fix(permissions): admin can no longer operate tests — start/submit/edit/create, view only
Aegis CI / lint-and-test (push) Has been cancelled
Snyk Security Scan / Python vulnerabilities (backend) (push) Has been cancelled
Snyk Security Scan / npm vulnerabilities (frontend) (push) Has been cancelled
Snyk Security Scan / Docker image vulnerabilities (backend) (push) Has been cancelled

Admin still bypassed require_any_role (non-strict) on the pure
operator actions: start-execution, submit-red, start-blue-work,
submit-blue, pause/resume-timer, and the red/blue field-edit + general
test create/update/remediation/import-rt/template endpoints all used
the loose dependency even where admin wasn't in the role tuple.
Switched every one of these to require_any_role_strict, matching the
review/validate/dispute/hold/assign endpoints already fixed earlier.

Frontend: removed every remaining role === "admin" disjunct gating
Start Execution, Submit to Blue Team, blue evaluating actions, timer
control, red/blue field editing, test creation, and template creation.
Team-blindness visibility (isBlind) deliberately keeps the admin
bypass — admin still sees both sides unmasked for oversight, since
that's visibility, not operating.

Updated ~20 tests whose fixtures used the admin account as a
convenience shortcut to create/drive tests through the workflow —
switched them to a red_lead account, fixing an incidental
fixture-resolution-order cookie bug along the way (client's cookie
jar prefers the last-logged-in role's cookie over any Bearer header
explicitly passed to a later request).
This commit is contained in:
kitos
2026-07-13 09:27:43 +02:00
parent 337faf824d
commit a3f86c7b31
13 changed files with 110 additions and 72 deletions
+2 -2
View File
@@ -80,9 +80,9 @@ export default function TestCatalogPage() {
const [searchParams, setSearchParams] = useSearchParams();
const { user } = useAuth();
// Only leads and admins can create tests from templates
// Only leads can create tests from templates — admin administers the
// site, not test content.
const canUseTemplate =
user?.role === "admin" ||
user?.role === "red_lead" ||
user?.role === "blue_lead";
+4 -5
View File
@@ -519,14 +519,13 @@ export default function TestDetailPage() {
const role = user?.role ?? "";
const canSaveRed =
(test.state === "draft" || test.state === "red_executing") &&
(role === "red_tech" || role === "red_lead" || role === "admin");
(role === "red_tech" || role === "red_lead");
const canSaveBlue =
test.state === "blue_evaluating" &&
(role === "blue_tech" || role === "blue_lead" || role === "admin");
(role === "blue_tech" || role === "blue_lead");
// Only leads and admins can create templates
const canSaveAsTemplate =
role === "red_lead" || role === "blue_lead" || role === "admin";
// Only leads can create templates — admin administers the site, not test content.
const canSaveAsTemplate = role === "red_lead" || role === "blue_lead";
// ── Render ─────────────────────────────────────────────────────
+2 -2
View File
@@ -139,8 +139,8 @@ export default function TestsPage() {
const navigate = useNavigate();
const { user } = useAuth();
const canCreate =
user?.role === "admin" || user?.role === "red_lead" || user?.role === "blue_lead";
// Only leads can create tests — admin administers the site, not test content.
const canCreate = user?.role === "red_lead" || user?.role === "blue_lead";
const techRole = isTechRole(user?.role);