Skip to content

Auth: Limit places administration to local - #1888

Open
AiyionPrime wants to merge 2 commits into
labgrid-project:masterfrom
AiyionPrime:feat/auth-local-admin
Open

Auth: Limit places administration to local#1888
AiyionPrime wants to merge 2 commits into
labgrid-project:masterfrom
AiyionPrime:feat/auth-local-admin

Conversation

@AiyionPrime

Copy link
Copy Markdown
Contributor

Description

Checklist

  • Documentation for the feature
  • Tests for the feature
  • The arguments and description in doc/configuration.rst have been updated
  • Add a section on how to use the feature to doc/usage.rst
  • Add a section on how to use the feature to doc/development.rst
  • PR has been tested
  • Man pages have been regenerated

@AiyionPrime
AiyionPrime force-pushed the feat/auth-local-admin branch from 0eb319a to 993699b Compare June 4, 2026 23:18
@AiyionPrime AiyionPrime changed the title Feat/auth local admin Limit places administration to local Jun 4, 2026
@AiyionPrime
AiyionPrime force-pushed the feat/auth-local-admin branch from 993699b to a9c2d91 Compare June 4, 2026 23:20
@AiyionPrime AiyionPrime changed the title Limit places administration to local Auth: Limit places administration to local Jun 5, 2026
@AiyionPrime
AiyionPrime force-pushed the feat/auth-local-admin branch from a9c2d91 to 528369d Compare June 6, 2026 22:09
Signed-off-by: Burfeind, Jan-Niklas <git@aiyionpri.me>
which can be set to LOCAL_ADMIN or left out.

Setting it to LOCAL_ADMIN requires all changes to places to come from
a loopback IP.

This allows a centralized places definition and gives clients
early feedback about an instance ignoring their demands.

Signed-off-by: Burfeind, Jan-Niklas <git@aiyionpri.me>
@AiyionPrime
AiyionPrime force-pushed the feat/auth-local-admin branch from 528369d to 380da7a Compare June 6, 2026 22:10
@AiyionPrime
AiyionPrime marked this pull request as ready for review June 6, 2026 22:11
@codecov

codecov Bot commented Jun 6, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 0% with 33 lines in your changes missing coverage. Please review.
✅ Project coverage is 45.8%. Comparing base (0507604) to head (380da7a).
⚠️ Report is 40 commits behind head on master.
✅ All tests successful. No failed tests found.

Files with missing lines Patch % Lines
labgrid/remote/coordinator.py 0.0% 33 Missing ⚠️
Additional details and impacted files
@@           Coverage Diff            @@
##           master   #1888     +/-   ##
========================================
- Coverage    46.0%   45.8%   -0.2%     
========================================
  Files         180     180             
  Lines       14464   14497     +33     
========================================
  Hits         6654    6654             
- Misses       7810    7843     +33     
Flag Coverage Δ
3.10 45.8% <0.0%> (-0.2%) ⬇️
3.11 45.8% <0.0%> (-0.2%) ⬇️
3.12 45.8% <0.0%> (-0.2%) ⬇️
3.13 45.8% <0.0%> (-0.2%) ⬇️
3.14 45.8% <0.0%> (-0.2%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

@AiyionPrime

Copy link
Copy Markdown
Contributor Author

@Emantor is there a branch I could take for inspiration to get this reviewed?

def auth_required(func):
@wraps(func)
async def decorated(self, request, context):
if environ.get("AUTH") == "LOCAL_ADMIN":

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should really stop adding more and more env variables to configure the exporter and reuse the existing configuration yaml for non-resource configuration as well.

@Emantor I think you mentioned that you had an Idea how that could look like?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For config related to deployment environments I tend to follow https://12factor.net/config

But if you'd rather have this in a config, I'd follow the wish :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants