Skip to content

fix: mgmt API — authorization, delete_permissions, body limits, CORS - #34

Merged
jamesainslie merged 4 commits into
mainfrom
fix-mgmt-api
Mar 30, 2026
Merged

jamesainslie merged 4 commits into
mainfrom
fix-mgmt-api

Conversation

@jamesainslie

Copy link
Copy Markdown
Contributor

Summary

Test plan

  • 12 new tests (authorization rejection, delete_permissions, vhost 404, hash redaction)
  • All workspace tests pass
  • Pre-push CI green

Closes #14, closes #15, closes #22

@github-actions

github-actions Bot commented Mar 30, 2026 •

Copy link
Copy Markdown

Benchmark Results

Metric main PR Delta Status
Publish 4p (msg/s) 62831 62083 -1.2% 🟢
E2E 4p/4c (msg/s) 27713 27512 -0.7% 🟢

🟢 PASSED: No significant regression.

Median of 3 runs. Threshold: -10%.

…#15)

The delete_permissions route handler was a no-op because it modified a
cloned User without writing it back. This adds the missing
remove_permissions method to UserStore so the handler can persist the
change through the store's write lock.
…mprovements (#14, #15, #22)

Authorization (#14):
- Add require_tag helper checking user tags against required roles
- Admin-only: user CRUD, permissions CRUD, definitions import
- Management+Admin: exchange/queue/binding mutations
- Monitoring+Management+Admin: read-only endpoints (overview, list, export)

delete_permissions (#15):
- Wire handler to UserStore::remove_permissions instead of modifying
  a detached clone

Management improvements (#22):
- import_definitions: collect errors, return 207 Multi-Status on partial failure
- Body size limit: 10 MB via DefaultBodyLimit layer
- Password hash redaction: non-admins see empty string in export_definitions
- CORS: add CorsLayer::permissive (was feature-flagged but unused)
- Vhost validation: return 404 for unknown vhost path parameters

Tests: 12 new unit tests covering authorization rejection, delete_permissions
persistence, vhost 404, and password hash redaction.
Added tower (ServiceExt::oneshot) and http-body-util (BodyExt::collect)
as dev-dependencies to support the new unit tests that exercise the
axum router directly without starting an HTTP server.
@jamesainslie
jamesainslie merged commit f15e09b into main Mar 30, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant