yasithdev opened a new pull request, #605:
URL: https://github.com/apache/airavata-custos/pull/605

   Admins can create projects over HTTP, but cannot edit a project, change its 
PI, or manage CO_PI / ALLOCATION_MANAGER tags. Nothing stops HTTP writes to 
projects that an external system (AMIE) owns.
   
   **Repro (master)**
   - `PUT /projects/{id}` → 405; a project created via `POST /projects` has no 
PI tag.
   - A CO_PI without an allocation membership is missing from `GET 
/projects/{id}/members`.
   - `POST /compute-allocation-memberships` on an AMIE-imported project's 
allocation succeeds over HTTP.
   
   This PR:
   
   | Change | Behavior |
   |---|---|
   | `POST /projects` | Origination is set to `custos`; `CreateProject` writes 
the PI tag in its transaction |
   | `PUT /projects/{id}` `{title, project_pi_id}` | Uses `UpdateProject`; a PI 
change moves the PI tag, allocation memberships untouched |
   | `PUT /projects/{id}/roles/{userId}` `{role}` | `EnsureProjectMembership`: 
`CO_PI` / `ALLOCATION_MANAGER` set the tag, `MEMBER` removes it; PI changes → 
409 |
   | `GET /projects/{id}/members` | Also lists tag holders without an 
allocation membership |
   | Read-only guard | HTTP writes (caller present) to non-`custos` projects, 
their allocations, memberships, resource mappings and membership overrides → 
409 `ErrExternalManaged`; connectors are unaffected |
   
   Projects created over HTTP before this change keep whatever origination was 
sent and become read-only unless backfilled to `custos`.
   
   **Test plan**
   - `internal/server/admin_project_integration_test.go`: admin create → 
`custos` + PI tag; assign CO_PI; PI change keeps the old PI's allocation; HTTP 
writes to an external project → 409 while the connector path succeeds.
   - `go test -tags integration ./...` against Postgres; `go generate ./...` 
leaves only `api/core.openapi.yaml` changed.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to