Skip to content

Keep user flags in migration 0268 when an installed app manages the role tables - #16103

Merged
Maffooch merged 1 commit into
DefectDojo:bugfixfrom
devGregA:fix/0268-flags-when-roles-kept
Sep 28, 2026
Merged

Maffooch merged 1 commit into
DefectDojo:bugfixfrom
devGregA:fix/0268-flags-when-roles-kept

Conversation

@devGregA

Copy link
Copy Markdown
Contributor

Description

Migration 0268_release_authorization_to_pro backfills the legacy authorized_users relations from the role tables, and derives user flags from global roles, for installs that move to the authorized_users model.

When an installed app other than dojo still manages the role tables, the global roles keep applying on that install, so there is nothing to translate them into. In that case the migration now leaves the user flags as they are. It reads this from the app registry: a managed model outside dojo whose table is dojo_global_role. The authorized_users backfill is unchanged. Installs where nothing else manages those tables run the migration exactly as before.

Test results

  • Added unittests/test_release_authorization_backfill.py. It runs the backfill against the migration state just before its RunPython step, once with the role tables released (a global Owner and a global Writer get their flags, as before) and once with an installed app keeping them (the flags are unchanged). Both pass locally.
  • ruff check (0.16.5, repo config) passes on the changed files.

Documentation

No documentation change needed.

🤖 Generated with Claude Code

…anaged

The 0268 backfill translates global roles into is_superuser / is_staff
for installs that move to the authorized_users model. When an installed
app still manages the role tables, the roles keep applying there, so the
translation is skipped and the flags stay as they were. Open source
only installs are unaffected: nothing else manages those tables, and the
backfill runs as before.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@devGregA devGregA added this to the 3.3.300 milestone Sep 27, 2026
@github-actions github-actions Bot added New Migration Adding a new migration file. Take care when merging. unittests labels Sep 27, 2026
@dryrunsecurity

Copy link
Copy Markdown

DryRun Security

This pull request modifies a sensitive database migration file that was changed by an author not included in the allowed list. Although the severity is low and the finding is non-blocking, it indicates a potential policy violation regarding code ownership.

Configured Sensitive Codepath Modified by Non-Allowed Author in dojo/db_migrations/0268_release_authorization_to_pro.py (drs_79b44779)
Vulnerability Configured Sensitive Codepath Modified by Non-Allowed Author
Description File 'dojo/db_migrations/0268_release_authorization_to_pro.py' matches configured sensitive codepath pattern 'dojo/db_migrations/*.py' and was modified by '' (commit 400ec6d) who is not in the allowed authors list.

Comment to provide feedback on these findings.

Report false positive: @dryrunsecurity fp [FINDING ID] [FEEDBACK]
Report low-impact: @dryrunsecurity nit [FINDING ID] [FEEDBACK]

Example: @dryrunsecurity fp drs_90eda195 This code is not user-facing

All finding details can be found in the DryRun Security Dashboard.

@Maffooch
Maffooch added this pull request to the merge queue Sep 28, 2026
Merged via the queue into DefectDojo:bugfix with commit 97068db Sep 28, 2026
47 checks passed
@Maffooch
Maffooch deleted the fix/0268-flags-when-roles-kept branch September 28, 2026 01:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

New Migration Adding a new migration file. Take care when merging. unittests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants