Skip to content

Commit

Permalink
SYN-8647: Don't accept * as a value for syn:user/syn:role (#4122)
Browse files Browse the repository at this point in the history
  • Loading branch information
MichaelSquires authored Feb 11, 2025
1 parent 90a7b3f commit 0b02215
Show file tree
Hide file tree
Showing 3 changed files with 26 additions and 0 deletions.
6 changes: 6 additions & 0 deletions changes/a014806e2981b195a520ad7ff8681b77.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
desc: Fixed a bug where ``syn:user`` and ``syn:role`` types could take a ``*`` and
return a new guid.
prs: []
type: bug
...
8 changes: 8 additions & 0 deletions synapse/models/syn.py
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,10 @@ def _normPyStr(self, text):
if user is not None:
return user.iden, {}

if text == '*':
mesg = f'{self.name} values must be a valid username or a guid.'
raise s_exc.BadTypeValu(mesg=mesg, name=self.name, valu=text)

try:
return s_types.Guid._normPyStr(self, text)
except s_exc.BadTypeValu:
Expand Down Expand Up @@ -55,6 +59,10 @@ def _normPyStr(self, text):
if role is not None:
return role.iden, {}

if text == '*':
mesg = f'{self.name} values must be a valid rolename or a guid.'
raise s_exc.BadTypeValu(mesg=mesg, name=self.name, valu=text)

try:
return s_types.Guid._normPyStr(self, text)
except s_exc.BadTypeValu:
Expand Down
12 changes: 12 additions & 0 deletions synapse/tests/test_model_syn.py
Original file line number Diff line number Diff line change
Expand Up @@ -69,6 +69,12 @@ async def test_syn_userrole(self):
self.eq(exc.exception.get('valu'), 'newp')
self.eq(exc.exception.get('name'), 'syn:user')

with self.raises(s_exc.BadTypeValu) as exc:
await core.callStorm('[ it:exec:query=* :synuser=* ]')
self.isin('syn:user values must be a valid username or a guid.', exc.exception.get('mesg'))
self.eq(exc.exception.get('valu'), '*')
self.eq(exc.exception.get('name'), 'syn:user')

(ok, iden) = await core.callStorm('return($lib.trycast(syn:role, all))')
self.true(ok)
self.eq(iden, core.auth.allrole.iden)
Expand All @@ -86,6 +92,12 @@ async def test_syn_userrole(self):
self.eq(exc.exception.get('valu'), 'newp')
self.eq(exc.exception.get('name'), 'syn:role')

with self.raises(s_exc.BadTypeValu) as exc:
await core.callStorm('$lib.cast(syn:role, *)')
self.eq(exc.exception.get('mesg'), 'syn:role values must be a valid rolename or a guid.')
self.eq(exc.exception.get('valu'), '*')
self.eq(exc.exception.get('name'), 'syn:role')

# coverage for DataModel without a cortex reference
iden = s_common.guid()

Expand Down

0 comments on commit 0b02215

Please sign in to comment.