Enforce tenant access rules at the gateway

FeatureAPIService
Ya
5 Agosti 2026, 06:53 UTC
Mwandishi
Kamo
Ahadi ya
fd0d0f3

This filter has been inert since it was written. resolveOrgId read org:domain:<host> from Redis, nothing ever wrote that key, and the null return fell through to allow; the geo branch was an empty if-block with a comment deferring to SecurityService, which was not enforcing either. Every request passed. It now reads the verdict SecurityService caches and asks that service on a miss, so the policy lives in one place rather than being reimplemented here. Hot path is one Redis read; a miss costs one short-timeout HTTP call per organization and address per 30s. Client address is the right-most public hop of X-Forwarded-For. Proxies append, so the left element is attacker-supplied — reading it would have let a header choose which country the request is judged as coming from. Exempts liveness probes, CORS preflight and the decision endpoint itself, and never judges cluster-internal addresses: service-to-service traffic has no country and blocking it would take the platform down. Fail-open on every path, with a test per dependency. This sits in front of all tenant API traffic, so a filter that blocks when Redis is slow is a total outage. Also drops **************** — template scaffolding from the initial commit, in a package with no @SpringBootConfiguration to find. It has never passed; CI builds with -DskipTests so nothing noticed. Removing it makes 'mvn test' usable here.

Mabadiliko yote

Je, unaona nini kuhusu usafiri?

Kila moja ya hizi updates ardhi katika nafasi yako ya kazi moja kwa moja. Kuanza bure na kuangalia kukua wiki baada ya wiki.

Kuwa Huru MileleMtazamo wa bei