fix: reject invalid coder principals safely
This commit is contained in:
@@ -15669,6 +15669,26 @@ mod tests {
|
||||
updated_at: TEST_CREATED_AT.to_string(),
|
||||
})
|
||||
.unwrap();
|
||||
let invalid_coder = scoped_set_ticket_assignment(
|
||||
State(api.clone()),
|
||||
AxumPath((
|
||||
TEST_WORKSPACE_ID.to_string(),
|
||||
ticket_id.clone(),
|
||||
"coder".to_string(),
|
||||
)),
|
||||
Json(SetTicketRoleAssignmentRequest {
|
||||
operation_id: "invalid-workspace-agent-coder".to_string(),
|
||||
principal: TicketAssignmentPrincipal::WorkspaceAgent {
|
||||
agent_key: "workspace-orchestrator".to_string(),
|
||||
},
|
||||
expected_assignment_id: None,
|
||||
}),
|
||||
)
|
||||
.await
|
||||
.unwrap_err()
|
||||
.into_response();
|
||||
assert_eq!(invalid_coder.status(), StatusCode::CONFLICT);
|
||||
|
||||
let assignment = TicketCoderAssignmentRecord {
|
||||
workspace_id: TEST_WORKSPACE_ID.to_string(),
|
||||
ticket_id: ticket_id.clone(),
|
||||
|
||||
@@ -3843,7 +3843,11 @@ impl ControlPlaneStore for SqliteWorkspaceStore {
|
||||
runtime_id,
|
||||
worker_id,
|
||||
} => (None, Some(runtime_id.as_str()), Some(worker_id.as_str())),
|
||||
TicketAssignmentPrincipal::WorkspaceAgent { .. } => unreachable!(),
|
||||
TicketAssignmentPrincipal::WorkspaceAgent { .. } => {
|
||||
return Err(Error::TicketAssignmentConflict(
|
||||
"Workspace agent principal cannot occupy the Coder role".to_string(),
|
||||
));
|
||||
}
|
||||
};
|
||||
let principal_json = serde_json::to_string(&record.principal).map_err(|error| {
|
||||
Error::Store(format!("serialize Ticket assignment principal: {error}"))
|
||||
|
||||
Reference in New Issue
Block a user