Release 2026.2.7.4 - #896
Merged
Merged
Conversation
…ation
A calibration could be published while its score set was still private, and the calibration READ rule
permitted any non-private calibration without consulting the score set. The variant routes under
/score-calibrations/{urn} check calibration READ only, so an unauthenticated caller holding the URN of
such a calibration received the private score set's variants, including every score and count column.
Any contributor could create and publish one, releasing data before the score set's owner did.
Close both halves. Publishing a calibration now fails with 400 while its score set is private, the
check that had been left commented out since calibrations were introduced. Calibration READ now also
requires READ on the score set, delegated to the score set's own rule, so calibrations already
published this way stop leaking on deploy, and writers that bypass the publish route (an admin move,
the calibration loader scripts) cannot reopen it. Denials are 404, matching the variant routes. This
also withholds a private calibration from its creator once they can no longer read the score set.
/score-calibrations/me returned every calibration a user had created with no permission check, so a
contributor removed from a private score set still received its calibrations' ranges and tmp URN. It
now filters on READ.
Existing rows are left as they are; clearing private and primary on public calibrations of private
score sets is a separate data fix.
Most of the test churn is fixtures that modelled the leaked state: calibrations published on
unpublished score sets, mock score sets with no private attribute, and dump score sets carrying a
published date with private left true.
…alysis-experiment-reuse fix(score-sets): only reuse meta-analysis experiments the caller can add to
…exposed-via-public-calibrations fix(permissions): require score set visibility to read a score calibration
Coverage Report for CI Build 36477423694Warning No base build found for commit Coverage: 88.81%Details
Uncovered ChangesNo uncovered changes found. Coverage RegressionsRequires a base build to compare against. How to fix this → Coverage Stats
💛 - Coveralls |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Features
N/A
Bug Fixes
Maintenance
N/A