fix: 書き込み系APIが require_read のみ(VIEWERでもマスタ変更可能) #38
Labels
No labels
h1-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
joe/o2#38
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
概要
書き込み系(POST/PUT/DELETE)の一部 API が
require_readしか要求しておらず、Role.VIEWERでもマスタの作成・更新・無効化が可能です。P2 マスタ画面の実装でこの操作導線が UI に露出したため、別タスクとして記録します。根拠
src/o2/api/__init__.py:158付近で_auth_deps = [Depends(require_read)]をaccounts_router/write_router/masters_router等に付与しているrequire_writeが個別指定されていないsrc/o2/api/masters.pyのPOST /customers、PUT /customers/{id}、POST /customers/{id}/deactivate、POST /products(write.py)、POST /accounts(accounts.py)getToken()の有無しか見ず、ロールでボタンを出し分けていない影響
対応方針(要検討)
require_writeを付与する(ルーター単位 or ルート単位)。get_current_userのロール判定はPermissionCheckerを使用verify_tenant_ownership)は既存のまま維持受け入れ条件
Role.VIEWERのトークンで書き込み API が 403Role.ACCOUNTANT/ADMINは従来どおり操作可能証拠
src/o2/api/__init__.py:158/src/o2/api/masters.py/src/o2/api/write.py/src/o2/api/accounts.py部分対応完了(UI露出モジュール)
書き込み系 API の権限不足について、Web UI から露出している3モジュールの変更系ルートに
require_writeを付与しました。mainebcfc14にマージ・push 済み。対応
src/o2/api/masters.pysrc/o2/api/write.pysrc/o2/api/accounts.pydependencies=[Depends(require_write)](GET には付与しない)tests/test_write_permissions.py(15件): VIEWER で変更系が 403、ACCOUNTANT で 200/201、VIEWER の GET は 200 のまま、未認証は 401未対応(フォローアップ #39)
_auth_deps = [Depends(require_read)]は他多数のルーターにも付与されており、変更系にrequire_writeが無いモジュールが残っています(sales_orders/purchase_orders/inventory/automation/payroll/tax/bank_reconciliation/ec/fixed_assets等)。全体監査は #39 として起票しました。本 Issue は UI露出分の是正が完了したためクローズします。