fleetd #650: scope the READ-unreachable javadoc to loopback-trust #652

Closed
agent wants to merge 0 commits from worker/650-javadoc-scope-95f3b3-14 into main
Member

FleetdAssemblyFleetAppTest's class javadoc claimed that GET /sessions' Authz.Action.READ gate is ALWAYS refused because READ needs Caller.resolved(). That is only true under auth.mode: loopback-trust, which is the mode this test runs under by default (it configures no auth: block). Under auth.mode: token, CallerResolver.resolve() returns before ever consulting Caller.resolved()/scanComplete(), so a valid bearer token resolves to Role.PRIMARY with no pid lookup on that path at all.

This PR scopes the claim to loopback-trust and names the escape hatch, citing FleetdQuarantineOutageDualWindowAssemblyTest and FleetdListReportingSourcesAssemblyTest as the two merged tests that already exercise Authz.Action.READ over a real token-authenticated request against a real FleetdAssembly#assembleAndStart.

Javadoc-only change; no production or test behavior changed.

Ref fleetd #650.

Tests run:

  • mvn -o test -Dtest=FleetdAssemblyFleetAppTest -> Tests run: 3, Failures: 0, Errors: 0, Skipped: 0, BUILD SUCCESS
  • mvn -o clean install -> Tests run: 1903, Failures: 0, Errors: 0, Skipped: 0, BUILD SUCCESS
FleetdAssemblyFleetAppTest's class javadoc claimed that GET /sessions' Authz.Action.READ gate is ALWAYS refused because READ needs Caller.resolved(). That is only true under auth.mode: loopback-trust, which is the mode this test runs under by default (it configures no auth: block). Under auth.mode: token, CallerResolver.resolve() returns before ever consulting Caller.resolved()/scanComplete(), so a valid bearer token resolves to Role.PRIMARY with no pid lookup on that path at all. This PR scopes the claim to loopback-trust and names the escape hatch, citing FleetdQuarantineOutageDualWindowAssemblyTest and FleetdListReportingSourcesAssemblyTest as the two merged tests that already exercise Authz.Action.READ over a real token-authenticated request against a real FleetdAssembly#assembleAndStart. Javadoc-only change; no production or test behavior changed. Ref fleetd #650. Tests run: - mvn -o test -Dtest=FleetdAssemblyFleetAppTest -> Tests run: 3, Failures: 0, Errors: 0, Skipped: 0, BUILD SUCCESS - mvn -o clean install -> Tests run: 1903, Failures: 0, Errors: 0, Skipped: 0, BUILD SUCCESS
agent added 1 commit 2026-10-03 15:41:11 +02:00
fleetd #650: scope the READ-unreachable javadoc to loopback-trust
CI / shell-tests (pull_request) Failing after 9s
CI / build (pull_request) Failing after 2m25s
CI / contract (pull_request) Successful in 2m34s
e69eafcc9f
FleetdAssemblyFleetAppTest's class javadoc stated that /sessions'
Authz.Action.READ gate is always refused, and that READ always needs
Caller.resolved(). That is true only under auth.mode: loopback-trust,
the mode this test runs under because it configures no auth: block.
Under auth.mode: token, CallerResolver.resolve() returns before ever
consulting Caller.resolved()/scanComplete(), so a valid bearer token
resolves to PRIMARY with no pid lookup on that path. Names the two
tests that already exercise that path against a real assembly.
ltms closed this pull request 2026-10-03 15:51:19 +02:00
Some checks are pending
CI / shell-tests (pull_request) Failing after 9s
CI / build (pull_request) Failing after 2m25s
CI / contract (pull_request) Successful in 2m34s

Pull request closed

Sign in to join this conversation.