node: check policy before visibility

In the `is_authorized` helper, the logic checks the policy and the visibility of
the repository.

If the policy is set to block, the function can return before getting the
repository and the identity document. This improves the check, since the
repository and identity document may be missing if the repository is blocked, so
it would return a different error other than the expected unauthorized error.
This commit is contained in:
Fintan Halpenny 2024-09-04 11:17:33 +01:00 committed by cloudhead
parent 1d57778f6b
commit f244d89e56
No known key found for this signature in database
1 changed files with 6 additions and 1 deletions

View File

@ -280,9 +280,14 @@ impl Worker {
fn is_authorized(&self, remote: NodeId, rid: RepoId) -> Result<(), UploadError> {
let policy = self.policies.seed_policy(&rid)?.policy;
// Check policy first, since if we're blocking then we likely don't have
// the repository.
if policy.is_block() {
return Err(UploadError::Unauthorized(remote, rid));
}
let repo = self.storage.repository(rid)?;
let doc = repo.identity_doc()?;
if !doc.is_visible_to(&remote) || policy.is_block() {
if !doc.is_visible_to(&remote) {
Err(UploadError::Unauthorized(remote, rid))
} else {
Ok(())