Skip to content

Backport RBAC (openedx-authz) bug fixes to release/verawood #513

Description

@BryanttV

Context

Since release/verawood was cut, several RBAC (openedx-authz) fixes have been merged into master. They correct wrongful 403s, crashes with platform-wide (glob) role assignments, and inconsistent permission gates. These fixes are not yet in release/verawood. Verawood is still on openedx-authz==1.21.0, while master is already on 1.23.0.

Goal

Backport to release/verawood the RBAC bug-fix PRs already merged into master, so Verawood doesn't carry permission regressions that are already resolved.

Scope

Includes: permission/role/authz fixes (Studio, Content Libraries, Instructor Dashboard) and the reverts that correct a previous backport.

Excludes:

  • New RBAC features, unless a fix needs them as a dependency (see "To evaluate").
  • Refactors, automated bumps, and test or lint fixes.

Backport criteria

  • Use git cherry-pick -x from the master commit.
  • If a fix depends on code or an openedx-authz version that Verawood doesn't have, backport the dependency first or drop the PR.
  • Each backport PR targets release/verawood, references the original PR, and passes the relevant tests.

PRs to backport (fixes)

403 / permission fixes in Studio

  • #38986 – Course Auditor gets 403 navigating to a course unit
  • #39075 – course editor gets 403 copying a unit to the clipboard
  • #39055 – allow Course Admin/Staff/Editor to sync library updates into a course
  • #39050 – gate xblock action menu on authz edit/manage_tags permissions
  • #39144 – align reindex link with authz permissions

Platform-wide (glob) and org-scoped roles

  • #38984 – RoleCache legacy compat layer ignores platform-wide glob role assignments
  • #38980 – platform-wide glob role assignments crash get_orgs_for_user/has_org_for_user
  • #38721 – add missing org scope support in instructor dashboard

Other

To decide before backporting

  • Revert #38973 (07f09868c1) – reverts "Cannot rerun courses – authz role assignment expects rerun to already exist" (#38840). Verawood does have #38840 (as #38858), so it probably needs the revert too. To be confirmed.
  • openedx-authz bump – #39001 (1.22.0 → 1.23.0). Verawood is on 1.21.0. We need to check whether the fixes above require a newer library version.

To evaluate (features the fixes might need as dependencies)

These are features, not fixes. Backport them only if a fix above doesn't apply cleanly without them:

  • #39013 – authz edit permission gate for XBlock component card action menu (likely a dependency of #39050)
  • #39007, #39008, #39010, #39009 – split read vs write authz checks (advanced settings, certificates, group configurations, library updates)
  • #39113 – add authz validation to course optimizer tool

Tasks

  • Verify that each PR applies cleanly on release/verawood (git cherry-pick --no-commit) and identify dependencies.
  • Resolve the openedx-authz bump and revert #38973.
  • Create the backport PRs (in chronological order to minimize conflicts).
  • Validate tests and merge.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions