anzinmhd commented on issue #74357:
URL: https://github.com/apache/airflow/issues/74357#issuecomment-6024076893
I reproduced the authorization conflict on current `main`.
There appear to be two separate permission-model issues involved:
1. Higher default roles do not inherit lower-role resource permissions in
the generated Keycloak model. For example, an `Admin` request for `Pool / LIST`
could receive `PERMIT` from `Admin` and `ReadOnly`, but `DENY` from `Op`,
causing the overall result to be denied under the resource server's `UNANIMOUS`
strategy.
I have a fix for this part that explicitly models the default role
hierarchy in the generated `User` and `Op` resource permissions. The relevant
Keycloak CLI unit tests pass, and the `Admin -> Pool / LIST` authorization now
evaluates to `PERMIT` with the resource server still using `UNANIMOUS`.
2. There is also a separate menu-permission overlap. For example, `Viewer ->
Pools / MENU` currently evaluates `ReadOnly = PERMIT` and `Admin = DENY`,
resulting in an overall denial under `UNANIMOUS`.
I am keeping the menu-permission behavior separate for now because it
appears to need a different fix rather than just extending the role hierarchy.
I will open a PR for the first part and reference this issue rather than
closing it.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]