fix(permissions): require score set visibility to read a score calibration - #895
Merged
bencap merged 1 commit intoSep 28, 2026
Conversation
…ation
A calibration could be published while its score set was still private, and the calibration READ rule
permitted any non-private calibration without consulting the score set. The variant routes under
/score-calibrations/{urn} check calibration READ only, so an unauthenticated caller holding the URN of
such a calibration received the private score set's variants, including every score and count column.
Any contributor could create and publish one, releasing data before the score set's owner did.
Close both halves. Publishing a calibration now fails with 400 while its score set is private, the
check that had been left commented out since calibrations were introduced. Calibration READ now also
requires READ on the score set, delegated to the score set's own rule, so calibrations already
published this way stop leaking on deploy, and writers that bypass the publish route (an admin move,
the calibration loader scripts) cannot reopen it. Denials are 404, matching the variant routes. This
also withholds a private calibration from its creator once they can no longer read the score set.
/score-calibrations/me returned every calibration a user had created with no permission check, so a
contributor removed from a private score set still received its calibrations' ranges and tmp URN. It
now filters on READ.
Existing rows are left as they are; clearing private and primary on public calibrations of private
score sets is a separate data fix.
Most of the test churn is fixtures that modelled the leaked state: calibrations published on
unpublished score sets, mock score sets with no private attribute, and dump score sets carrying a
published date with private left true.
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A score calibration is now readable only by users who can read its score set. Before this change, a published calibration on a private score set exposed that score set's variants through the calibration's variant routes.
READnow also requiresREADon the score set. Denials are 404, matching the variant routes. This protects calibrations that were already published this way, and ones written by paths that skip the publish route./score-calibrations/me: returns only calibrations the user can still read.Existing rows are unchanged. Clearing
private/primaryon public calibrations of private score sets is a separate data fix to run at deploy.Tests
Adds permission, lib, and router tests. Most of the test changes update fixtures that relied on the old behavior, such as calibrations published on unpublished score sets.