-
Notifications
You must be signed in to change notification settings - Fork 4.4k
fix: correct workspace admin permission validation in project member updates #9119
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: preview
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -15,6 +15,7 @@ | |
| WorkspaceMember, | ||
| User, | ||
| ) | ||
| from plane.app.permissions import ROLE | ||
|
|
||
|
|
||
| class TestProjectBase: | ||
|
|
@@ -229,6 +230,100 @@ def test_create_project_with_all_optional_fields(self, session_client, workspace | |
| assert response_data["network"] == project_data["network"] | ||
|
|
||
|
|
||
| @pytest.mark.contract | ||
| class TestProjectMemberAPI: | ||
| """Test project member role operations""" | ||
|
|
||
| def get_project_member_url(self, workspace_slug: str, project_id: uuid.UUID, pk: uuid.UUID) -> str: | ||
| return f"/api/workspaces/{workspace_slug}/projects/{project_id}/members/{pk}/" | ||
|
|
||
| @pytest.mark.django_db | ||
| def test_workspace_admin_can_promote_member_above_project_role(self, session_client, workspace, create_user): | ||
| """Workspace admins can assign project roles above their own project role.""" | ||
| project = Project.objects.create(name="Role Project", identifier="RP", workspace=workspace) | ||
| requesting_project_member = ProjectMember.objects.create( | ||
| project=project, member=create_user, role=ROLE.GUEST.value, is_active=True | ||
| ) | ||
|
|
||
| target_user = User.objects.create_user(email="target@example.com", username="target") | ||
| WorkspaceMember.objects.create( | ||
| workspace=workspace, member=target_user, role=ROLE.MEMBER.value, is_active=True | ||
| ) | ||
| target_project_member = ProjectMember.objects.create( | ||
| project=project, member=target_user, role=ROLE.MEMBER.value, is_active=True | ||
| ) | ||
|
|
||
| url = self.get_project_member_url(workspace.slug, project.id, target_project_member.id) | ||
| response = session_client.patch(url, {"role": ROLE.ADMIN.value}, format="json") | ||
|
|
||
| assert response.status_code == status.HTTP_200_OK | ||
| target_project_member.refresh_from_db() | ||
| assert target_project_member.role == ROLE.ADMIN.value | ||
|
|
||
| requesting_project_member.refresh_from_db() | ||
| assert requesting_project_member.role == ROLE.GUEST.value | ||
|
|
||
| @pytest.mark.django_db | ||
| def test_non_admin_project_member_cannot_promote_member_to_admin(self, api_client, workspace): | ||
| """Non-admin project members cannot promote project members.""" | ||
| project = Project.objects.create(name="Protected Role Project", identifier="PRP", workspace=workspace) | ||
|
|
||
| requesting_user = User.objects.create_user(email="requester@example.com", username="requester") | ||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. This assertion will fail. With requester project_role=15 patching a target whose project_role=15, the first guard in if project_member.role >= requested_project_member.role and not is_workspace_admin:
return Response({"error": "You cannot update the role of a member with a role equal to or higher than your own"},
status=status.HTTP_403_FORBIDDEN)
Both |
||
| WorkspaceMember.objects.create( | ||
| workspace=workspace, member=requesting_user, role=ROLE.MEMBER.value, is_active=True | ||
| ) | ||
| ProjectMember.objects.create(project=project, member=requesting_user, role=ROLE.MEMBER.value, is_active=True) | ||
|
|
||
| target_user = User.objects.create_user(email="member-target@example.com", username="member-target") | ||
| WorkspaceMember.objects.create( | ||
| workspace=workspace, member=target_user, role=ROLE.MEMBER.value, is_active=True | ||
| ) | ||
| target_project_member = ProjectMember.objects.create( | ||
| project=project, member=target_user, role=ROLE.MEMBER.value, is_active=True | ||
| ) | ||
|
|
||
| api_client.force_authenticate(user=requesting_user) | ||
|
|
||
| url = self.get_project_member_url(workspace.slug, project.id, target_project_member.id) | ||
| response = api_client.patch(url, {"role": ROLE.ADMIN.value}, format="json") | ||
|
|
||
| assert response.status_code == status.HTTP_403_FORBIDDEN | ||
| assert response.data["error"] == "You do not have permission to update roles" | ||
|
|
||
| target_project_member.refresh_from_db() | ||
| assert target_project_member.role == ROLE.MEMBER.value | ||
|
|
||
| @pytest.mark.django_db | ||
| def test_project_member_cannot_promote_lower_project_member(self, api_client, workspace): | ||
| """Non-admin project members cannot promote lower project members.""" | ||
| project = Project.objects.create(name="No Expansion Project", identifier="NEP", workspace=workspace) | ||
|
|
||
| requesting_user = User.objects.create_user(email="role-member@example.com", username="role-member") | ||
| WorkspaceMember.objects.create( | ||
| workspace=workspace, member=requesting_user, role=ROLE.MEMBER.value, is_active=True | ||
| ) | ||
| ProjectMember.objects.create(project=project, member=requesting_user, role=ROLE.MEMBER.value, is_active=True) | ||
|
|
||
| target_user = User.objects.create_user(email="lower-target@example.com", username="lower-target") | ||
| WorkspaceMember.objects.create( | ||
| workspace=workspace, member=target_user, role=ROLE.MEMBER.value, is_active=True | ||
| ) | ||
| target_project_member = ProjectMember.objects.create( | ||
| project=project, member=target_user, role=ROLE.GUEST.value, is_active=True | ||
| ) | ||
|
|
||
| api_client.force_authenticate(user=requesting_user) | ||
|
|
||
| url = self.get_project_member_url(workspace.slug, project.id, target_project_member.id) | ||
| response = api_client.patch(url, {"role": ROLE.MEMBER.value}, format="json") | ||
|
|
||
| assert response.status_code == status.HTTP_403_FORBIDDEN | ||
| assert response.data["error"] == "You do not have permission to update roles" | ||
|
|
||
| target_project_member.refresh_from_db() | ||
| assert target_project_member.role == ROLE.GUEST.value | ||
|
|
||
|
|
||
| @pytest.mark.contract | ||
| class TestProjectAPIGet(TestProjectBase): | ||
| """Test project GET operations""" | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This test passes on
previewwithout the PR. The bug it documents (workspace admin with low project role unable to promote) was already fixed by #9014 (is_workspace_admin = requester_workspace_role == ROLE.ADMIN.value). The test is still valuable as a regression guard, but it shouldn't be framed as proving this PR fixes anything — the production fix is already shipped.