Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 7 additions & 6 deletions COMPATIBILITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -81,12 +81,13 @@ template configuration retains its explicit `VERSION_2_3_0` compatibility
setting. This dependency update does not change API, database schema, or
template configuration.

Engine `0.183.325` includes `projectTemplate.isPublic` in non-admin v1 API
responses as a read-only field. The admin create and update permission remains
unchanged. Public templates still have no owning `accountId`; their `remove`
action link is omitted for non-admin callers, while private template owners
and admins retain it. Direct update and delete authorization remains enforced
by the existing policy. There is no database migration.
Engine `0.183.326` restores `projectTemplate.isPublic` in non-admin v1 API
responses as a read-only field. In `0.183.325`, v2-beta exposed the field but
the frozen v1 user schema omitted it. The admin create and update permission
remains unchanged. Public templates still have no owning `accountId`; their
`remove` action link is omitted for non-admin callers, while private template
owners and admins retain it. Direct update and delete authorization remains
enforced by the existing policy. There is no database migration.
The `v0.183.324` tag is source-only and has no published release artifact.

## External identity type upgrades
Expand Down
11 changes: 6 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,10 +14,11 @@ preserved upstream boundary.
## Current release

The latest public Engine release is
[`v0.183.325`](https://github.com/PastureStack/orchestration-engine/releases/tag/v0.183.325).
It exposes `projectTemplate.isPublic` to non-admin readers as a read-only field
and omits unavailable remove actions on non-owned templates. See the
[release note](docs/releases/orchestration-engine-0.183.325.md) for behavior,
[`v0.183.326`](https://github.com/PastureStack/orchestration-engine/releases/tag/v0.183.326).
It restores read-only `projectTemplate.isPublic` in both v1 and v2-beta
responses for non-admin readers and omits unavailable remove actions on
non-owned templates. See the
[release note](docs/releases/orchestration-engine-0.183.326.md) for behavior,
tests, and compatibility details. Previous release notes remain in
[`docs/releases`](docs/releases), and the
[GitHub release history](https://github.com/PastureStack/orchestration-engine/releases)
Expand Down Expand Up @@ -45,7 +46,7 @@ bash scripts/check-cattle-jdk25-full-package
After the gate passes, package and check the release artifact:

```sh
ENGINE_VERSION=0.183.325 bash scripts/build --release
ENGINE_VERSION=0.183.326 bash scripts/build --release
bash scripts/check-release-artifact dist/artifacts/cattle.jar
```

Expand Down
2 changes: 1 addition & 1 deletion code/framework/api-pub-sub-jetty/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<groupId>io.cattle</groupId>
<artifactId>cattle-parent</artifactId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../parent/pom.xml</relativePath>
</parent>
<dependencies>
Expand Down
2 changes: 1 addition & 1 deletion code/framework/api-pub-sub/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<groupId>io.cattle</groupId>
<artifactId>cattle-parent</artifactId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../parent/pom.xml</relativePath>
</parent>
<dependencies>
Expand Down
2 changes: 1 addition & 1 deletion code/framework/api/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<artifactId>cattle-parent</artifactId>
<groupId>io.cattle</groupId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../parent/pom.xml</relativePath>
</parent>
<dependencies>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -89,7 +89,9 @@ protected void init() {

protected void copyAccessors(Schema schema) {
SchemaFactory parentSchemaFactory = schemaFactory;
mergeProjectMemberExternalIdTypeOptions(schema, parentSchemaFactory.getSchema(schema.getId()));
Schema coreSchema = parentSchemaFactory.getSchema(schema.getId());
mergeProjectMemberExternalIdTypeOptions(schema, coreSchema);
mergeProjectTemplatePublicReadField(schema, coreSchema);
Class<?> clz = parentSchemaFactory.getSchemaClass(schema.getId());
if (clz == null) {
return;
Expand Down Expand Up @@ -129,6 +131,28 @@ protected void mergeProjectMemberExternalIdTypeOptions(Schema schema, Schema par
((FieldImpl) field).setOptions(new ArrayList<String>(options));
}

protected void mergeProjectTemplatePublicReadField(Schema schema, Schema parentSchema) {
if (parentSchema == null || !"projectTemplate".equals(schema.getId()) ||
schema.getResourceFields().containsKey("isPublic")) {
return;
}

Field parentField = parentSchema.getResourceFields().get("isPublic");
if (!(parentField instanceof FieldImpl)) {
return;
}

