Skip to content

fix: environment-admin resource pages request globally protected data - #4151

Merged
kmendell merged 1 commit into
mainfrom
fix_environment-admin_resource_pages_request_globally_protected_data
Sep 22, 2026
Merged

kmendell merged 1 commit into
mainfrom
fix_environment-admin_resource_pages_request_globally_protected_data

Conversation

@kmendell

@kmendell kmendell commented Sep 21, 2026 •

Copy link
Copy Markdown
Member

Checklist

  • This PR is not opened from my fork’s main branch
  • All new user-facing strings are translated via Paraglide (m.*())

What This PR Implements

Fixes: #3911

Changes Made

Testing Done

AI Tool Used (if applicable)

Additional Context

Disclaimer Greptiles Reviews use AI, make sure to check over its work.

To better help train Greptile on our codebase, if the comment is useful and valid Like the comment, if its not helpful or invalid Dislike

To have Greptile Re-Review the changes, mention greptileai.

RetriggerConfidence Score: 5/5

The PR appears safe to merge; the changes since the previous review correctly address the outstanding encoder-error handling concern without introducing a new actionable issue.

Summary

This PR prevents environment-scoped administrators from requesting globally protected resources and moves environment-specific display data into authorized resource responses.

  • Gates template, variable, and S3-destination requests using their global permissions.
  • Adds server-resolved container auto-update eligibility to container list and detail responses.
  • Includes the image-upload limit in image-list responses, removing the images page’s dependency on global settings.
  • Separates successful auto-update mutations from subsequent refresh failures.
  • Adds RBAC and update-flow coverage for environment-scoped administrators.

Reviews (3) · Last reviewed commit: "fix: environment-admin resource pages re..."

Copy link
Copy Markdown
Member Author

This stack of pull requests is managed by Graphite. Learn more about stacking.

@arcane-github-automation

arcane-github-automation Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Container images for this PR have been built successfully!

  • Manager: ghcr.io/getarcaneapp/manager:pr-4151
  • Agent: ghcr.io/getarcaneapp/agent:pr-4151

Built from commit 3251e8a

@kmendell
kmendell force-pushed the fix_environment-admin_resource_pages_request_globally_protected_data branch from 1c71ba3 to 13d369c Compare September 22, 2026 00:13
@kmendell
kmendell marked this pull request as ready for review September 22, 2026 00:18
@kmendell
kmendell requested a review from a team September 22, 2026 00:18
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-09-22T00:25:33.240647Z 13d369c Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@graphite-app

graphite-app Bot commented Sep 22, 2026

Copy link
Copy Markdown

Graphite Automations

"Warn authors when publishing large PRs" took an action on this PR • (09/22/26)

1 teammate was notified to this PR based on Kyle Mendell's automation.

Comment thread frontend/src/routes/(app)/images/+page.svelte Outdated
Comment thread frontend/src/routes/(app)/containers/components/ContainerOverview.svelte Outdated
Comment thread backend/internal/container/resource_stats_test.go Outdated
@kmendell
kmendell force-pushed the fix_environment-admin_resource_pages_request_globally_protected_data branch from 13d369c to bb5affb Compare September 22, 2026 01:04
@kmendell
kmendell force-pushed the fix_environment-admin_resource_pages_request_globally_protected_data branch from bb5affb to 3251e8a Compare September 22, 2026 01:10
@kmendell
kmendell merged commit 91825a6 into main Sep 22, 2026
21 of 24 checks passed
@kmendell
kmendell deleted the fix_environment-admin_resource_pages_request_globally_protected_data branch September 22, 2026 01:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

🐞 Bug: Environment only Admin has missing permissions on their environment

1 participant