UNOMI-976: Restrict Groovy action upload to system administrators - #852
Open
sergehuber wants to merge 1 commit into
Open
UNOMI-976: Restrict Groovy action upload to system administrators#852sergehuber wants to merge 1 commit into
sergehuber wants to merge 1 commit into
Conversation
Uploading a Groovy action puts code into the server process. That is a host-level operation rather than something confined to one tenant's data plane, so GroovyActionsEndPoint now requires UnomiRoles.ADMINISTRATOR on every path, including the multipart upload. GroovyActionsServiceImpl also compiles through GroovyClassLoader.parseClass(codeSource, false) rather than GroovyShell.parse. The distinction matters because GroovyShell.parse instantiates the script, and instantiating a Groovy script is what evaluates its @field initializers. Saving an action should compile it and nothing more; evaluating any part of a script's body belongs to dispatch, not to storage. The emitted bytecode is otherwise identical, which was checked rather than assumed. testSaveCompilesWithoutInstantiating carries its own positive control: the same script is first run through a plain GroovyShell and must set the marker. Without that step a probe that silently failed to set it would make the real assertion pass while proving nothing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Closed
10 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Uploading a Groovy action puts code into the server process. That is a host-level operation rather
than something confined to one tenant's data plane, so GroovyActionsEndPoint now requires
UnomiRoles.ADMINISTRATOR on every path, including the multipart upload.
GroovyActionsServiceImpl also compiles through GroovyClassLoader.parseClass(codeSource, false)
rather than GroovyShell.parse. The distinction matters because GroovyShell.parse instantiates the
script, and instantiating a Groovy script is what evaluates its @field initializers. Saving an
action should compile it and nothing more; evaluating any part of a script's body belongs to
dispatch, not to storage. The emitted bytecode is otherwise identical, which was checked rather
than assumed.
testSaveCompilesWithoutInstantiating carries its own positive control: the same script is first run
through a plain GroovyShell and must set the marker. Without that step a probe that silently failed
to set it would make the real assertion pass while proving nothing.
Jira: https://issues.apache.org/jira/browse/UNOMI-976