// v1 loads frozen .ser schemas. The current user auth overlay grants
// read access, but cannot add a field missing from those snapshots.
// Copy only this public-state field and keep mutation admin-only.
FieldImpl readOnly = new FieldImpl(parentField);
readOnly.setName("isPublic");
readOnly.setCreate(false);
readOnly.setUpdate(false);
readOnly.setReadOnCreateOnly(false);
schema.getResourceFields().put("isPublic", readOnly);
}

public String getFile() {
return file;
}
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,11 @@
package io.cattle.platform.api.schema;

import static org.junit.Assert.assertEquals;
import static org.junit.Assert.assertFalse;
import static org.junit.Assert.assertNotNull;
import static org.junit.Assert.assertNotSame;
import static org.junit.Assert.assertSame;
import static org.junit.Assert.assertTrue;

import io.github.ibuildthecloud.gdapi.factory.SchemaFactory;
import io.github.ibuildthecloud.gdapi.factory.impl.AbstractSchemaFactory;
Expand All @@ -16,6 +20,9 @@
import java.io.InputStream;
import java.io.ObjectOutputStream;
import java.net.URL;
import java.nio.file.Files;
import java.nio.file.Path;
import java.nio.file.Paths;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.Collections;
Expand Down Expand Up @@ -95,6 +102,89 @@ public void enrichesFrozenV1ProjectMemberIdentityTypesFromCoreSchema() throws Ex
.getResourceFields().get("externalIdType").getOptions());
}

@Test
public void exposesFrozenV1ProjectTemplatePublicStateWithoutGrantingWrites() throws Exception {
String resourceName = "schemas/v1-project-template-user.bin";
SchemaImpl frozen = schema("projectTemplate", "projectTemplates");
SchemaImpl core = schema("projectTemplate", "projectTemplates");
FieldImpl coreField = new FieldImpl();
coreField.setName("isPublic");
coreField.setType("boolean");
coreField.setCreate(true);
coreField.setUpdate(true);
core.getResourceFields().put("isPublic", coreField);

Thread.currentThread().setContextClassLoader(new ResourceClassLoader(resourceName,
serialize(Arrays.<Object>asList(frozen))));
FileSchemaFactory factory = factory(resourceName, new SingleSchemaFactory(core));
factory.start();

FieldImpl loaded = (FieldImpl) factory.getSchema("projectTemplate")
.getResourceFields().get("isPublic");
assertNotNull(loaded);
assertNotSame(coreField, loaded);
assertEquals("boolean", loaded.getType());
assertTrue(loaded.isIncludeInList());
assertFalse(loaded.isCreate());
assertFalse(loaded.isUpdate());
assertFalse(loaded.isReadOnCreateOnly());
assertTrue("The current core schema must not be modified", coreField.isCreate());
assertTrue(coreField.isUpdate());
}

@Test
public void preservesExistingFrozenV1AdminProjectTemplatePermissions() throws Exception {
String resourceName = "schemas/v1-project-template-admin.bin";
SchemaImpl frozen = schema("projectTemplate", "projectTemplates");
FieldImpl frozenField = new FieldImpl();
frozenField.setCreate(true);
frozenField.setUpdate(true);
frozen.getResourceFields().put("isPublic", frozenField);
SchemaImpl core = schema("projectTemplate", "projectTemplates");
core.getResourceFields().put("isPublic", new FieldImpl());

Thread.currentThread().setContextClassLoader(new ResourceClassLoader(resourceName,
serialize(Arrays.<Object>asList(frozen))));
FileSchemaFactory factory = factory(resourceName, new SingleSchemaFactory(core));
factory.start();

FieldImpl loaded = (FieldImpl) factory.getSchema("projectTemplate")
.getResourceFields().get("isPublic");
assertTrue(loaded.isCreate());
assertTrue(loaded.isUpdate());
}

@Test
public void repairsThePackagedFrozenV1UserSchemaNotOnlySyntheticFixtures() throws Exception {
String resourceName = "schema/v1/user.ser";
Path current = Paths.get("").toAbsolutePath();
while (current != null && !Files.isRegularFile(
current.resolve("resources/content/").resolve(resourceName))) {
current = current.getParent();
}
assertNotNull("Unable to locate the packaged frozen v1 schema", current);

SchemaImpl core = schema("projectTemplate", "projectTemplates");
FieldImpl coreField = new FieldImpl();
coreField.setName("isPublic");
coreField.setType("boolean");
coreField.setCreate(true);
coreField.setUpdate(true);
core.getResourceFields().put("isPublic", coreField);

Thread.currentThread().setContextClassLoader(new ResourceClassLoader(resourceName,
Files.readAllBytes(current.resolve("resources/content/").resolve(resourceName))));
FileSchemaFactory factory = factory(resourceName, new SingleSchemaFactory(core));
factory.start();

FieldImpl loaded = (FieldImpl) factory.getSchema("projectTemplate")
.getResourceFields().get("isPublic");
assertNotNull(loaded);
assertFalse(loaded.isCreate());
assertFalse(loaded.isUpdate());
assertEquals("boolean", loaded.getType());
}

