Skip to content

Conversation

@nuclearcat
Copy link
Member

Happy new year! :)
Implementing as mentioned in issue, also,
tighten node edit authz and document groups.

Centralize node edit checks (owner, group, runtime, superuser) and reuse them for batch nodeset updates. Lock down user self updates to prevent group escalation and document group management limits and workflows. Add unit tests for authz rules and self-update guard.

Ref: #640

Happy new year! :)
Implementing as mentioned in issue, also,
tighten node edit authz and document groups.

Centralize node edit checks (owner, group, runtime, superuser) and
reuse them for batch nodeset updates. Lock down user self
updates to prevent group escalation and document group management
limits and workflows. Add unit tests for authz rules and
self-update guard.

Ref: kernelci#640

Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
…er privileges

Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
@nuclearcat nuclearcat added this pull request to the merge queue Jan 8, 2026
Merged via the queue into kernelci:main with commit cd08769 Jan 8, 2026
4 checks passed
@nuclearcat nuclearcat deleted the add-finegrained branch January 8, 2026 12:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant