openedx / openedx/openedx-authz
Bug: REST API mixed namespace PUT throws a 500
Open
@bmtcril is already working on this.
Since May 28, 2026.
- Dominant language
- Python
- Stars
- 0
- Forks
- 9
- Avg merge
- 13d 9h
- Merged PRs (30d)
- 9
Description
Sending PUT /api/authz/v1/roles/users/ with a scopes list that mixes namespaces (e.g., one lib: scope and one course-v1: scope) causes an uncaught ValueError inside DynamicScopePermission.has_permission. The exception propagates out of DRF's exception handler, which only handles APIException subclasses, and bubbles up to a 500.
It's a relatively small thing, but we should either gracefully handle mixed scopes or catch the error and return a 400 (and document the limitation).
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.