From 0ee6e6b6306bacea848e6f00d7f5118b28512d3c Mon Sep 17 00:00:00 2001 From: Frederick Muriuki Muriithi Date: Wed, 19 Aug 2026 13:16:44 -0500 Subject: Remove `grant_access_to_sysadmins()` function. The "system-administrator" role acts at the system level and should not be granted against a non-system resource. This function is therefore a bug in its entirety and thus needed to go. --- gn_auth/auth/authorisation/resources/groups/models.py | 8 -------- 1 file changed, 8 deletions(-) (limited to 'gn_auth/auth/authorisation/resources/groups') diff --git a/gn_auth/auth/authorisation/resources/groups/models.py b/gn_auth/auth/authorisation/resources/groups/models.py index 07e6dbe..68f4ea0 100644 --- a/gn_auth/auth/authorisation/resources/groups/models.py +++ b/gn_auth/auth/authorisation/resources/groups/models.py @@ -19,8 +19,6 @@ from gn_auth.auth.authorisation.checks import authorised_p from gn_auth.auth.authorisation.privileges import Privilege from gn_auth.auth.authorisation.resources.errors import MissingGroupError from gn_auth.auth.authorisation.resources.system.models import system_resource -from gn_auth.auth.authorisation.resources.common import ( - grant_access_to_sysadmins) from gn_auth.auth.authorisation.resources.base import ( Resource, resource_from_dbrow) @@ -153,9 +151,6 @@ def create_group( "INSERT INTO group_resources(resource_id, group_id) " "VALUES(:resource_id, :group_id)", _group_resource) - grant_access_to_sysadmins(cursor, - _group_resource_id, - system_resource(conn).resource_id) add_user_to_group(cursor, new_group, group_leader) revoke_user_role_by_name(cursor, group_leader, "group-creator") assign_user_role_by_name(cursor, @@ -375,9 +370,6 @@ def remove_user_from_group( user, grp_resource.resource_id, "group-creator") - grant_access_to_sysadmins(cursor, - grp_resource.resource_id, - system_resource(conn).resource_id) @authorised_p( -- cgit 1.4.1