly could hit the no-namespace case, though, and so would any future app that registers scheduled actions without registering permissions.
Fix
forNamespace()always returns permissions. When no app claims the namespace, or there's no namespace, it falls back toFullAccessOnlyPermissions. That lets through full-access identities and code running with authorization switched off, and nobody else.if (permissions)andpermissions ? … : falsechecks.api-scheduler-serverlists every pending action at startup, with no namespace, to re-arm the timers. That's a system task, so it now runs insidewithoutAuthorization()and still sees everything. Without this, the self-hosted scheduler would stop restoring pending actions on restart.FullAccessOnlyPermissionschecksisAuthorizationEnabled()as well ashasFullAccess(), becausehasFullAccess()reads the identity's permissions and ignoreswithoutAuthorization().Tests
api-headless-cms-scheduler/__tests__/schedulerPermissions.test.tsis new:Scheduler/NotAuthorizedScheduler/NotAuthorizedwithoutAuthorization()Checks
yarn buildpasses.The same change goes to
nextwith the scheduler permissions port (#5907), so both branches stay identical.Workspace: wby-next2 · 🧹 MERGE 6.5.0 => NEXT
🤖 Generated with Claude Code