Skip to content

product type updates and tests#15307

Open
svader0 wants to merge 1 commit into
DefectDojo:bugfixfrom
svader0:bugfix-product-type-authorized-users-authz
Open

product type updates and tests#15307
svader0 wants to merge 1 commit into
DefectDojo:bugfixfrom
svader0:bugfix-product-type-authorized-users-authz

Conversation

@svader0

@svader0 svader0 commented Jul 21, 2026

Copy link
Copy Markdown
Collaborator

Hardening/consistency improvement to product type API object permission checks. Aligns changes to a product type's member list with the member-management permission the web UI already requires, and adds a regression test. No functional change for correctly-permissioned users.

@github-actions github-actions Bot added docker New Migration Adding a new migration file. Take care when merging. settings_changes Needs changes to settings.py based on changes in settings.dist.py included in this PR apiv2 docs unittests ui parser helm labels Jul 21, 2026
@svader0
svader0 force-pushed the bugfix-product-type-authorized-users-authz branch from 080451b to 5514c35 Compare July 21, 2026 18:10
@github-actions github-actions Bot removed docker New Migration Adding a new migration file. Take care when merging. settings_changes Needs changes to settings.py based on changes in settings.dist.py included in this PR apiv2 docs ui parser helm labels Jul 21, 2026
@svader0
svader0 force-pushed the bugfix-product-type-authorized-users-authz branch from 5514c35 to 7196076 Compare July 21, 2026 18:16
valentijnscholten added a commit that referenced this pull request Jul 21, 2026
The unit-test matrix runs a flag-off leg (unit-tests.yml
v3_feature_locations: [false, true]); with the flag off dojo/urls.py
does not mount /api/v3-alpha/, so mount-dependent v3 tests hit the SPA
catch-all (200 HTML) and failed - 66 failures on the PR's
test-rest-framework (false) job, invisible locally because the
settings default is True.

Guards (skipUnless settings.V3_FEATURE_LOCATIONS):
- ApiV3TestCase: covers every HTTP contract test transitively
- ApiV3ImportShim mixin: covers the import-corpus tests (they subclass
  the v2 corpus mixins, not ApiV3TestCase)
- TestApiV3OpenApi: get_openapi_schema() resolves the mounted namespace
  (KeyError 'api_v3' when unmounted)
Genuinely mount-independent unit tests keep running (static authz
tripwire, expand cycle guard).

Verified: flag-off Ran 511 OK (skipped=506); flag-on unchanged Ran 511
OK (skipped=6).

Plan §12 also records: PR #15307 verdict (v3 IMMUNE - authorized_users
not on the write surface) + the recommendation to implement member
management as a sub-resource, not an inline write field.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant