Commit 18dffe1
feat: require explicit admin override for self-approval; fix :run PID file
Admin users now follow the same self-approval path as regular users when
reviewing their own pushes. ROLE_ADMIN alone no longer bypasses the
identity check for self-review — admins either use the self-certify path
(ROLE_SELF_CERTIFY + repo permission) or must explicitly activate an
admin override toggle in the dashboard UI.
Changes:
- Backend: checkReviewerIdentity now treats admin self-review the same
as regular user self-review unless adminOverride=true is sent in the
approve request body. Admins reviewing someone else's push still bypass
unconditionally. isSelfApproval only flags the attestation when the
override is explicitly used.
- Frontend: isSelfReview applies to admins too; self-certify blue banner
shown for admins with the permission; admin override toggle is hidden
when self-certify is active and only surfaces as a low-prominence link
for the break-glass case.
- Fix :run PID file: applicationDefaultJvmArgs only applies to generated
distribution scripts, not the Gradle JavaExec run task. Added the
-Dgitproxyjava.pidfile JVM arg explicitly to tasks.named('run') in
both server and dashboard build.gradle so :stop works after ctrl+c.
- Local config: grant thomas-cooper ROLE_SELF_CERTIFY so the self-certify
path is exercisable in local dev without needing the admin override.
closes #184
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>1 parent d2e08c7 commit 18dffe1
7 files changed
Lines changed: 104 additions & 45 deletions
File tree
- git-proxy-java-dashboard
- frontend/src
- pages
- src
- main/java/org/finos/gitproxy/dashboard/controller
- test/java/org/finos/gitproxy/dashboard/controller
- git-proxy-java-server
- src/main/resources
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
116 | 116 | | |
117 | 117 | | |
118 | 118 | | |
| 119 | + | |
119 | 120 | | |
120 | 121 | | |
121 | 122 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
98 | 98 | | |
99 | 99 | | |
100 | 100 | | |
| 101 | + | |
101 | 102 | | |
102 | 103 | | |
103 | 104 | | |
| |||
Lines changed: 28 additions & 12 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
449 | 449 | | |
450 | 450 | | |
451 | 451 | | |
| 452 | + | |
452 | 453 | | |
453 | 454 | | |
454 | 455 | | |
| |||
470 | 471 | | |
471 | 472 | | |
472 | 473 | | |
| 474 | + | |
473 | 475 | | |
474 | 476 | | |
475 | 477 | | |
| |||
550 | 552 | | |
551 | 553 | | |
552 | 554 | | |
| 555 | + | |
553 | 556 | | |
554 | 557 | | |
555 | 558 | | |
| |||
887 | 890 | | |
888 | 891 | | |
889 | 892 | | |
890 | | - | |
891 | | - | |
892 | | - | |
| 893 | + | |
893 | 894 | | |
894 | 895 | | |
895 | 896 | | |
896 | 897 | | |
897 | 898 | | |
898 | | - | |
| 899 | + | |
| 900 | + | |
| 901 | + | |
899 | 902 | | |
900 | 903 | | |
901 | 904 | | |
| |||
924 | 927 | | |
925 | 928 | | |
926 | 929 | | |
927 | | - | |
| 930 | + | |
928 | 931 | | |
929 | 932 | | |
930 | 933 | | |
| |||
933 | 936 | | |
934 | 937 | | |
935 | 938 | | |
936 | | - | |
| 939 | + | |
937 | 940 | | |
938 | | - | |
| 941 | + | |
939 | 942 | | |
940 | 943 | | |
941 | 944 | | |
942 | 945 | | |
943 | 946 | | |
944 | 947 | | |
945 | | - | |
| 948 | + | |
| 949 | + | |
| 950 | + | |
| 951 | + | |
| 952 | + | |
| 953 | + | |
| 954 | + | |
| 955 | + | |
| 956 | + | |
946 | 957 | | |
947 | 958 | | |
948 | 959 | | |
| |||
962 | 973 | | |
963 | 974 | | |
964 | 975 | | |
965 | | - | |
| 976 | + | |
966 | 977 | | |
967 | 978 | | |
968 | 979 | | |
| |||
977 | 988 | | |
978 | 989 | | |
979 | 990 | | |
980 | | - | |
| 991 | + | |
981 | 992 | | |
982 | 993 | | |
983 | 994 | | |
984 | 995 | | |
985 | 996 | | |
986 | 997 | | |
987 | 998 | | |
988 | | - | |
| 999 | + | |
989 | 1000 | | |
990 | 1001 | | |
991 | 1002 | | |
| |||
997 | 1008 | | |
998 | 1009 | | |
999 | 1010 | | |
1000 | | - | |
| 1011 | + | |
| 1012 | + | |
| 1013 | + | |
| 1014 | + | |
| 1015 | + | |
| 1016 | + | |
1001 | 1017 | | |
1002 | 1018 | | |
1003 | 1019 | | |
| |||
git-proxy-java-dashboard/src/main/java/org/finos/gitproxy/dashboard/controller/PushController.java
Lines changed: 39 additions & 26 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
138 | 138 | | |
139 | 139 | | |
140 | 140 | | |
141 | | - | |
142 | | - | |
143 | | - | |
144 | | - | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
145 | 146 | | |
146 | 147 | | |
147 | 148 | | |
| |||
190 | 191 | | |
191 | 192 | | |
192 | 193 | | |
193 | | - | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
194 | 199 | | |
195 | 200 | | |
196 | 201 | | |
| |||
206 | 211 | | |
207 | 212 | | |
208 | 213 | | |
209 | | - | |
| 214 | + | |
210 | 215 | | |
211 | 216 | | |
212 | 217 | | |
| |||
220 | 225 | | |
221 | 226 | | |
222 | 227 | | |
223 | | - | |
| 228 | + | |
224 | 229 | | |
225 | 230 | | |
226 | 231 | | |
| |||
277 | 282 | | |
278 | 283 | | |
279 | 284 | | |
280 | | - | |
| 285 | + | |
281 | 286 | | |
282 | 287 | | |
283 | 288 | | |
| |||
286 | 291 | | |
287 | 292 | | |
288 | 293 | | |
289 | | - | |
| 294 | + | |
290 | 295 | | |
291 | 296 | | |
292 | 297 | | |
| |||
298 | 303 | | |
299 | 304 | | |
300 | 305 | | |
301 | | - | |
302 | | - | |
303 | | - | |
304 | | - | |
| 306 | + | |
| 307 | + | |
| 308 | + | |
| 309 | + | |
| 310 | + | |
| 311 | + | |
305 | 312 | | |
306 | | - | |
| 313 | + | |
| 314 | + | |
307 | 315 | | |
308 | 316 | | |
309 | 317 | | |
310 | 318 | | |
311 | 319 | | |
| 320 | + | |
| 321 | + | |
312 | 322 | | |
313 | 323 | | |
314 | | - | |
| 324 | + | |
315 | 325 | | |
316 | | - | |
317 | | - | |
318 | 326 | | |
319 | 327 | | |
| 328 | + | |
| 329 | + | |
| 330 | + | |
| 331 | + | |
| 332 | + | |
| 333 | + | |
| 334 | + | |
| 335 | + | |
| 336 | + | |
320 | 337 | | |
321 | 338 | | |
322 | 339 | | |
| |||
326 | 343 | | |
327 | 344 | | |
328 | 345 | | |
329 | | - | |
| 346 | + | |
330 | 347 | | |
331 | 348 | | |
332 | | - | |
333 | | - | |
334 | 349 | | |
335 | 350 | | |
336 | 351 | | |
| |||
400 | 415 | | |
401 | 416 | | |
402 | 417 | | |
403 | | - | |
404 | | - | |
405 | | - | |
406 | | - | |
407 | | - | |
408 | | - | |
| 418 | + | |
| 419 | + | |
| 420 | + | |
| 421 | + | |
409 | 422 | | |
410 | 423 | | |
411 | 424 | | |
| |||
Lines changed: 32 additions & 6 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
52 | 52 | | |
53 | 53 | | |
54 | 54 | | |
55 | | - | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
56 | 60 | | |
57 | 61 | | |
58 | 62 | | |
| |||
288 | 292 | | |
289 | 293 | | |
290 | 294 | | |
291 | | - | |
| 295 | + | |
| 296 | + | |
| 297 | + | |
| 298 | + | |
| 299 | + | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
| 305 | + | |
292 | 306 | | |
293 | 307 | | |
294 | | - | |
| 308 | + | |
295 | 309 | | |
296 | | - | |
| 310 | + | |
| 311 | + | |
| 312 | + | |
297 | 313 | | |
298 | 314 | | |
299 | 315 | | |
300 | | - | |
| 316 | + | |
301 | 317 | | |
302 | 318 | | |
303 | 319 | | |
304 | 320 | | |
305 | | - | |
| 321 | + | |
306 | 322 | | |
307 | 323 | | |
308 | 324 | | |
309 | 325 | | |
| 326 | + | |
| 327 | + | |
| 328 | + | |
| 329 | + | |
| 330 | + | |
| 331 | + | |
| 332 | + | |
| 333 | + | |
| 334 | + | |
| 335 | + | |
310 | 336 | | |
311 | 337 | | |
312 | 338 | | |
| |||
0 commit comments