@Test
public void doesNotWidenOptionsOnUnrelatedFrozenSchemas() throws Exception {
String resourceName = "schemas/v1-account.bin";
Expand Down
2 changes: 1 addition & 1 deletion code/framework/archaius/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<groupId>io.cattle</groupId>
<artifactId>cattle-meta-parent</artifactId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../meta-parent/pom.xml</relativePath>
</parent>
</project>
2 changes: 1 addition & 1 deletion code/framework/async/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<groupId>io.cattle</groupId>
<artifactId>cattle-parent</artifactId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../parent/pom.xml</relativePath>
</parent>
<dependencies>
Expand Down
2 changes: 1 addition & 1 deletion code/framework/auditing/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<artifactId>cattle-parent</artifactId>
<groupId>io.cattle</groupId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../parent/pom.xml</relativePath>
</parent>

Expand Down
2 changes: 1 addition & 1 deletion code/framework/db-loader/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<groupId>io.cattle</groupId>
<artifactId>cattle-parent</artifactId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../parent/pom.xml</relativePath>
</parent>
<dependencies>
Expand Down
2 changes: 1 addition & 1 deletion code/framework/deferred/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<groupId>io.cattle</groupId>
<artifactId>cattle-parent</artifactId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../parent/pom.xml</relativePath>
</parent>
<dependencies>
Expand Down
2 changes: 1 addition & 1 deletion code/framework/encryption/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<groupId>io.cattle</groupId>
<artifactId>cattle-parent</artifactId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../parent/pom.xml</relativePath>
</parent>
<dependencies>
Expand Down
2 changes: 1 addition & 1 deletion code/framework/engine/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<groupId>io.cattle</groupId>
<artifactId>cattle-parent</artifactId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../parent/pom.xml</relativePath>
</parent>
<dependencies>
Expand Down
2 changes: 1 addition & 1 deletion code/framework/eventing/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<groupId>io.cattle</groupId>
<artifactId>cattle-parent</artifactId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../parent/pom.xml</relativePath>
</parent>
<dependencies>
Expand Down
2 changes: 1 addition & 1 deletion code/framework/events/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<groupId>io.cattle</groupId>
<artifactId>cattle-parent</artifactId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../parent/pom.xml</relativePath>
</parent>
<dependencies>
Expand Down
2 changes: 1 addition & 1 deletion code/framework/extension-spring/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<artifactId>cattle-parent</artifactId>
<groupId>io.cattle</groupId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../parent/pom.xml</relativePath>
</parent>
<dependencies>
Expand Down
2 changes: 1 addition & 1 deletion code/framework/extension/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<artifactId>cattle-parent</artifactId>
<groupId>io.cattle</groupId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../parent/pom.xml</relativePath>
</parent>
<dependencies>
Expand Down
2 changes: 1 addition & 1 deletion code/framework/java-server/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<groupId>io.cattle</groupId>
<artifactId>cattle-parent</artifactId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../parent/pom.xml</relativePath>
</parent>
<dependencies>
Expand Down
2 changes: 1 addition & 1 deletion code/framework/jmx/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<groupId>io.cattle</groupId>
<artifactId>cattle-parent</artifactId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../parent/pom.xml</relativePath>
</parent>
<dependencies>
Expand Down
2 changes: 1 addition & 1 deletion code/framework/jooq/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<groupId>io.cattle</groupId>
<artifactId>cattle-parent</artifactId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../parent/pom.xml</relativePath>
</parent>
<dependencies>
Expand Down
2 changes: 1 addition & 1 deletion code/framework/json/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<groupId>io.cattle</groupId>
<artifactId>cattle-parent</artifactId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../parent/pom.xml</relativePath>
</parent>
<dependencies>
Expand Down
2 changes: 1 addition & 1 deletion code/framework/launcher/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<groupId>io.cattle</groupId>
<artifactId>cattle-parent</artifactId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../parent/pom.xml</relativePath>
</parent>
<dependencies>
Expand Down
2 changes: 1 addition & 1 deletion code/framework/lock/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<groupId>io.cattle</groupId>
<artifactId>cattle-parent</artifactId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../parent/pom.xml</relativePath>
</parent>
<dependencies>
Expand Down
2 changes: 1 addition & 1 deletion code/framework/logback/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<groupId>io.cattle</groupId>
<artifactId>cattle-meta-parent</artifactId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../meta-parent/pom.xml</relativePath>
</parent>
<dependencies>
Expand Down
2 changes: 1 addition & 1 deletion code/framework/managed-context/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
<parent>
<groupId>io.cattle</groupId>
<artifactId>cattle-parent</artifactId>
<version>0.183.325</version>
<version>0.183.326</version>
<relativePath>../../parent/pom.xml</relativePath>
</parent>
<dependencies>
Expand Down
Loading
Loading