Failure scenario
Start Odin with one of its authorization stores truncated, malformed, or wrong-shaped:
- A corrupt
permissions.json is ignored, so every runtime override disappears and users fall back to configured/default tiers. In a deployment where an override demoted a user, that user regains the broader fallback tier.
- A corrupt or wrong-shaped
host_access.json is ignored, leaving the default allowed_hosts=None; users regain access to every configured host.
- A corrupt or wrong-shaped
api_tokens.json loads an empty token set. The next successful token mutation writes that partial/empty in-memory set over the damaged file, permanently losing valid entries that could have been recovered.
The loaders neither fail startup nor mark their stores read-only/corrupt. Subsequent mutations overwrite the only live file, converting a transient/truncated read into silent authorization loss or privilege broadening.
Sites
src/permissions/manager.py:55-70 treats corrupt/wrong-shaped permission data as empty and allows later overwrite.
src/permissions/host_access.py:59-81 treats corrupt/wrong-shaped host policy as allow-all defaults and allows later overwrite.
src/permissions/token_manager.py:38-104 treats corrupt/wrong-shaped token storage as empty and allows later overwrite.
Expected result
Use corruption-safe strict loading for authorization mutation paths: preserve the damaged bytes, surface an unhealthy/fail-closed state, and refuse writes until repaired. Effective fallback policy on unreadable host/RBAC data must not broaden access.
Failure scenario
Start Odin with one of its authorization stores truncated, malformed, or wrong-shaped:
permissions.jsonis ignored, so every runtime override disappears and users fall back to configured/default tiers. In a deployment where an override demoted a user, that user regains the broader fallback tier.host_access.jsonis ignored, leaving the defaultallowed_hosts=None; users regain access to every configured host.api_tokens.jsonloads an empty token set. The next successful token mutation writes that partial/empty in-memory set over the damaged file, permanently losing valid entries that could have been recovered.The loaders neither fail startup nor mark their stores read-only/corrupt. Subsequent mutations overwrite the only live file, converting a transient/truncated read into silent authorization loss or privilege broadening.
Sites
src/permissions/manager.py:55-70treats corrupt/wrong-shaped permission data as empty and allows later overwrite.src/permissions/host_access.py:59-81treats corrupt/wrong-shaped host policy as allow-all defaults and allows later overwrite.src/permissions/token_manager.py:38-104treats corrupt/wrong-shaped token storage as empty and allows later overwrite.Expected result
Use corruption-safe strict loading for authorization mutation paths: preserve the damaged bytes, surface an unhealthy/fail-closed state, and refuse writes until repaired. Effective fallback policy on unreadable host/RBAC data must not broaden access.