RBAC: Fix an issue with server admins not being able to manage users in orgs that they don't belong to (#92024)
* look at global perms if user is not a part of the target org * use constant * update tests
This commit is contained in:
@@ -205,6 +205,10 @@ func AuthorizeInOrgMiddleware(ac AccessControl, authnService authn.Service) func
|
||||
var orgUser identity.Requester = c.SignedInUser
|
||||
if targetOrgID != c.SignedInUser.GetOrgID() {
|
||||
orgUser, err = authnService.ResolveIdentity(c.Req.Context(), targetOrgID, c.SignedInUser.GetID())
|
||||
if err == nil && orgUser.GetOrgID() == NoOrgID {
|
||||
// User is not a member of the target org, so only their global permissions are relevant
|
||||
orgUser, err = authnService.ResolveIdentity(c.Req.Context(), GlobalOrgID, c.SignedInUser.GetID())
|
||||
}
|
||||
if err != nil {
|
||||
deny(c, nil, fmt.Errorf("failed to authenticate user in target org: %w", err))
|
||||
return
|
||||
|
||||
Reference in New Issue
Block a user