diff options
| author | Frederick Muriuki Muriithi | 2026-08-19 13:16:44 -0500 |
|---|---|---|
| committer | Frederick Muriuki Muriithi | 2026-08-19 13:16:44 -0500 |
| commit | 0ee6e6b6306bacea848e6f00d7f5118b28512d3c (patch) | |
| tree | 9cfce60a5ceb1efa195be9ef6b934fcf5b9e9481 /gn_auth/auth/authorisation/resources/common.py | |
| parent | e478df43ec07cb7409cd11cbe0bd7717cfd7c045 (diff) | |
| download | gn-auth-0ee6e6b6306bacea848e6f00d7f5118b28512d3c.tar.gz | |
Remove `grant_access_to_sysadmins()` function.
The "system-administrator" role acts at the system level and should not be granted against a non-system resource. This function is therefore a bug in its entirety and thus needed to go.
Diffstat (limited to 'gn_auth/auth/authorisation/resources/common.py')
| -rw-r--r-- | gn_auth/auth/authorisation/resources/common.py | 24 |
1 files changed, 0 insertions, 24 deletions
diff --git a/gn_auth/auth/authorisation/resources/common.py b/gn_auth/auth/authorisation/resources/common.py index fd358f1..0c12fe1 100644 --- a/gn_auth/auth/authorisation/resources/common.py +++ b/gn_auth/auth/authorisation/resources/common.py @@ -22,27 +22,3 @@ def assign_resource_owner_role( "ON CONFLICT (user_id, role_id, resource_id) DO NOTHING", params) return params - - -def grant_access_to_sysadmins( - cursor: db.DbCursor, - resource_id: uuid.UUID, - system_resource_id: uuid.UUID -): - """Grant sysadmins access to resource identified by `resource_id`.""" - cursor.execute( - "SELECT role_id FROM roles WHERE role_name='system-administrator'") - sysadminroleid = cursor.fetchone()[0] - - cursor.execute(# Fetch sysadmin IDs. - "SELECT user_roles.user_id FROM roles INNER JOIN user_roles " - "ON roles.role_id=user_roles.role_id " - "WHERE role_name='system-administrator' AND resource_id=?", - (str(system_resource_id),)) - - cursor.executemany( - "INSERT INTO user_roles(user_id, role_id, resource_id) " - "VALUES (?, ?, ?) " - "ON CONFLICT (user_id, role_id, resource_id) DO NOTHING", - tuple((row["user_id"], sysadminroleid, str(resource_id)) - for row in cursor.fetchall())) |
