Repository navigation
Conversation
|
Droid finished @RIT3shSapata's task —— View job Review summary: The overall approach looks sound and closes a real security gap, but the new 403 paths currently depend on |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The OpenAPI startup schema is incomplete, serialization is inconsistent, and HEAD/admin behavior lacks coverage.
Review effort: Balanced
Findings: 1
Open (3)
What changed in this PR
Adds a startup option to disable public _local document access while preserving admin API behavior.
Changes:
- Adds
api.enable_local_endpoint_for_public_api. - Blocks public
_localCRUD and mixed_bulk_docsrequests when disabled. - Adds enabled/disabled behavior tests.
| File | Description |
|---|---|
rest/handler.go |
Detects disabled public _local access. |
rest/doc_api.go |
Rejects public _local CRUD requests. |
rest/config_startup.go |
Defines the startup setting and default behavior. |
rest/config_flags.go |
Registers the corresponding CLI flag. |
rest/bulk_api.go |
Rejects bulk requests containing local documents. |
rest/api_test.go |
Tests public endpoint and bulk behavior. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
- bulk api now returns row level errors - fixed the way the endpoints return an error to prevent 406 - added case to test the HEAD request as well - open api spec have been updated - added test case to ensure the admin api is not affected by this change - added omitempty tag to the config
Redocly previews |
|
@droid review |
|
Droid finished @RIT3shSapata's task —— View job Both candidate comments are valid: the new TestLocalEndpointForPublicAPI does not compile due to |
| RequireStatus(t, rt.SendUserRequest(http.MethodPut, "/{{.keyspace}}/_local/doc2", `{"key":"value"}`, "alice"), test.expectedPutStatus) | ||
| RequireStatus(t, rt.SendUserRequest(http.MethodDelete, "/{{.keyspace}}/_local/doc1", "", "alice"), test.expectedStatus) |
| MutateStartupConfig: func(config *StartupConfig) { | ||
| config.API.EnableLocalEndpointForPublicAPI = new(test.enabled) |
|
|
||
| RequireStatus(t, rt.SendUserRequest(http.MethodGet, "/{{.keyspace}}/_local/doc1", "", "alice"), test.expectedStatus) | ||
| RequireStatus(t, rt.SendUserRequest(http.MethodHead, "/{{.keyspace}}/_local/doc1", "", "alice"), test.expectedStatus) | ||
| RequireStatus(t, rt.SendUserRequestWithHeaders(http.MethodGet, "/{{.keyspace}}/_local/doc1", "", map[string]string{"Accept": "text/html"}, "alice", RestTesterDefaultUserPassword), test.expectedStatus) |
| "api.admin_interface_authentication": {config: &config.API.AdminInterfaceAuthentication, flagValue: fs.Bool("api.admin_interface_authentication", false, "Whether the admin API requires authentication")}, | ||
| "api.metrics_interface_authentication": {config: &config.API.MetricsInterfaceAuthentication, flagValue: fs.Bool("api.metrics_interface_authentication", false, "Whether the metrics API requires authentication")}, | ||
| "api.enable_admin_authentication_permissions_check": {config: &config.API.EnableAdminAuthenticationPermissionsCheck, flagValue: fs.Bool("api.enable_admin_authentication_permissions_check", false, "Whether to enable the DP permissions check feature of admin auth")}, | ||
| "api.enable_local_endpoint_for_public_api": {config: &config.API.EnableLocalEndpointForPublicAPI, flagValue: fs.Bool("api.enable_local_endpoint_for_public_api", true, "Whether to enable the local endpoint for public API")}, |


CBG-5892
Add a startup config option to turn off the
_localdocument endpoints on the public API. The_localendpoints do not enforce write access control, so any authenticated user can store any data in the bucket.api.enable_local_endpoint_for_public_api, also available as a CLI flag. If it is not set, the endpoints stay enabled, so the default behavior does not change. The decision about the default is separate from this PR.false,GET,HEAD,PUTandDELETEon/{keyspace}/_local/{docid}on the public API return 403 with{"error":"Forbidden","reason":"_local endpoint is disabled"}, whatever theAcceptheader is.false, a public_bulk_docsrequest still returns 201 and writes its normal docs. Each_localdoc in the request is not written and gets a 403 status in the response.Startup-config, the 403 response on the public_localendpoints, and the_bulk_docsbehavior.TestLocalEndpointForPublicAPIcovers the enabled and disabled cases forGET,HEAD,PUT,DELETEand_bulk_docs, a client that does not accept JSON, and the admin API.Pre-review checklist
base.UD(docID),base.MD(dbName))docs/apiDependencies (if applicable)
Integration Tests