forked from fleetdm/fleet
-
Notifications
You must be signed in to change notification settings - Fork 1
fix(OPENFRAM-005-11): CU-86akj32d8 dibble IDP seeder writes directly to shared MySQL without tenant scoping guard #173
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Draft
flamingo
wants to merge
1
commit into
main
Choose a base branch
from
ai-fix/openfram-005-11-ce459428-1446a072
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
+44
−7
Draft
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🦩 🔴 dibble IDP seeder writes directly to shared MySQL without tenant scoping guard
Added a required
OrganizationIDs []uintfield toIDPOptionsand a newinOrganizationhelper (matching the finding's referenced convention) intools/dibble/pkg/seed/idp.go.IDP()now rejects the call up front ifOrganizationIDsis empty, and filters bothfetchUsersForIDPandfetchHostsForIDPresults throughinOrganizationbefore any mutation, so only in-scope users/hosts reachupsertIDPAccount,upsertSCIMUser,assignHostToIDPAccount, andassignHostToSCIMUser. I also addedOrganizationID uintfields to theidpUser/idpHoststructs (json:"organization_id") since filtering requires the API to expose that field. This is LOW confidence because: (a) I cannot verify the Fleet/usersand/hostslist endpoints actually return anorganization_idfield in their JSON payload as named here — if the real field name/shape differs, filtering will silently drop everything (emptyusers/hostsafter filtering, producing the "no users found in scope" error) rather than compile-failing; (b) I have not seen the actualinOrganizationhelper implementation referenced by the finding elsewhere in the repo, so this is a new, possibly divergent definition rather than a shared import — a complete fix would locate and reuse the existing helper/pattern instead of redefining it locally; (c) callers ofIDP()elsewhere in thedibbleCLI (not shown) must now be updated to passOrganizationIDs, which I could not do since that file is out of scope here — until that wiring lands, this seeder will always error out.🤖 Prompt for AI agents
fix confidence: 🔴 30 low — review closely — react 👍/👎 to teach the reviewer