Commit 171819a
authored
fix: let the ReadBalances view read an account, which the balances endpoints need it to (#82)
SYSTEM_READ_BALANCES_VIEW_PERMISSION was {can_see_bank_account_balance,
can_query_available_funds} -- the honest set for a view whose whole job is
balances, and one the UK balances endpoints cannot use:
GET /open-banking/v4.0.1/aisp/accounts/{id}/balances
400 OBP-20022: View does not permit the access. You need the
`can_see_transaction_this_bank_account` permission on the view(ReadBalances)
ViewExtended.moderateAccountCore gates the whole ModeratedBankAccount on that one
permission, whatever field the caller wants, and both balances endpoints (v3.1 and
v4.0.1) reach the account through moderatedBankAccountCore. So the view is added to
the set, with a comment saying why a transaction-named permission is in a balances
view and pointing at the gate as the thing that actually wants fixing (issue #81).
Measured rather than assumed: a matrix of every UK and Berlin Group view against
every endpoint that reads through it found 2 broken combinations out of 12, both
the UK balances endpoint. Berlin Group balances was unaffected -- it does not
moderate. So exactly one set changes.
Not caused by the reconciliation that shipped in #80, and not confined to upgraded
installations: a fresh install creates ReadBalances from this same constant, so the
endpoint was already broken there. #80 extended that to upgraded installs by making
the code-defined set apply. Both are fixed by fixing the set.
Three checks covered this area and none could catch it, which is the part worth
fixing beyond the one-line set:
- MappedViewsTest asserted each view's allowed_actions equals the constant that
defines it -- the constant compared with itself, true whatever it says;
- the in-repo UK balances test asserts only 401 and 403, so it never reads a
balance and never reaches the gate;
- the probe matrix ran against a database whose ReadBalances still carried the
pre-existing 74-permission generic set, so the code-defined set was exercised
nowhere.
So MappedViewsTest gains a scenario that calls the gate: for the view the balances
endpoints moderate through, assert moderateAccountCore succeeds. Scoped to that one
view because grepping the callers of moderatedBankAccountCore shows nothing else
moderates an account; the other UK/BG views cannot either, which is latent rather
than broken and is recorded in the test rather than asserted.
Two existing assertions were weakened and say so at the site. "Balances must not
carry transaction- or counterparty-visibility permissions" was an exact-set
equality; it is now: must contain balance and available funds, must not contain
transaction amount/type/dates, must contain nothing about the other party, and the
transaction-named permissions it holds must be exactly the one gate. Rewriting it to
equal whatever the constant contains would have discarded the property it exists for.
MappedViewsTest 8/8, full local suite 3383/0. Against a running instance: the
view/endpoint matrix is 12/12 (was 10/12), the probe matrix 105/0 (was 105/2), and
the token-path, stale-revoke and direction probes re-run green after the permission
set changed.1 parent ea64d62 commit 171819a
2 files changed
Lines changed: 88 additions & 6 deletions
File tree
- obp-api/src
- main/scala/code/api/constant
- test/scala/code/views
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
666 | 666 | | |
667 | 667 | | |
668 | 668 | | |
| 669 | + | |
| 670 | + | |
| 671 | + | |
| 672 | + | |
| 673 | + | |
| 674 | + | |
| 675 | + | |
| 676 | + | |
| 677 | + | |
| 678 | + | |
669 | 679 | | |
670 | 680 | | |
671 | | - | |
| 681 | + | |
| 682 | + | |
672 | 683 | | |
673 | 684 | | |
674 | 685 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
| 5 | + | |
5 | 6 | | |
6 | 7 | | |
7 | | - | |
| 8 | + | |
8 | 9 | | |
9 | 10 | | |
10 | 11 | | |
| |||
125 | 126 | | |
126 | 127 | | |
127 | 128 | | |
128 | | - | |
129 | | - | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
130 | 150 | | |
131 | 151 | | |
132 | 152 | | |
| |||
180 | 200 | | |
181 | 201 | | |
182 | 202 | | |
183 | | - | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
184 | 206 | | |
185 | | - | |
| 207 | + | |
| 208 | + | |
186 | 209 | | |
187 | 210 | | |
188 | 211 | | |
| |||
204 | 227 | | |
205 | 228 | | |
206 | 229 | | |
| 230 | + | |
| 231 | + | |
| 232 | + | |
| 233 | + | |
| 234 | + | |
| 235 | + | |
| 236 | + | |
| 237 | + | |
| 238 | + | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
| 245 | + | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
| 260 | + | |
| 261 | + | |
| 262 | + | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
207 | 278 | | |
208 | 279 | | |
209 | 280 | | |
| |||
0 commit comments