Skip to content

permissions/branding: low-severity follow-ups from the tenancy-adoption review #396

Description

@antosubash

Low-severity follow-ups found while reviewing the tenancy-adoption stack (#385–#395).

  1. The permission editor drops a role's code-mapped permissions until restart. modules/permissions/permissions/service.py:~117-118 pops _role_map[role] and re-maps only the DB keys.
  2. The branding reaper deletes the bytes before its own commit. FileStorageService.delete flushes the soft-delete and deletes the backend object, and only then does branding/reaper.py commit.
    • If that commit fails, the row stays live with no bytes.
    • Fix: commit the soft-delete first, then delete the object, or leave orphaned objects to a janitor.
  3. branding/tenant_branding.py _INFLIGHT is module-global, shared across app instances in one process. In tests, a failed read that every waiter cancelled can log "exception never retrieved".

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions