Skip to content

feat(users): reserve the tenant: role namespace, pin tenant-role isolation (#377) [stack 2/11] - #386

Merged
antosubash merged 6 commits into
tenancy/01-prereqsfrom
tenancy/02-permissions
Oct 1, 2026
Merged

antosubash merged 6 commits into
tenancy/01-prereqsfrom
tenancy/02-permissions

Conversation

@antosubash

Copy link
Copy Markdown
Owner

Closes #377. Stack 2/11 of the tenancy-adoption series (base: #385).

What

  • After feat(tenancy): fail-closed isolation + tenants module (SaaS groundwork) #370, grants already add up: resolved_permissions_for merges the registry's tenant:* mappings with the user's own roles. So this PR adds a guard and pins the behaviour in tests rather than changing logic.
  • Guard: a @validates("name") on users.Role rejects any role name that starts with tenant: (case-insensitive). No API creates or renames roles; they come only from bootstrap and seeds. Putting the guard on the model therefore covers every path.
  • Tests (14, modules/tenants/tests/test_tenant_role_permissions.py):
    • Reserved names are refused, on construction and on rename.
    • tenant:* roles hold no * and no platform permissions.
    • A tenant admin gets 403 on platform tenant admin routes.
    • sync_admin_all_permissions never touches tenant:*.
    • Only the active tenant's role applies.

Tests

make test-py: 3333 passed. make lint is clean.

https://claude.ai/code/session_01F8RiTBUJQnZmSq56qReZeV

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Deploying simple-module-python with  Cloudflare Pages  Cloudflare Pages

Latest commit: bf58c98
Status: ✅  Deploy successful!
Preview URL: https://b1832cec.simple-module-python.pages.dev
Branch Preview URL: https://tenancy-02-permissions.simple-module-python.pages.dev

View logs

@antosubash
antosubash added this pull request to stack #397 October 1, 2026 16:14
@antosubash
antosubash marked this pull request as ready for review October 1, 2026 16:15
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-10-01T16:19:05.554028Z bf58c98 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@antosubash
antosubash merged commit 87446de into main Oct 1, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

permissions: role→permission grants stay global, but must support mapping the synthetic tenant:<role> principal roles

1 participant