Ignore the test database and record the abstention trap - #241
Merged
Merged
Conversation
The sqlite database created by the documented test setup was untracked and uncovered by .gitignore, so following the setup commands left a binary in the working tree that a staging sweep would commit. Abstention has caused four separate access-control bugs, each recorded separately and each found by accident. They are one rule: what abstention means is decided by the access-decision strategy, not by the voter, and a configuration check in supports() is abstention rather than denial.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #241 +/- ##
=========================================
Coverage 87.81% 87.81%
Complexity 2665 2665
=========================================
Files 258 258
Lines 7730 7730
=========================================
Hits 6788 6788
Misses 942 942
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two pieces of housekeeping, neither touching behaviour.
tests/Functional/app/db.sqlitewas not ignoredIt is created by the test setup this repo documents:
php tests/Functional/app/bin/console -e test doctrine:database:createSo anyone following the README ends up with an untracked binary in their working tree, and a
git add -Acommits it. It has never been committed, which is luck rather than design — it came close twice today, and both times only because workers were told to stage explicitly.Abstention has caused four bugs, and they are one rule
Each was recorded separately as its own war story. They are the same mistake:
RouteVoter::supports()returned false whenroute_securitywas unconfigured, so every voter abstained andAffirmativeStrategy::decide()denied viaallowIfAllAbstainDecisions(defaultfalse) — every routed page 401 for everyone, silently (Feature: Route-level live / scheduled publication date #224)ComponentVoterreturned true when all three sub-votes abstained, so a component in a page nothing routes to was public (Nested child page whose parent has no Route: the parent is invisible to the public (voter chain ignores parentPage/parentPageData) #225)SiteConfigParameterVoter::supports()requires an instance, and a plainsecurity:on aPostruns before denormalization with no object — so every voter abstains and the write is denied, admins included.securityPostDenormalize:is required (Purge rendered HTML when a site-wide resource changes (front-end cache tag, no new endpoint) #232)voteByPageTemplateabstains only when aPagehas no page data at all, which is why a routeless template page was already protected while a routeless plain page leaked its components — the two shapes are not interchangeable in a regression test (Nested child page whose parent has no Route: the parent is invisible to the public (voter chain ignores parentPage/parentPageData) #225)Consolidated into a Working Principles entry, because the pattern is what generalises, not the four instances:
Two of those four bit this week. Recording it as a rule rather than as history is the point.
🤖 Generated with Claude Code