oxidecomputer / oxidecomputer/omicron
Add authz checks on non-external DataStore methods
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 572
- Forks
- 97
- Avg merge
- 2d 12h
- Merged PRs (30d)
- 96
Description
Some intended-for-internal-use DataStore methods already have authz checks (e.g., inventory management), but others do not (e.g., Oximeter collector/producer management). They all should, although as long as they're only called by internal-to-Nexus systems (RPWs, sagas, etc.), this presumably isn't particularly urgent.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by comparing the existing authorization checks in nexus/db-queries/src/db/datastore/inventory.rs with the unchecked methods in nexus/db-queries/src/db/datastore/oximeter.rs. Review the other intended-for-internal-use DataStore methods and their RPW or saga callers, then confirm that each such method enforces authorization consistently.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- authorization, backend
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100