For anyone but the superuser, erchef refuses to remove the admins group from an object's grant ACE. It answers 403 "Admin group cannot be removed from the Grant ACE" (oc_chef_authz_acl_constraints). To a caller that looks exactly like an ordinary permission 403 (ErrForbidden).
cinc-cli has to guess: it treats a 403 on a revoke of admins from grant as this case, so it doesn't tell the user they lack grant permission. ACLs.Revoke knows what it attempted, so it could say so directly:
- a sentinel such as
ErrAdminsRequiredOnGrant, wrapped alongside ErrForbidden when a revoke touching admins on grant gets a 403, or
- a field on
ACLChangeError recording which constraint the server enforced.
cinc-server-ng doesn't enforce the constraint yet (cinc-project/cinc-server-ng#211), so the unit test needs a cinctest fixture, and the integration case stays a cinc-server-ng gap until that's fixed.
For anyone but the superuser, erchef refuses to remove the
adminsgroup from an object'sgrantACE. It answers 403 "Admin group cannot be removed from the Grant ACE" (oc_chef_authz_acl_constraints). To a caller that looks exactly like an ordinary permission 403 (ErrForbidden).cinc-cli has to guess: it treats a 403 on a revoke of
adminsfromgrantas this case, so it doesn't tell the user they lack grant permission.ACLs.Revokeknows what it attempted, so it could say so directly:ErrAdminsRequiredOnGrant, wrapped alongsideErrForbiddenwhen a revoke touchingadminsongrantgets a 403, orACLChangeErrorrecording which constraint the server enforced.cinc-server-ng doesn't enforce the constraint yet (cinc-project/cinc-server-ng#211), so the unit test needs a cinctest fixture, and the integration case stays a cinc-server-ng gap until that's fixed.