| Age | Commit message (Collapse) | Author | |
|---|---|---|---|
| 2026-06-03 | wsgi: extract __create_one_user__ helper from create_users | Claude Sonnet 4.6 | |
| Refactor create_users to delegate per-user DB creation to a shared __create_one_user__ helper. No behaviour change — preparation for reuse by the forthcoming create_test_users command. | |||
| 2026-06-03 | wsgi: add delete-users CLI command | Claude Sonnet 4.6 | |
| Add a delete-users command that removes one or more users by UUID, unconditionally bypassing the policy checks in the HTTP endpoint. Delegates to delete_users_by_id from the authorisation users models. | |||
| 2026-06-03 | Only grant system-administration role against the system resource. | Frederick Muriuki Muriithi | |
| 2026-06-02 | users/models: add delete_users_by_id function | Claude Sonnet 4.6 | |
| Add a low-level delete_users_by_id function that removes users and all their dependent data unconditionally, bypassing the policy checks in the '/auth/users/delete' HTTP endpoint (which refuses to delete privileged users). This is intended for use by CLI test-teardown commands and the sudo-wrapped CI cleanup script. It might also find utility in other places where we do actually need to delete a user and their data unconditionally. Co-authored-by: Frederick Muriuki Muriithi <fredmanglis@gmail.com> | |||
| 2026-06-02 | wsgi: add create-users CLI command | Claude Sonnet 4.6 | |
| Add a general-purpose `create-users` command that creates one or more users with explicitly specified name, email, password and role. Supported roles: system-admin (assigns default roles plus grant_sysadmin_role), none (assigns default roles only). Output is written as JSON to a file (with 0600 permissions) or stdout. Helper functions __parse_user_spec__ and __write_output__ are factored out for reuse by the forthcoming create-test-users command. | |||
| 2026-05-21 | Override all settings with the startup settings before doing checks. | Frederick Muriuki Muriithi | |
| The startup checks should be used sparingly, if at all, and they override every other setting. | |||
| 2026-05-21 | Remove dead code caught by vulture. | Frederick Muriuki Muriithi | |
| 2026-05-21 | Move scripts to top-level gn_auth package. | Frederick Muriuki Muriithi | |
| In preparation for migrating to pyproject.toml (from setup.py and friends) we need to have only one top-level package. This will also help in improving testing and checks down the line, since everything will be relative to one single top-level directory. | |||
| 2026-05-21 | Move migrations to top-level gn_auth package. | Frederick Muriuki Muriithi | |
| In preparation for migrating to pyproject.toml (from setup.py and friends) we need to have only one top-level package. This will also help in improving testing and checks down the line, since everything will be relative to one single top-level directory. | |||
| 2026-05-21 | Deprecate functions which duplicate those in gn-libs. | Frederick Muriuki Muriithi | |
| The `gn_auth.auth.authorisation.resources.checks.can_[edit/delete]` functions duplicate the utility provided by similar named functions in the `gn_libs.privileges.resources` package. These ones are, thus, deprecated in favour of the gn-libs ones. | |||
| 2026-05-21 | Delete unused function. | Frederick Muriuki Muriithi | |
| The `gn_auth.auth.authorisation.resources.checks.can_view` function is no longer used in this code base. It can be safely removed. | |||
| 2026-05-21 | Remove unused argument/parameter from function. | Frederick Muriuki Muriithi | |
| 2026-05-20 | Raise a NotFoundError if not a single resource is found. | Frederick Muriuki Muriithi | |
| 2026-05-20 | Initialise initial value used in reduce. | Frederick Muriuki Muriithi | |
| To avoid failures later due to missing keys, we initialise the initial value used in reduce to a dict with empty tuples for every key. | |||
| 2026-05-18 | Refactor authorisation-by-datasets-and-traits endpoint. | Frederick Muriuki Muriithi | |
| Fetch resources using the dataset names (and trait names where relevant) to simplify the code, and make it clearer what the endpoint actually does. | |||
| 2026-05-18 | Fetch genotype resources by dataset. | Frederick Muriuki Muriithi | |
| 2026-05-18 | Fetch mRNA resources by dataset name. | Frederick Muriuki Muriithi | |
| 2026-05-18 | Fetch phenotype resources by dataset name and trait name. | Frederick Muriuki Muriithi | |
