Skip to content

feat(auth): add the GRIMOIRE service permission - #77

Merged
ExtraToast merged 1 commit into
mainfrom
feat/grimoire-permission
Oct 1, 2026
Merged

ExtraToast merged 1 commit into
mainfrom
feat/grimoire-permission

Conversation

@ExtraToast

Copy link
Copy Markdown
Contributor

Summary

Adds GRIMOIRE for grimoire.jorisjonkers.dev. That route sits behind forward-auth, and this entry is its only per-user gate. Without it, fromHost resolves the host to null and verify() lets every authenticated user through. With it, only ROLE_ADMIN and holders of SERVICE_GRIMOIRE get in.

  • ServicePermission.GRIMOIRE("grimoire")
  • ServicePermissionTest resolves the production and local hostnames.
  • ForwardAuthIntegrationTest adds grimoire to the hosts a USER without grants is denied.

Release

Release auth-api so the deployed enum knows the host before fleet-infra routes grimoire.jorisjonkers.dev. Pairs with the home-portal change that lists GRIMOIRE in the admin permissions editor.

@ExtraToast
ExtraToast merged commit 558cc3d into main Oct 1, 2026
10 checks passed
@ExtraToast
ExtraToast deleted the feat/grimoire-permission branch October 1, 2026 08:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant