Skip to content

Disallow service accounts from team deletion flow - #532

Merged
thokra-nav merged 1 commit into
mainfrom
require_human
Sep 30, 2026
Merged

thokra-nav merged 1 commit into
mainfrom
require_human

Conversation

@thokra-nav

Copy link
Copy Markdown
Contributor

Block service accounts from requesting or confirming team deletion, even when they have the Team owner role. Add authz coverage and integration tests to verify rejected attempts do not create keys, confirm deletions, or write activity log entries. Update deletion docs to clarify the human-user requirement.

Block service accounts from requesting or confirming team deletion,
even when they have the Team owner role. Add authz coverage and
integration tests to verify rejected attempts do not create keys,
confirm deletions, or write activity log entries. Update deletion docs
to clarify the human-user requirement.
@thokra-nav
thokra-nav requested a review from a team as a code owner September 30, 2026 13:31
@thokra-nav
thokra-nav requested a balanced review from Copilot and removed request for a team September 30, 2026 13:34

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The authorization change is focused and covered by unit and integration tests for both deletion operations.

Review effort: Balanced
Findings: None

What changed in this PR

Prevents service accounts from participating in the team deletion flow.

Changes:

  • Rejects service accounts in team deletion authorization.
  • Adds authorization and integration coverage for rejected attempts and side effects.
  • Documents the human-user requirement.
File Description
internal/​auth/​authz/​queries.go Rejects service accounts during deletion authorization.
internal/​auth/​authz/​authz_test.go Tests service-account rejection.
integration_tests/​request_team_deletion.lua Verifies rejected requests have no side effects.
integration_tests/​confirm_team_deletion.lua Verifies rejected confirmations leave deletion pending.
docs/​deleting_teams.md Documents the service-account restriction.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@thokra-nav
thokra-nav merged commit 9eb975f into main Sep 30, 2026
11 checks passed
@thokra-nav
thokra-nav deleted the require_human branch September 30, 2026 13:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants