Skip to content

fix(hosts): the node-side resolve switch is super_admin only - #23

Merged
marcoome merged 1 commit into
mainfrom
fix/resolve-switch-role
Sep 21, 2026
Merged

marcoome merged 1 commit into
mainfrom
fix/resolve-switch-role

Conversation

@marcoome

Copy link
Copy Markdown
Contributor

Authorization gap found by an independent review of 1.7.0. Impact and scope are in the CHANGELOG.

Verified: go build, go vet, make check-migrations, all five Compose profiles, go test -race ./... (41 packages).

The switch waives panel-side resolution, and with it the screen that checks
where a backend actually points. It was settable by any account that could
edit a route, so a scope-restricted admin could turn off screening for their
own route. Same bar as skipping upstream TLS verification now.

The policy lives in one function rather than two literal role comparisons, so
the create and edit forms cannot drift apart.
@marcoome
marcoome merged commit 1326da4 into main Sep 21, 2026
2 checks passed
@marcoome
marcoome deleted the fix/resolve-switch-role branch September 21, 2026 11:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant