Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking β€œSign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Crasm 1061/remove regional admin access to manage orgs #772

Draft
wants to merge 2 commits into
base: develop
Choose a base branch
from
Draft
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions backend/src/xfd_django/xfd_api/api_methods/organization.py
Original file line number Diff line number Diff line change
@@ -37,6 +37,9 @@ def is_valid_uuid(val: str) -> bool:
def list_organizations(current_user):
"""List organizations that the user is a member of or has access to."""
try:
if is_regional_admin(current_user):
raise HTTPException(status_code=401, detail="Unauthorized")

# Check if user is GlobalViewAdmin or has memberships
if not is_global_view_admin(current_user) and not get_org_memberships(
current_user
@@ -985,6 +988,9 @@ def update_org_scan(organization_id: str, scan_id, scan_data, current_user):
def list_organizations_v2(state, regionId, current_user):
"""List organizations that the user is a member of or has access to."""
try:
if is_regional_admin(current_user):
raise HTTPException(status_code=401, detail="Unauthorized")

# Check if user is GlobalViewAdmin or has memberships
if not is_global_view_admin(current_user) and not get_org_memberships(
current_user