Skip to content

Wikiインポート検証・タスク結果APIにADMIN権限チェックを追加 - #798

Open
NishikawaKoharu wants to merge 2 commits into
RCOSDP:developfrom
NishikawaKoharu:feature/fix-wiki-import-api-permission
Open

NishikawaKoharu wants to merge 2 commits into
RCOSDP:developfrom
NishikawaKoharu:feature/fix-wiki-import-api-permission

Conversation

@NishikawaKoharu

@NishikawaKoharu NishikawaKoharu commented Sep 18, 2026 •

Copy link
Copy Markdown

Purpose

Harden authorization on Wiki import-related APIs so that unauthenticated users and non-admin contributors cannot start import validation or retrieve async task results.

Previously, project_wiki_validate_for_import and project_get_task_result did not require ADMIN permission (and the validate endpoint lacked registration/addon checks aligned with the production import API). This could allow unauthorized callers to obtain a task ID or read Celery task results.

This PR requires ADMIN for both endpoints and aligns decorator checks with the existing import API.

Changes

  • Add @must_have_permission(ADMIN), @must_not_be_registration, and @must_have_addon('wiki', 'node') to project_wiki_validate_for_import
  • Add @must_have_permission(ADMIN) and @must_not_be_registration to project_get_task_result
  • Update existing wiki import tests to pass authenticated admin auth where needed

Review follow-ups:

  • Bind Wiki import/validate task_id to the node via WikiImportTask when starting the task
  • Reject project_get_task_result with 404 unless the task_id belongs to the requested node (prevents reading other projects' Wiki results or unrelated Celery results such as WEKO deposit)
  • Record validate tasks as Completed + process_end so they do not affect importing UI / abort / concurrent-import checks
  • Bind import tasks as Running before returning taskId to avoid a race with polling
  • Add tests for same-node success and cross-node / unknown task_id rejection

QA Notes

  • Does this change require a data migration? No
  • Risk level: Medium (permissions code touched; additive authorization checks)
  • How to verify (API, unauthenticated):
    • GET /api/v1/project/<pid>/wiki/import/<dir_id>/validate/ → expect 401
    • GET /api/v1/project/<pid>/wiki/get_task_result/<task_id>/ → expect 401
    • POST /api/v1/project/<pid>/wiki/import/<dir_id>/ → expect 401 (unchanged baseline)
    • With project ADMIN auth, validate/import flows should still work as before
  • Impacted features: Wiki import (validate / task result / import)
  • Performance impact: None expected

Documentation

No documentation updates required.

Side Effects

Unauthenticated or non-ADMIN callers can no longer start validation or poll task results. ADMIN users are unaffected aside from the intended permission enforcement.

Ticket

https://redmine.devops.rcos.nii.ac.jp/issues/62776
https://redmine.devops.rcos.nii.ac.jp/issues/62777

@yacchin1205 yacchin1205 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Redmine 62777 にコメントしました。ご確認ください。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants