fix: repair migration collection names and cross-cutting scoping gaps
Findings from the final whole-branch review. - scopedCollections named "audit" and "channels", but the code writes to audit_logs and notification_channels. On upgrade from single-tenant, legacy audit events and channels would never get org_id, becoming invisible to org-filtered reads while channels silently stopped firing — and the detection loop counted the wrong names, so the 0001 marker could be written having migrated nothing. Names fixed, plus migration 0003 so an incorrectly-migrated instance converges with a fresh one. - EnsureAuthIndexes failure is now fatal. GetUserByEmail is unscoped and the OIDC cross-org guard compares against whichever duplicate Mongo returns first, so users.email uniqueness is a security invariant, and a legacy collection with duplicate emails is the realistic upgrade case. - Evict the per-org OIDC provider cache on save; rotating away from a compromised IdP previously had no effect until restart. - Build the oauth2 config per request instead of mutating a shared cached pointer outside the mutex, which raced on RedirectURL between concurrent logins for the same org. - Stamp org_id on console_sessions, incidents and monitor_rollups, the last collections with no tenant column. 0003 derives their org from the owning server/monitor rather than defaulting, so one org's console history and incident timeline cannot merge into another's. - Seed default steps when an org is created, not only at boot. - Reject an empty session OrgID at the middleware. - Derive the app root label from APP_ROOT_LABEL instead of hardcoding "vantage", which silently disabled the host guard off that domain. - Stop caching negative slug lookups, so a new org's subdomain resolves immediately.
This commit is contained in:
@@ -8,6 +8,7 @@ import (
|
||||
|
||||
type ConsoleSession struct {
|
||||
ID bson.ObjectID `bson:"_id,omitempty" json:"_id,omitempty"`
|
||||
OrgID string `bson:"org_id" json:"org_id"`
|
||||
SessionID string `bson:"session_id" json:"session_id"`
|
||||
ServerID string `bson:"server_id" json:"server_id"`
|
||||
Protocol string `bson:"protocol" json:"protocol"` // ssh | rdp | vnc
|
||||
|
||||
@@ -63,6 +63,7 @@ type Monitor struct {
|
||||
}
|
||||
|
||||
type Incident struct {
|
||||
OrgID string `bson:"org_id" json:"org_id"`
|
||||
IncidentID string `bson:"incident_id" json:"incident_id"`
|
||||
MonitorID string `bson:"monitor_id" json:"monitor_id"`
|
||||
StartedAt time.Time `bson:"started_at" json:"started_at"`
|
||||
@@ -71,6 +72,7 @@ type Incident struct {
|
||||
}
|
||||
|
||||
type Rollup struct {
|
||||
OrgID string `bson:"org_id" json:"org_id"`
|
||||
MonitorID string `bson:"monitor_id" json:"monitor_id"`
|
||||
PeriodStart time.Time `bson:"period_start" json:"period_start"` // hour bucket
|
||||
Checks int `bson:"checks" json:"checks"`
|
||||
|
||||
Reference in New Issue
Block a user