fix(security): rebuild tenant-scoped analytics query on current main - #456
Draft
seonghobae wants to merge 4 commits into
Draft
fix(security): rebuild tenant-scoped analytics query on current main#456seonghobae wants to merge 4 commits into
seonghobae wants to merge 4 commits into
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Objective
Reconstruct the storage-scoped analytics tenant boundary directly on current protected
main, without importing stale ancestry or reading a global conversion-job inventory into the controller process.Exact reconstruction identity
eb0a32e87e7470469c8fa0f8c67d9583654bef57;c2ee90a90666a715b35a7be1973cc5b0916e7373;e0c02dc3305020ae1ad6900d0a04790aee7104d3;Security invariant
The analytics controller passes the authenticated tenant predicate into
ConversionJobRepository.findAllByTenantId(...)and never obtains a global job inventory merely to filter it in process. The repository default fails closed with an empty result and cannot invokefindAll(). The in-memory adapter normalizes nonblank tenant authority and applies ownership filtering at its storage boundary. Missing permission fails before either query is invoked.Scope boundary
This is a process-local query-boundary contract. It does not add durable database row-level security, alter KPI denominator/version semantics, change authentication, persist analytics, or complete issue #326. Durable adapters must implement the same tenant predicate in storage.
Test-first lineage
The focused regression proves the controller calls only the scoped query, authorization failure touches neither query, the interface default cannot fall back to the global inventory, and the in-memory adapter returns only owned jobs. Predecessor checks and reviews do not transfer to this exact current-main reconstruction.
Merge gate
Keep Draft until exact-head CI, Security Scan, SAST Semgrep, fuzz, zero valid unresolved findings, and a qualifying independent non-author approval are present. Any head movement requires complete revalidation.