The GitHub Actions job "Backport Approval Check" on 
texera.git/fix/result-export-authz has failed.
Run started by GitHub user Yicong-Huang (triggered by Yicong-Huang).

Head commit for run:
8090b240e70143f76d00fcd3d81c97c11a7d8452 / ali <[email protected]>
fix(amber): hold result export to the same rules the export dialog applies

Both export endpoints build their work out of the request body, and the
only rule either applied was workflow read access. The per-operator
dataset restriction the downloadability endpoint computes for the UI, and
the computing unit the execution lookup keys on, were left to the client.

Both endpoints now share one validateUserCanExportResult: workflow read
access, access to the named computing unit, and no requested operator
carrying data out of a non-downloadable dataset the caller does not own.
The two new refusals answer 403 — the session is valid, and the
frontend's interceptor logs a user out on any 401.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_015qVdnpDpXZePfB9Zfa3noz

Report URL: https://github.com/apache/texera/actions/runs/35552163619

With regards,
GitHub Actions via GitBox

Reply via email to