-
Notifications
You must be signed in to change notification settings - Fork 29
Guard tenant context at database access, not at object creation #331
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
11 commits
Select commit
Hold shift + click to select a range
d82bab7
Tenant round-trips through Marshal, JSON, YAML, and MessagePack
flavorjones c5e8079
Guard association tenant context at the query, not at creation
flavorjones 07adbde
Guard `#reload` against cross-tenant access
flavorjones da79b07
Guard `#destroy` and `#delete` against cross-tenant access
flavorjones f79e7c3
Update AR equality methods to respect tenant.
flavorjones ebfe836
Guard `belongs_to` assignment against cross-tenant records
flavorjones bb3c09c
Guard the callback-free write methods against cross-tenant access
flavorjones a84a2a2
Guard `#valid?` against cross-tenant access
flavorjones c4b4e46
ci: add msgpack to appraisal gemfiles
flavorjones 4221335
Keep a `nil` tenant across a serialization round trip
flavorjones a7943fa
doc: Update CHANGELOG.md
flavorjones File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,32 @@ | ||
| # frozen_string_literal: true | ||
|
|
||
| module ActiveRecord | ||
| module Tenanted | ||
| # Tenant context is checked when an association reads or writes the database, and not when the | ||
| # Association object is created. Serializers create associations to dump and restore their | ||
| # targets without ever going near a connection, and must not be tripped up by the check. | ||
| # | ||
| # `klass` is resolved at both of these seams, so a polymorphic association is checked against | ||
| # the class it actually points at rather than being presumed tenanted. | ||
| module Associations # :nodoc: | ||
| # Every query built on behalf of an association funnels through here, including the ones | ||
| # issued by a collection proxy that has outlived the tenant context it was created in. | ||
| def scope | ||
| ensure_owner_tenant_context_safety | ||
| super | ||
|
flavorjones marked this conversation as resolved.
|
||
| end | ||
|
|
||
| private | ||
| # Called by the collection and singular association readers, so that the exception is | ||
| # raised at the call site that made the mistake and not at the eventual query. | ||
| def ensure_klass_exists! | ||
| super | ||
| ensure_owner_tenant_context_safety | ||
| end | ||
|
|
||
| def ensure_owner_tenant_context_safety | ||
| owner.ensure_tenant_context_safety if owner.class.tenanted? && klass&.tenanted? | ||
| end | ||
| end | ||
| end | ||
| end | ||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.