Skip to content

check every rule belongs to the project and role when reordering project role permissions - #14318

Open
Damans227 wants to merge 1 commit into
apache:4.20from
Damans227:project-role-rule-scope-4.20
Open

Damans227 wants to merge 1 commit into
apache:4.20from
Damans227:project-role-rule-scope-4.20

Conversation

@Damans227

Copy link
Copy Markdown
Collaborator

Reordering a project role's rules looked up each rule id on its own and never checked that it belonged to the project or role the call was made for. This makes reorder and single rule updates use the same lookup, which rejects rule ids from another project, and reorder also rejects rules from another role in the same project.

Test:

Unit tests added for a rule from another project, a rule from another role, and a normal reorder.

@codecov

codecov Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 85.71429% with 1 line in your changes missing coverage. Please review.
✅ Project coverage is 16.39%. Comparing base (4b2d387) to head (c2d8498).

Files with missing lines Patch % Lines
...in/acl/project/UpdateProjectRolePermissionCmd.java 85.71% 1 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff            @@
##               4.20   #14318   +/-   ##
=========================================
  Coverage     16.39%   16.39%           
- Complexity    13631    13638    +7     
=========================================
  Files          5669     5669           
  Lines        501541   501541           
  Branches      60925    60925           
=========================================
+ Hits          82228    82251   +23     
+ Misses       410104   410077   -27     
- Partials       9209     9213    +4     
Flag Coverage Δ
uitests 4.16% <ø> (ø)
unittests 17.26% <85.71%> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant