Repository navigation
Conversation
AdminMiddleware passes any user who is an admin of any team. It gated the /api/admin write group, platform provider CRUD, management addon and GitOps mutations, and Git provider config. A team admin could therefore create users, edit identity providers, network pools, policies, the platform config and any other team's members. Platform-level mutations now use RequirePlatformAdmin. Team member and group-sync routes keep the any-team-admin middleware and the handlers narrow it to the named team (authorizeTeamMembershipChange). GET /api/admin/config and GET /api/admin/audit move to the platform-viewer tier of the /admin group so read-only platform viewers can use them.
Review follow-up. GET /api/admin/config returns the audit and notification webhook URLs, which are bearer-like secrets, so it stays in the platform-admin group; only the audit log moves to the viewer tier. AuditHandler.ListTeam now accepts platform viewers alongside team admins, matching ListAll.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
auth.AdminMiddleware(internal/auth/middleware.go:431) isRequireAdmin, which passes any user who is an admin of any team (UserSession.IsAdmin,session.go:299). It gated the/api/adminwrite group, platform provider CRUD, management addon and GitOps mutations, and Git provider config (router.go:320,332,396,485,542). A team admin could create users, edit identity providers, network pools, policies, the platform config, and add or remove members of teams they do not administer. Found in the 2026-08 parity audit (H15, D5).Change
auth.RequirePlatformAdmin()(previously defined, never wired).IsAdminOfTeam(name)throughauthorizeTeamMembershipChange, so an admin of team A cannot edit team B.GET /admin/configandGET /admin/auditmove to the platform-viewer tier of the/admingroup;AuditHandler.ListAllaccepts platform viewer or above instead of platform admin only.GET /admin/observability/statusstays admin-only because the handler writes ButlerConfig.Verification
CGO_ENABLED=0 go build ./...,go vet ./internal/api/...cleanCGO_ENABLED=0 go test ./...passes;teams_membership_authz_test.gocovers nil session, platform admin, platform viewer, own-team admin, other-team admin, and mixed memberships./adminroute already required platform viewer or above before this change, so no currently working caller loses access.Depends on
#92 (team create/update/delete gates). Independent files except the
/admin/teamslines inrouter.go; merge either order.Out of scope
Observed while here: the whole
/api/adminroute requires platform viewer or above, so a team admin without a platform role cannot reach/api/admin/teams/{t}/membersat all, which is what the consoleTeamMembersPagecalls. That is pre-existing and worth a product decision (team-scoped member management outside/admin). TheUpdateMemberRolehandler still allows promoting to admin without restriction; unchanged here.