diff --git a/apps/provisioning/pkg/auth/session_access_checker.go b/apps/provisioning/pkg/auth/session_access_checker.go index 27ea420959e..00348ef8e59 100644 --- a/apps/provisioning/pkg/auth/session_access_checker.go +++ b/apps/provisioning/pkg/auth/session_access_checker.go @@ -45,11 +45,6 @@ func (c *sessionAccessChecker) Check(ctx context.Context, req authlib.CheckReque return apierrors.NewUnauthorized(fmt.Sprintf("failed to get requester: %v", err)) } - // AccessPolicy identities are trusted internal callers - if authlib.IsIdentityType(requester.GetIdentityType(), authlib.TypeAccessPolicy) { - return nil - } - // Fill in namespace from identity if not provided if req.Namespace == "" { req.Namespace = requester.GetNamespace() diff --git a/apps/provisioning/pkg/auth/session_access_checker_test.go b/apps/provisioning/pkg/auth/session_access_checker_test.go index 2375fcf7b5d..1e99a6e46db 100644 --- a/apps/provisioning/pkg/auth/session_access_checker_test.go +++ b/apps/provisioning/pkg/auth/session_access_checker_test.go @@ -108,12 +108,6 @@ func TestSessionAccessChecker_Check(t *testing.T) { requester: &mockRequester{orgRole: identity.RoleAdmin, identityType: authlib.TypeUser}, expectAllow: false, }, - { - name: "AccessPolicy identity is always allowed", - innerResponse: authlib.CheckResponse{Allowed: false}, - requester: &mockRequester{orgRole: identity.RoleViewer, identityType: authlib.TypeAccessPolicy}, - expectAllow: true, - }, } for _, tt := range tests { diff --git a/apps/provisioning/pkg/auth/token_access_checker.go b/apps/provisioning/pkg/auth/token_access_checker.go index 8339074468a..d2c6f9e1c5b 100644 --- a/apps/provisioning/pkg/auth/token_access_checker.go +++ b/apps/provisioning/pkg/auth/token_access_checker.go @@ -36,11 +36,6 @@ func (c *tokenAccessChecker) Check(ctx context.Context, req authlib.CheckRequest return apierrors.NewUnauthorized("no auth info in context") } - // AccessPolicy identities are trusted internal callers - if authlib.IsIdentityType(id.GetIdentityType(), authlib.TypeAccessPolicy) { - return nil - } - // Fill in namespace from identity if not provided if req.Namespace == "" { req.Namespace = id.GetNamespace() diff --git a/apps/provisioning/pkg/auth/token_access_checker_test.go b/apps/provisioning/pkg/auth/token_access_checker_test.go index aa6184b3a0a..bce0d3a77a0 100644 --- a/apps/provisioning/pkg/auth/token_access_checker_test.go +++ b/apps/provisioning/pkg/auth/token_access_checker_test.go @@ -47,12 +47,6 @@ func TestTokenAccessChecker_Check(t *testing.T) { authInfo: &identity.StaticRequester{Type: authlib.TypeUser}, expectAllow: false, }, - { - name: "AccessPolicy identity is always allowed", - innerResponse: authlib.CheckResponse{Allowed: false}, - authInfo: &identity.StaticRequester{Type: authlib.TypeAccessPolicy}, - expectAllow: true, - }, } for _, tt := range tests {