RBAC: Fix an issue with server admins not being able to manage users in orgs that they don't belong to (#92024)

* look at global perms if user is not a part of the target org

* use constant

* update tests
This commit is contained in:
Ieva
2024-08-22 10:04:06 +01:00
committed by GitHub
parent 40cdfeb00b
commit 41ac5b5ae7
2 changed files with 42 additions and 62 deletions
+4
View File
@@ -205,6 +205,10 @@ func AuthorizeInOrgMiddleware(ac AccessControl, authnService authn.Service) func
var orgUser identity.Requester = c.SignedInUser
if targetOrgID != c.SignedInUser.GetOrgID() {
orgUser, err = authnService.ResolveIdentity(c.Req.Context(), targetOrgID, c.SignedInUser.GetID())
if err == nil && orgUser.GetOrgID() == NoOrgID {
// User is not a member of the target org, so only their global permissions are relevant
orgUser, err = authnService.ResolveIdentity(c.Req.Context(), GlobalOrgID, c.SignedInUser.GetID())
}
if err != nil {
deny(c, nil, fmt.Errorf("failed to authenticate user in target org: %w", err))
return