Repository navigation
docs(spec): job queue domain queues bypass their dedicated endpoint (#37883) - #37906
ihoffmann-dot wants to merge 3 commits into
Conversation
Spec review: requesting changesThe diagnosis is right: five queues accept jobs through 1. Every queue declares its entry point, and the framework enforces itThe generic endpoint was designed as the single entry point: the queue validates itself and the generic endpoint feeds it. The new features (bulk folder operations, bulk upload, maintenance) put validation in an endpoint of their own instead. The spec accepts that split and makes it permanent with an optional mark on Proposal:
The rationale for rejecting
Two reasons do hold. The folder-delete overlap lock and the maintenance cluster singleton must be held while the job is created. The upload ceilings apply while the multipart is being read. Neither fits in a separate 2.
|
fabrizzio-dotCMS
left a comment
There was a problem hiding this comment.
Requesting changes; details in #37906 (comment)
|
Claude finished @ihoffmann-dot's task in 1m 54s —— View job Spec review (PR 1 of 2, spec only)I verified every code reference the spec makes against Code references — all accurate
Review points addressed
Notes for the plan (non-blocking)
The diagnosis and the reworked fix are sound and the spec is internally consistent with the code it cites. The three notes above are clarity items for |
fabrizzio-dotCMS
left a comment
There was a problem hiding this comment.
Thanks, Ivan — the rework covers my review. Approving; one non-blocking correction to fold in before merge:
The maintenance endpoints check admin + portlet, not just the portlet. MaintenanceResource.assertBackendUser requires requireAdmin(true) and requiredPortlet(Portlet.MAINTENANCE) (L1700, L1703), so through the generic endpoint any back-end user, admin or not, can start these jobs. My review understated this too. Please name both checks in the Severity paragraph, and in AC-002/AC-006 make the user a non-admin back-end user without the Maintenance portlet. The fix itself doesn't change.
Nit: in the declarations table, list POST /api/v1/maintenance/assets/_fix and /assets/_clean separately.
On the open question: 👍 to deciding core vs plugin by the Jandex index rather than the package name.
AC-006 reproductionRan the reproduction on unmodified Setup: integration test calling
For maintenance this confirms the privilege escalation: a back-end user without the portlet can create both jobs, which What this does and does not show
The test is not in this PR (it is spec only). It will go into PR 2 together with the fix, registered in a |
|
@fabrizzio-dotCMS heads-up on one scope change from the approved spec. I am moving to another project and the team will continue; the details are in the handover comment on #37883: #37883 (comment) The fix is on branch What I did not implement: the check in Also pending: the short doc for new queues and the ADR proposed in the plan. |
Proposed Changes
specs/37883-job-queue-domain-queues-bypass/spec.md; no code. Implementation follows in PR 2 after this spec is approved.POST /api/v1/jobs/{queueName}(and/upload) skips the validation and authorization of five queues that have a dedicated endpoint:folderBulkDuplicate,folderBulkDelete,assetBulkUpload,maintenanceFixAssets,maintenanceCleanAssets.Validatorper processor cannot carry delete's overlap lock, upload's multipart ceilings or the maintenance permission and cluster lock).@Queueholding the dedicated endpoint's path.403, with a message naming the dedicated endpoint.GET /api/v1/jobs/queueskeeps listing marked queues.Checklist
clean-assets). This comes from reading the code onmainand is not reproduced yet; reviewers should weigh how the team wants to handle it (see the spec's last open question).Additional Info
Open question for reviewers: whether the maintenance finding should follow the security process before this spec is public.
Refs #37883
🤖 Generated with Claude Code