fix: 測定用インデックスに閲覧・投稿グループの既定値を入れる - #1922
Conversation
v2.1.0 からインデックスの閲覧判定はロールに加えてグループの一致も要る (check_groups)。グループに属さない利用者とゲストは "-89"(No Group)として 照合される。fixtures.py は browsing_group / contribute_group を空のまま インデックスを作っていたため、公開インデックスの公開アイテムでも 一般ユーザ・未ログインが遮断され、測定結果が遮断に化けていた。 画面からインデックスを作ったときと同じ既定値(全グループ + "-89")を 入れる。index ステップの時点では測定用グループがまだ無いことがあるので、 グループ作成後の index_acl ステップで入れ直す。 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing |
Reviewer's Guide測定用インデックスの閲覧・投稿グループを、画面作成時と同じ「全グループ + No Group (-89)」に設定し、グループ作成後の index_acl ステップでも再適用することで、v2.1.0 のグループ一致判定による公開アイテムの誤ったアクセス遮断を防ぐ。 Sequence diagram for applying default index groups during fixture creationsequenceDiagram
participant Fixtures
participant Index
participant Group
participant Database
Fixtures->>Index: _index()
Index->>Group: Group.query.all()
Group-->>Index: group IDs
Index->>Database: save browsing_group and contribute_group
Fixtures->>Index: _index_acl()
Index->>Group: Group.query.all()
Group-->>Index: group IDs plus -89
Index->>Database: update existing indexes with default groups
Index->>Database: save ACL-specific group settings
Flow diagram for default index group assignmentflowchart TD
A[index fixture creation] --> B["_default_groups()"]
B --> C[all group IDs plus -89 No Group]
C --> D[set browsing_group and contribute_group]
D --> E[index_acl after group creation]
E --> F[reapply defaults to measurement indexes]
F --> G[v2.1.0 group matching allows public and guest access]
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Hey - I've reviewed your changes and they look great!
Sourcery assessment
Needs a human reviewer. If the default group list is wrong or incomplete, generated indexes could deny browsing or contributing to users and guests because group matching is part of the authorization check. The affected fixture records can be regenerated or their group fields corrected, so reverting the script and rerunning the fixtures repairs the problem.
API インベントリ差分(件数のみ)
ベースラインとの差分(生成されませんでした) 台帳との突き合わせ(生成されませんでした) ソース由来の経路検知(生成されませんでした) |
変更内容
tools/api-inventory/scripts/fixtures.pyのみ。browsing_group/contribute_groupに、画面からインデックスを作ったときと同じ既定値(全グループ +-89(No Group))を入れるindexステップの時点では測定用グループがまだ無いことがあるので、グループ作成後のindex_aclステップで入れ直すNoneから上記に変える(「グループ限定」パターンは従来どおりそのグループだけに上書き)目的
v2.1.0 からインデックスの閲覧判定はロールに加えてグループの一致も要る(
check_groups)。グループに属さない利用者とゲストは-89として照合される。fixtures.pyはグループを空のままインデックスを作っていたため、公開インデックスの公開アイテムでも一般ユーザ・未ログインが遮断され、測定結果が遮断に化けていた。動作確認
PAYLOADテンプレートを実際の引数で展開し、Python として読めることを確認cd tools/api-inventory && python3 -m pytest全件パス🤖 Generated with Claude Code
Summary by Sourcery
Restore the default group access settings for measurement indexes to match indexes created through the UI and prevent public measurements from being incorrectly blocked.
Bug Fixes:
Enhancements: