fix(hub): require system access for alert subscriptions and delivery (#2455)

Co-authored-by: hank <hank@henrygd.me>
This commit is contained in:
user01010111
2026-09-30 03:27:11 +13:00
committed by GitHub
parent a77ed345d7
commit 0484c54919
9 changed files with 404 additions and 15 deletions

View File

@@ -118,6 +118,25 @@ func setCollectionAuthSettings(app core.App) error {
return err
}
// Alerts belong to their user and may only reference systems the user can access.
// The user and system of an existing alert cannot be changed through the API.
// Readonly users can still manage their own alerts, so these build on the read rule.
alertsOwnerRule := authenticatedRule + " && user = @request.auth.id"
alertsCreateRule := alertsOwnerRule
alertsUpdateRule := alertsOwnerRule + " && @request.body.user:changed = false && @request.body.system:changed = false"
if shareAllSystems != "true" {
alertsCreateRule += " && system.users.id ?= @request.auth.id"
alertsUpdateRule += " && system.users.id ?= @request.auth.id"
}
if err := applyCollectionRules(app, []string{"alerts"}, collectionRules{
list: &alertsOwnerRule,
create: &alertsCreateRule,
update: &alertsUpdateRule,
delete: &alertsOwnerRule,
}); err != nil {
return err
}
if err := applyCollectionRules(app, []string{"system_details"}, collectionRules{
list: &systemScopedReadRule,
view: &systemScopedReadRule,

View File

@@ -47,8 +47,8 @@ func TestCollectionRulesDefault(t *testing.T) {
require.NoError(t, err, "Failed to find alerts collection")
assert.Equal(t, isUserMatchesUser, *alertsCollection.ListRule)
assert.Nil(t, alertsCollection.ViewRule)
assert.Equal(t, isUserMatchesUser, *alertsCollection.CreateRule)
assert.Equal(t, isUserMatchesUser, *alertsCollection.UpdateRule)
assert.Equal(t, isUserMatchesUser+` && system.users.id ?= @request.auth.id`, *alertsCollection.CreateRule)
assert.Equal(t, isUserMatchesUser+` && @request.body.user:changed = false && @request.body.system:changed = false && system.users.id ?= @request.auth.id`, *alertsCollection.UpdateRule)
assert.Equal(t, isUserMatchesUser, *alertsCollection.DeleteRule)
alertNames := alertsCollection.Fields.GetByName("name").(*core.SelectField).Values
for _, name := range []string{"CPUIOWait", "CPUSteal"} {
@@ -183,7 +183,7 @@ func TestCollectionRulesShareAllSystems(t *testing.T) {
assert.Equal(t, isUserMatchesUser, *alertsCollection.ListRule)
assert.Nil(t, alertsCollection.ViewRule)
assert.Equal(t, isUserMatchesUser, *alertsCollection.CreateRule)
assert.Equal(t, isUserMatchesUser, *alertsCollection.UpdateRule)
assert.Equal(t, isUserMatchesUser+` && @request.body.user:changed = false && @request.body.system:changed = false`, *alertsCollection.UpdateRule)
assert.Equal(t, isUserMatchesUser, *alertsCollection.DeleteRule)
// alerts_history collection