| Age | Commit message (Collapse) | Author |
|
The system-administrator role carries system:resource:assign-owner
(migration 20250729_02), but no endpoint used it. Sysadmins had no API
path to bootstrap ownership on a resource that has no owner yet.
Implement two endpoints in gn_auth/auth/system/admin/resources.py
(the blueprint skeleton was already wired in a preceding commit):
POST /auth/system/administration/resources/<resource_id>/assign-owner
Body: {"user_id": "<uuid>"}
Assigns the resource-owner role to the named user on the resource.
POST /auth/system/administration/resources/<resource_id>/revoke-owner
Body: {"user_id": "<uuid>"}
Revokes the resource-owner role from the named user on the resource.
Both check system:resource:assign-owner on the *system* resource, so a
sysadmin can grant/revoke ownership without being resource-owner
themselves.
Reviewed-By: Frederick M. Muriithi <fredmanglis@gmail.com>
|
|
|
|
JWTBearerToken.__init__ was calling with_db_connection with
app.config["SQL_URI"] (the GeneNetwork MariaDB URI) to look up the
authenticated user and OAuth2 client. gn_libs.sqlite3.with_db_connection
expects a SQLite file path, so passing a MySQL URI causes an
OperationalError: unable to open database file every time a JWT is
validated through require_oauth.acquire().
Use app.config["AUTH_DB"] (the gn-auth SQLite database) for both
lookups. Also normalise the whitespace in the user lookup lambda while
here.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Reviewed-By: Frederick M. Muriithi <fredmanglis@gmail.com>
|
|
The gn_auth.auth.db.sqlite3 module is deprecated and should be
removed. This cleanup goes a ways towards that goal.
|
|
Prefer the endpoint `/auth/users/<uuid:user_id/roles/revoke` that
conforms to the Subject-Verb-Object paradigm, i.e. Revoke from a
user (subject), the specified role acting on the specified
resource (object) -- revoke a role would be the 'Verb'.
|
|
Adds unassign_user_role_by_name to roles/models.py — mirrors
assign_user_role_by_name but issues a resource-scoped DELETE,
resolving the TODO on the older revoke_user_role_by_name which
lacked the resource_id filter.
The new revoke_user_role endpoint checks resource:user:assign-role
(same privilege as assign) via can_assign_role, then calls
unassign_user_role_by_name.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Reviewed-By: Frederick M. Muriithi <fredmanglis@gmail.com>
|
|
|
|
Checks resource:user:assign-role via can_assign_role (gn_libs.privileges.resources)
on the caller's roles for the request's resource_id — caller must hold
resource-owner (or masquerade as one) on that resource.
Updates test setup to grant resource-owner on SYSTEM_RESOURCE instead of
system-administrator, matching the actual privilege model.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Reviewed-By: Frederick M. Muriithi <fredmanglis@gmail.com>
|
|
|
|
Parses email/name/password from the JSON body, calls create_verified_user,
and returns 201 with the new user's user_id, email, and name.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Reviewed-By: Frederick M. Muriithi <fredmanglis@gmail.com>
Added input validation.
|
|
|
|
Adds @require_oauth("profile") for 401 on unauthenticated requests and
an authorised_for2 check for the system:user:create-user privilege,
raising ForbiddenAccess (403) for non-admin callers.
Returns 501 for the success path until the body logic is implemented.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Reviewed-By: Frederick M. Muriithi <fredmanglis@gmail.com>
|
|
Two TDD tests that define the expected auth behaviour of the new
create-user endpoint before it is implemented:
- No Authorization header → 401
- Valid token for a non-admin user → 403
Both tests fail (404) until the endpoint exists.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Reviewed-By: Frederick M. Muriithi <fredmanglis@gmail.com>
Add's aso a dummy endpoint.
|
|
Replaces the dummy stub with a real implementation that:
- calls save_user(cursor, email, name, verified=True) to create the user
with the verified flag set, bypassing the email verification flow
- calls set_user_password to store the hashed credential in user_credentials
- returns the newly created User with no roles assigned
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Reviewed-By: Frederick M. Muriithi <fredmanglis@gmail.com>
|
|
Two unit tests for the (not yet implemented) create_verified_user function
in gn_auth.auth.authorisation.users.admin.models:
* test_create_verified_user_sets_verified_flag — asserts user.verified is
True and the flag is persisted in the DB
* test_create_verified_user_has_no_roles — asserts no roles are assigned
to the newly created user
Both tests use conn_after_auth_migrations to run against a fully migrated
SQLite test database.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Reviewed-By: Frederick M. Muriithi <fredmanglis@gmail.com>
|
|
|
|
|
|
|
|
dataset list in query
Previously the full list of datasets (currently over 900) was included in the query. This commit instead handles the exclusion at the Python level, dramatically speeding up the query
|
|
The "system-administrator" role acts at the system level and should
not be granted against a non-system resource. This function is
therefore a bug in its entirety and thus needed to go.
