Skip to content

fix: 測定用インデックスに閲覧・投稿グループの既定値を入れる - #1922

Merged
mhaya merged 1 commit into
develop_v2.1.0from
fix/api-inventory-fixture-no-group
Sep 28, 2026
Merged

mhaya merged 1 commit into
develop_v2.1.0from
fix/api-inventory-fixture-no-group

Conversation

@mhaya

@mhaya mhaya commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

変更内容

tools/api-inventory/scripts/fixtures.py のみ。

  • 測定用インデックスの browsing_group / contribute_group に、画面からインデックスを作ったときと同じ既定値(全グループ + -89(No Group))を入れる
  • index ステップの時点では測定用グループがまだ無いことがあるので、グループ作成後の index_acl ステップで入れ直す
  • アクセス制御パターンの既定値を None から上記に変える(「グループ限定」パターンは従来どおりそのグループだけに上書き)
  • docstring の閲覧判定の説明を v2.1.0 の仕様に合わせる

目的

v2.1.0 からインデックスの閲覧判定はロールに加えてグループの一致も要る(check_groups)。グループに属さない利用者とゲストは -89 として照合される。fixtures.py はグループを空のままインデックスを作っていたため、公開インデックスの公開アイテムでも一般ユーザ・未ログインが遮断され、測定結果が遮断に化けていた。

動作確認

  • PAYLOAD テンプレートを実際の引数で展開し、Python として読めることを確認
  • cd tools/api-inventory && python3 -m pytest 全件パス
  • 実機での再投入・再測定は未実施(実機が起動していないため)

🤖 Generated with Claude Code

Summary by Sourcery

Restore the default group access settings for measurement indexes to match indexes created through the UI and prevent public measurements from being incorrectly blocked.

Bug Fixes:

  • Ensure measurement indexes include the default browsing and contribution groups so public access checks work correctly for regular users and guests.

Enhancements:

  • Align index access-control defaults and documentation with v2.1.0 group-aware access evaluation, including the No Group identifier.

v2.1.0 からインデックスの閲覧判定はロールに加えてグループの一致も要る
(check_groups)。グループに属さない利用者とゲストは "-89"(No Group)として
照合される。fixtures.py は browsing_group / contribute_group を空のまま
インデックスを作っていたため、公開インデックスの公開アイテムでも
一般ユーザ・未ログインが遮断され、測定結果が遮断に化けていた。

画面からインデックスを作ったときと同じ既定値(全グループ + "-89")を
入れる。index ステップの時点では測定用グループがまだ無いことがあるので、
グループ作成後の index_acl ステップで入れ直す。

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing

@sourcery-ai

sourcery-ai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Reviewer's Guide

測定用インデックスの閲覧・投稿グループを、画面作成時と同じ「全グループ + No Group (-89)」に設定し、グループ作成後の index_acl ステップでも再適用することで、v2.1.0 のグループ一致判定による公開アイテムの誤ったアクセス遮断を防ぐ。

Sequence diagram for applying default index groups during fixture creation

sequenceDiagram
    participant Fixtures
    participant Index
    participant Group
    participant Database

    Fixtures->>Index: _index()
    Index->>Group: Group.query.all()
    Group-->>Index: group IDs
    Index->>Database: save browsing_group and contribute_group
    Fixtures->>Index: _index_acl()
    Index->>Group: Group.query.all()
    Group-->>Index: group IDs plus -89
    Index->>Database: update existing indexes with default groups
    Index->>Database: save ACL-specific group settings
Loading

Flow diagram for default index group assignment

flowchart TD
    A[index fixture creation] --> B["_default_groups()"]
    B --> C[all group IDs plus -89 No Group]
    C --> D[set browsing_group and contribute_group]
    D --> E[index_acl after group creation]
    E --> F[reapply defaults to measurement indexes]
    F --> G[v2.1.0 group matching allows public and guest access]
Loading

File-Level Changes

Change Details Files
測定用インデックスの閲覧・投稿グループ既定値を、全グループと No Group の組み合わせに統一する。
  • グループIDを取得して「全グループ + -89」を生成するヘルパーを追加
  • root および子インデックス作成時に閲覧・投稿グループを設定
  • index_acl で測定用グループ作成後の既定値を再設定し、ACL対象インデックスにも適用
  • 「グループ限定」などの個別ACLパターンによる上書きは維持
tools/api-inventory/scripts/fixtures.py
v2.1.0 のグループ一致を含む閲覧判定に合わせて、ACL仕様の説明を更新する。
  • ロールとグループの一致条件、および未所属ユーザ・ゲストの -89 照合をdocstringに反映
  • 測定用グループ作成後に既定値を再投入する理由とタイミングを明記
tools/api-inventory/scripts/fixtures.py

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 25316b84-3d74-4ca3-bce0-4b98afb07ee9

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@mhaya
mhaya merged commit 8887f79 into develop_v2.1.0 Sep 28, 2026
125 of 160 checks passed

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!

Sourcery assessment

Needs a human reviewer. If the default group list is wrong or incomplete, generated indexes could deny browsing or contributing to users and guests because group matching is part of the authorization check. The affected fixture records can be regenerated or their group fields corrected, so reverting the script and rerunning the fixtures repairs the problem.


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

@github-actions

Copy link
Copy Markdown

API インベントリ差分(件数のみ)

台帳ブランチ: develop_v2.1.0

明細は公開できないため件数のみ表示しています。該当箇所はプライベートリポジトリ側の台帳・レポートで確認してください。

ベースラインとの差分

(生成されませんでした)

台帳との突き合わせ

(生成されませんでした)

ソース由来の経路検知

(生成されませんでした)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant