Add a read-only READER role and an explicit default role for IdP users - #718
Merged
Merged
Conversation
coopernetes
force-pushed
the
feature/reader-role
branch
2 times, most recently
from
October 2, 2026 17:41
535f03a to
f5773fd
Compare
coopernetes
force-pushed
the
feature/reader-role
branch
2 times, most recently
from
October 2, 2026 23:09
ab38bb6 to
38cb2a8
Compare
Everyone who signed in got USER, and every IdP role mapping added it too, so an open deployment (require-role-mapping: false) let anyone in the directory approve other people's pushes. READER sees pushes, repositories, providers and activity and changes nothing. Acting now needs USER or ADMIN (ADMIN implies USER), a mapping grants only the role it names, and a session with no READER, USER, AUDITOR or ADMIN role is refused. A repository grant is inert for a user who cannot act; Test Permission says why. auth.default-role (NONE, READER, USER or AUDITOR; NONE by default) decides what an IdP user with no mapped session role gets. It replaces auth.require-role-mapping, which is still accepted with a warning (true reads as NONE, false as READER). Startup fails when role-mappings is empty and the default role is NONE, since no one could sign in. closes #715 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The images on main shipped openssl and libssl3t64 3.0.13-0ubuntu3.15 (CVE-2026-84782, high, plus four low). Ubuntu published 3.16 on 2026-09-29, but the build's apt upgrade step was served from the build cache, so it never ran against the new archive. The 2026-10-02 temurin images ship 3.16. The SECURITY_UPGRADE_PKGS apt upgrade goes: the base images now carry the fix, and a cached layer made it unreliable anyway. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
coopernetes
force-pushed
the
feature/reader-role
branch
from
October 3, 2026 01:39
38cb2a8 to
00dff19
Compare
coopernetes
enabled auto-merge
October 3, 2026 01:39
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Everyone who signed in got
USER, and every IdP role mapping added it too, sorequire-role-mapping: falselet anyone in the directory approve other people's pushes.READERsees pushes, repositories, providers and fetch and SCM API activity, and changes nothing.USERorADMIN(ADMINimpliesUSER);AUDITORstill makes a session read-only. A repository grant is inert for a user who cannot act, including one with no stored record.auth.default-role(NONEdefault,READER,USER,AUDITOR) decides what an IdP user with no mapped session role gets; it replaces the deprecatedrequire-role-mapping(true→NONE,false→READER, both set fails startup).READER,USER,AUDITOR,ADMINis refused, soSELF_CERTIFYalone admits no one.IdpRoleMapper); LDAP and AD without a group search base now go through it too.role-mappingsis empty and the default role isNONE.reason: ROLE_CANNOT_ACT, additive on the response).observeris now aREADERwith its own spec; a newnewcomer(plainUSER, no grants) takes over the specs that grant to or act as a user.Worth a close look:
role-mappingsfails to start until it setsdefault-role(it used to give everyoneUSER).roles: [SELF_CERTIFY]are refused sign-in and need[USER, SELF_CERTIFY]; the repo-permissions doc example and the Playwright fixture are updated.Also bumps the temurin base image digests (separate commit): main's images fail the container scan on openssl/libssl3t64 3.0.13-0ubuntu3.15 (CVE-2026-84782). The new base images ship 3.16; the PR's container scan is the check.
closes #715
🤖 Generated with Claude Code