| 2026-05-18 | Update call to `can_edit` to separate resource and system privileges | Frederick Muriuki Muriithi | |
| 2026-05-18 | Replace objects with gn_libs alternatives and deprecate the module. | Frederick Muriuki Muriithi | |
| Replace the functions and classes in `gn_auth.auth.db.sqlite3` with those in `gn_libs.sqlite3` to reduce duplications. Deprecate the `gn_auth.auth.db.sqlite3` module and the remaining function(s) within in preparation for removal. | |||
| 2026-05-01 | Use module-level logging rather than the app's logger. | Frederick Muriuki Muriithi | |
| 2026-05-01 | Enable turning logging on/off by module. | Frederick Muriuki Muriithi | |
| To help with debugging and traceability, both in development and production, we need to be able to turn individual module loggers on or off in a flexible way. This commit enables that. | |||
| 2026-05-01 | Ensure ALL users with access to the resource are actually listed. | Frederick Muriuki Muriithi | |
| 2026-04-23 | Remove debug artifact. | Frederick Muriuki Muriithi | |
| 2026-04-23 | Improve error messages. | Frederick Muriuki Muriithi | |
| 2026-04-23 | Fix minor linting bugs. | Frederick Muriuki Muriithi | |
| 2026-04-23 | AuthorisationError is HTTP status code 401. | Frederick Muriuki Muriithi | |
| 2026-04-23 | Allow anonymous users "public-view" privileges. | Frederick Muriuki Muriithi | |
| The default system-level privilege is the "public-view", i.e. the users can view basic details about the Genenetwork system. If no authorisation is provided when accessing the /auth/system/roles endpoint, return the default role/privilege. | |||
| 2026-04-20 | Implement editing resource name. | Frederick Muriuki Muriithi | |
| 2026-04-20 | Use module-level logger rather than application's logger. | Frederick Muriuki Muriithi | |
| 2026-04-15 | Do not grant sysadmins direct access at resource creation. | Frederick Muriuki Muriithi | |
| 2026-04-08 | user resources: Add a text filter for further filtering. | Frederick Muriuki Muriithi | |
| 2026-04-08 | user resources: Enable filtering using only the limit and offset. | Frederick Muriuki Muriithi | |
| 2026-04-08 | Use module-level logger. | Frederick Muriuki Muriithi | |
| 2026-04-08 | user resources: return total with filtered records. | Frederick Muriuki Muriithi | |
| Return a count of the total number of resources that the user has access to even if we are only interested in a few of the records. | |||
| 2026-04-07 | Handle minor bug. | Frederick Muriuki Muriithi | |
| 2026-04-07 | Update code to handle resource creators and creation times. | Frederick Muriuki Muriithi | |
| 2026-04-07 | Add creator and creation time tracking to Resources. | Frederick Muriuki Muriithi | |
| 2026-04-02 | Update resource creation: Add tracking information | Frederick Muriuki Muriithi | |
| Add the creator of the resource and the time the resource was created. | |||
| 2026-03-26 | Update edit access: use more flexible 'can_edit(...)' function. | Frederick Muriuki Muriithi | |
| 2026-02-10 | Check only for the base URL and path. | Frederick Muriuki Muriithi | |
| To allow the client to pass flags to the redirect_uri that the authorisation server has no interest in, check that only the "base" url (protocol, hostname/netlog and path) are registered, ignoring any query and fragment parameters. | |||
| 2026-02-10 | Bug: Fix import path. | Frederick Muriuki Muriithi | |
| 2026-02-10 | Setup correct flash message classes. | Frederick Muriuki Muriithi | |
| 2026-02-10 | Authorisation Check: New function to check user has edit access. | Frederick Muriuki Muriithi | |
| 2026-02-10 | Authorisation Check: New function to check user has view access. | Frederick Muriuki Muriithi | |
| 2026-02-10 | Use Auth function that checks for delete access. | Frederick Muriuki Muriithi | |
| 2026-02-10 | Authorisation Check: New function to check user has delete access. | Frederick Muriuki Muriithi | |
| 2026-02-06 | Use AuthorisationError to indicate error condition. | Frederick Muriuki Muriithi | |
| 2026-02-06 | Replace hard-coded email check with check against privileges | Frederick Muriuki Muriithi | |
| Fix the check: rather than using a hard-coded email to check for authorisation, we instead check against the privileges the user has on the resource, or whether they have global privileges allowing them to act on any data. | |||
| 2026-02-06 | Fetch a single resource ID: delete data from one resource at a time. | Frederick Muriuki Muriithi | |