|
|
|
|
|
|
While we do not actually use the password-flow for authentication on
the system, it is useful for getting tokens when running (integration)
tests against the system. This commit allows the test harness to make
use of the simpler password-flow authentication to get tokens.
|
|
|
|
|
|
|
|
On CI/CD, the tests are run under a different user that the one that
runs the gn-auth service, therefore we need the generated files to be
readable by more than just the user running the gn-auth service.
|
|
|
|
ever allowing them
This commit allows the auth system to handle Temp traits (by just treating them as public traits)
|
|
|
|
Add delete-test-users which reads the credentials file produced by
create-test-users and deletes all listed users unconditionally via
delete_users_by_id, bypassing policy checks. Intended for CI teardown.
|
|
Add delete-oauth2-client which reads a credentials file produced
by create-oauth2-client or create-test-oauth2-client and removes the
client and its associated tokens from the database.
|
|
Add create-test-oauth2-client which reads the users-file produced
by create-test-users to find the client owner, auto-generates the client
name with the session timestamp, and delegates to __create_one_client__.
|
|
Add a __create_one_client__ helper that constructs an OAuth2Client,
hashes the secret, persists it via save_client, and returns a credential
record dict. Add create-oauth2-client CLI command that exposes all client
parameters explicitly. Preparation for reuse by create-test-oauth2-client.
|
|
Add create_test_users which auto-generates timestamped emails and random
passwords for ephemeral test accounts, delegating DB creation to the
__create_one_user__ helper introduced in the previous commit.
|
|
Refactor create_users to delegate per-user DB creation to a shared
__create_one_user__ helper. No behaviour change — preparation for
reuse by the forthcoming create_test_users command.
|
|
Add a delete-users command that removes one or more users by UUID,
unconditionally bypassing the policy checks in the HTTP endpoint.
Delegates to delete_users_by_id from the authorisation users models.
|
|
|
|
Add a low-level delete_users_by_id function that removes users and all
their dependent data unconditionally, bypassing the policy checks in the
'/auth/users/delete' HTTP endpoint (which refuses to delete privileged
users).
This is intended for use by CLI test-teardown commands and the
sudo-wrapped CI cleanup script. It might also find utility in other
places where we do actually need to delete a user and their data
unconditionally.
Co-authored-by: Frederick Muriuki Muriithi <fredmanglis@gmail.com>
|
|
Add a general-purpose `create-users` command that creates one or more
users with explicitly specified name, email, password and role.
Supported roles: system-admin (assigns default roles plus
grant_sysadmin_role), none (assigns default roles only).
Output is written as JSON to a file (with 0600 permissions) or stdout.
Helper functions __parse_user_spec__ and __write_output__ are factored
out for reuse by the forthcoming create-test-users command.
|
|
The startup checks should be used sparingly, if at all, and they
override every other setting.
|
|
|
|
In preparation for migrating to pyproject.toml (from setup.py and
friends) we need to have only one top-level package. This will also
help in improving testing and checks down the line, since everything
will be relative to one single top-level directory.
|
|
In preparation for migrating to pyproject.toml (from setup.py and
friends) we need to have only one top-level package. This will also
help in improving testing and checks down the line, since everything
will be relative to one single top-level directory.
|
|
The `gn_auth.auth.authorisation.resources.checks.can_[edit/delete]`
functions duplicate the utility provided by similar named functions in
the `gn_libs.privileges.resources` package. These ones are, thus,
deprecated in favour of the gn-libs ones.
|
|
The `gn_auth.auth.authorisation.resources.checks.can_view` function is
no longer used in this code base. It can be safely removed.
|
|
|
|
|
|
To avoid failures later due to missing keys, we initialise the initial
value used in reduce to a dict with empty tuples for every key.
|
|
Fetch resources using the dataset names (and trait names where
relevant) to simplify the code, and make it clearer what the endpoint
actually does.
|