Skip to content

fix: Authorize task creation on the project of the resolved status - EXO-90711 - #656

Merged
boubaker merged 1 commit into
feature/maintenancefrom
fix/add-task-authorize-status-project
Oct 5, 2026
Merged

boubaker merged 1 commit into
feature/maintenancefrom
fix/add-task-authorize-status-project

Conversation

@boubaker

Copy link
Copy Markdown
Member

Fix: TaskRestService#addTask authorizes on the project the task is actually stored in. When a status id is posted, the status is loaded through StatusService and the view permission is checked on its own project; an unknown status is a 400. A creation always starts from id 0. Creation with a project and no status id (default status) is unchanged.

Tests: TestTaskRestService#testAddTaskAuthorizesOnTheProjectOfThePostedStatus fails on the previous code; each guard, reverted, fails it.

Knowledge: to follow — the eng-standards pitfall ledger PR that records this surface, opened after its dedup with the parallel backfill; its entry is re-stamped once this fix reaches develop.

This change is classified N1 (computed on 2c33c40a3) — its approver must be an Archi/Dev who knows it is N1, not an approval on AI review alone; author ≠ approver.

🤖 Generated with Claude Code

@boubaker boubaker changed the title fix: Authorize task creation on the project of the resolved status EXO-TBD fix: Authorize task creation on the project of the resolved status - EXO-90711 Sep 28, 2026
@boubaker
boubaker requested a review from ahamdi September 28, 2026 16:31
@boubaker
boubaker marked this pull request as ready for review September 28, 2026 16:31
ahamdi
ahamdi previously approved these changes Sep 29, 2026
@exo-swf
exo-swf dismissed ahamdi’s stale review September 30, 2026 23:18

The merge-base changed after approval.

@exo-swf
exo-swf force-pushed the feature/maintenance branch 2 times, most recently from 5f3a58d to 2a5a860 Compare October 1, 2026 23:18
…EXO-TBD

When a status id is posted, addTask loads the status and checks the
view permission on its own project; an unknown status is a bad request.
A creation always starts from id 0.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@boubaker
boubaker force-pushed the fix/add-task-authorize-status-project branch from 2c33c40 to 10a10ea Compare October 5, 2026 13:02
@boubaker

boubaker commented Oct 5, 2026

Copy link
Copy Markdown
Member Author

Rebased on new feature/maintenance

@boubaker
boubaker requested a review from Jihed525 October 5, 2026 13:03
@sonarqubecloud

sonarqubecloud Bot commented Oct 5, 2026

Copy link
Copy Markdown

@boubaker
boubaker merged commit 2fa5d67 into feature/maintenance Oct 5, 2026
9 checks passed
@boubaker
boubaker deleted the fix/add-task-authorize-status-project branch October 5, 2026 13:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants