mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-10-01 04:21:58 +00:00
fix(modelregistry): address audit findings
Replace try-lock/sleep scheme with blocking locks, add ErrModelNotFound/ ErrModelExists/ErrInvalidModel sentinels, make RegisterModelWithRules atomic, snapshot in IterateModels, guard defaultRegistry access, cap the pointer-unwrap depth, and recover panics in callbacks and reflection. Security hooks now allow-by-default only on ErrModelNotFound. Add tests.
This commit is contained in:
@@ -2,6 +2,7 @@ package security
|
||||
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
"fmt"
|
||||
"reflect"
|
||||
|
||||
@@ -284,7 +285,10 @@ func checkModelUpdateAllowed(secCtx SecurityContext) error {
|
||||
rules, err = modelregistry.GetModelRulesByName(entity)
|
||||
}
|
||||
if err != nil {
|
||||
return nil // model not registered, allow by default
|
||||
if errors.Is(err, modelregistry.ErrModelNotFound) {
|
||||
return nil // model not registered, allow by default
|
||||
}
|
||||
return err
|
||||
}
|
||||
}
|
||||
if !rules.CanUpdate {
|
||||
@@ -308,7 +312,10 @@ func checkModelDeleteAllowed(secCtx SecurityContext) error {
|
||||
rules, err = modelregistry.GetModelRulesByName(entity)
|
||||
}
|
||||
if err != nil {
|
||||
return nil // model not registered, allow by default
|
||||
if errors.Is(err, modelregistry.ErrModelNotFound) {
|
||||
return nil // model not registered, allow by default
|
||||
}
|
||||
return err
|
||||
}
|
||||
}
|
||||
if !rules.CanDelete {
|
||||
|
||||
Reference in New Issue
Block a user