| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
|
⚠️ Please install the Codecov Report✅ All modified and coverable lines are covered by tests. @@ Coverage Diff @@
## master #6951 +/- ##
==========================================
+ Coverage 49.08% 49.14% +0.05%
==========================================
Files 433 433
Lines 54332 54338 +6
Branches 7917 7918 +1
==========================================
+ Hits 26667 26702 +35
+ Misses 25788 25761 -27
+ Partials 1877 1875 -2
... and 4 files with indirect coverage changes Continue to review full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Sorry, something went wrong.
… API apply_permission silently dropped any type or action name that was not in the name-to-enum maps. A typo or wrong casing in every type left the spec with an empty types list, which Permission treats as ALL_RESOURCE_TYPES, so a permission meant for one resource type ended up covering all of them. Partially invalid action lists were also narrowed without notice. Return a 400 listing the invalid names and the valid options instead. Signed-off-by: LuisFigueroaG <luis.h.figueroa.g@gmail.com>
| Back | FazBrowse Home | New Git URL |
What this PR does / why we need it:
POST /permissions silently dropped any type or action name it did not recognize:
A typo or wrong casing in every type (e.g. "feature_view" instead of "FEATURE_VIEW") left the spec with an empty types list, which Permission treats as ALL_RESOURCE_TYPES. So a permission meant for one resource type was stored covering all 12 of them, with a 201. A partly invalid action list such as ["DESCRIBE", "READ"] was also narrowed to ["DESCRIBE"] without any notice.
The endpoint now returns a 400 that lists the invalid names and the valid options, consistent with the other 400s in the REST registry API. Valid requests behave as before.
Which issue(s) this PR fixes:
No existing issue.
Checks
Testing Strategy
Added REST tests in test_api_rest_registry.py for the valid apply/get/delete path and for rejecting unknown types and actions (lowercase type, a typo among valid types, lowercase action, partly invalid actions). Each rejection test also checks that nothing was stored. The rejection tests fail on master and pass with this change. ruff format --check, ruff check and mypy pass on the changed files, and pytest sdk/python/tests/unit/api passes (139 passed, 6 skipped).