feat(antienum): 403 when sub can read, 404 otherwise
this is a UX improvement, always return a 404 not found when subject do not have any access on the resource
but returns an explicit 403 forbidden is subject try a forbidden action on a resourse it can read
regarding performance, the role is already in cache for the second call with read perm
This commit is contained in:
@@ -234,13 +234,14 @@ jsonpath "$[?(@.subject.id == '{{bob_user_id}}')].resource.type" == "calendar"
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
# Step 8c – Viewer Bob is denied on the unified list endpoint —
|
||||
# `Share` is required, Viewer's bundle excludes it → 404
|
||||
# anti-enum shape (same treatment as any other resource type).
|
||||
# `Share` is required, Viewer's bundle excludes it. Bob has Read
|
||||
# on the calendar → graduated denial returns 403 (see
|
||||
# [[project_authz_require_graduated_denial]]).
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
GET {{base_url}}/api/grants?resource_type=calendar&resource_id={{calendar_id}}
|
||||
Authorization: Bearer {{bob_token}}
|
||||
|
||||
HTTP 404
|
||||
HTTP 403
|
||||
|
||||
|
||||
# ─────────────────────────────────────────────────────────────
|
||||
|
||||
Reference in New Issue
Block a user