feat(security): add staging-phase tester allowlist for admin pathways#646
Open
AliceTenni wants to merge 1 commit into
Open
feat(security): add staging-phase tester allowlist for admin pathways#646AliceTenni wants to merge 1 commit into
AliceTenni wants to merge 1 commit into
Conversation
Exposes advanced administrative operations on public test networks before full audit completion poses unmitigated configuration security risks. This change adds a conditional access layer that restricts execution of admin write pathways to an explicit tester allowlist whenever staging mode is active. Changes: - src/staging.rs (new): StagingConfig struct, set_staging_mode, add_tester, remove_tester, is_staging_active, get_staging_config, and check_staging_access — the core gate function. Includes unit tests covering all allowlist lifecycle scenarios. - src/lib.rs: add StagingNotAuthorized (error code 37), STAGING_KEY constant, pub mod staging declaration, and wire check_staging_access into propose_upgrade, execute_upgrade, cancel_upgrade, set_value, set_heartbeat_interval, and upsert_node_profile. Expose staging management as public contract functions (set_staging_mode, add_staging_tester, remove_staging_tester, is_staging_active, get_staging_config). - src/admin.rs: wire check_staging_access into propose_admin_change and propose_ownership_transfer. - src/test.rs: add 7 integration tests covering: staging off (no-op), management restricted to admin, unauthorized callers blocked on all pathways, authorized testers clearing the gate, admin always passing, disabling staging unblocking callers, and add/remove lifecycle. Access decision table: staging off -> pass (no-op, existing rules apply) staging on + is admin -> pass staging on + in list -> pass staging on + neither -> StagingNotAuthorized The check fires before the NotAdmin guard so unauthorized callers are rejected at the earliest possible point without leaking information through downstream error differences.
|
@AliceTenni Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
closes #290
Exposes advanced administrative operations on public test networks before full audit completion poses unmitigated configuration security risks. This change adds a conditional access layer that restricts execution of admin write pathways to an explicit tester allowlist whenever staging mode is active.
Changes:
Access decision table:
staging off -> pass (no-op, existing rules apply)
staging on + is admin -> pass
staging on + in list -> pass
staging on + neither -> StagingNotAuthorized
The check fires before the NotAdmin guard so unauthorized callers are rejected at the earliest possible point without leaking information through downstream error differences.