Skip to content

Add a read-only READER role and an explicit default role for IdP users - #718

Merged
coopernetes merged 2 commits into
mainfrom
feature/reader-role
Oct 3, 2026
Merged

coopernetes merged 2 commits into
mainfrom
feature/reader-role

Conversation

@coopernetes

@coopernetes coopernetes commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Everyone who signed in got USER, and every IdP role mapping added it too, so require-role-mapping: false let anyone in the directory approve other people's pushes.

  • READER sees pushes, repositories, providers and fetch and SCM API activity, and changes nothing.
  • Acting needs USER or ADMIN (ADMIN implies USER); AUDITOR still makes a session read-only. A repository grant is inert for a user who cannot act, including one with no stored record.
  • A mapping grants only the role it names. auth.default-role (NONE default, READER, USER, AUDITOR) decides what an IdP user with no mapped session role gets; it replaces the deprecated require-role-mapping (true → NONE, false → READER, both set fails startup).
  • A session holding none of READER, USER, AUDITOR, ADMIN is refused, so SELF_CERTIFY alone admits no one.
  • LDAP, AD and OIDC share one mapper (IdpRoleMapper); LDAP and AD without a group search base now go through it too.
  • Startup warns about mappings and local users that admit no one alone, and fails when role-mappings is empty and the default role is NONE.
  • Add User form offers Reader, User, Auditor, Admin. Authentication docs gain an upgrading section.
  • Test Permission says why a matching grant is denied (reason: ROLE_CANNOT_ACT, additive on the response).
  • Playwright: observer is now a READER with its own spec; a new newcomer (plain USER, no grants) takes over the specs that grant to or act as a user.

Worth a close look:

  • An IdP deployment with empty role-mappings fails to start until it sets default-role (it used to give everyone USER).
  • Local users configured as roles: [SELF_CERTIFY] are refused sign-in and need [USER, SELF_CERTIFY]; the repo-permissions doc example and the Playwright fixture are updated.

Also bumps the temurin base image digests (separate commit): main's images fail the container scan on openssl/libssl3t64 3.0.13-0ubuntu3.15 (CVE-2026-84782). The new base images ship 3.16; the PR's container scan is the check.

closes #715

🤖 Generated with Claude Code

@coopernetes
coopernetes force-pushed the feature/reader-role branch 2 times, most recently from 535f03a to f5773fd Compare October 2, 2026 17:41
@coopernetes coopernetes changed the title Add a read-only READER role and stop granting USER implicitly Add a read-only READER role and an explicit default role for IdP users Oct 2, 2026
@coopernetes
coopernetes force-pushed the feature/reader-role branch 2 times, most recently from ab38bb6 to 38cb2a8 Compare October 2, 2026 23:09
coopernetes and others added 2 commits October 2, 2026 21:39
Everyone who signed in got USER, and every IdP role mapping added it too, so an open deployment
(require-role-mapping: false) let anyone in the directory approve other people's pushes.

READER sees pushes, repositories, providers and activity and changes nothing. Acting now needs
USER or ADMIN (ADMIN implies USER), a mapping grants only the role it names, and a session with no
READER, USER, AUDITOR or ADMIN role is refused. A repository grant is inert for a user who cannot
act; Test Permission says why.

auth.default-role (NONE, READER, USER or AUDITOR; NONE by default) decides what an IdP user with no mapped
session role gets. It replaces auth.require-role-mapping, which is still accepted with a warning
(true reads as NONE, false as READER). Startup fails when role-mappings is empty and the default
role is NONE, since no one could sign in.

closes #715

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The images on main shipped openssl and libssl3t64 3.0.13-0ubuntu3.15 (CVE-2026-84782, high, plus
four low). Ubuntu published 3.16 on 2026-09-29, but the build's apt upgrade step was served from
the build cache, so it never ran against the new archive. The 2026-10-02 temurin images ship 3.16.

The SECURITY_UPGRADE_PKGS apt upgrade goes: the base images now carry the fix, and a cached layer
made it unreliable anyway.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@coopernetes
coopernetes enabled auto-merge October 3, 2026 01:39
@coopernetes
coopernetes merged commit 35619e0 into main Oct 3, 2026
25 checks passed
@coopernetes
coopernetes deleted the feature/reader-role branch October 3, 2026 01:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Read-only READER role and limited open access

1 participant