Skip to content

fix(server-nestjs): guard system settings upsert behind ManageSystem - #2734

Merged
shikanime merged 3 commits into
mainfrom
fix/settings-guard
Sep 29, 2026
Merged

shikanime merged 3 commits into
mainfrom
fix/settings-guard

Conversation

@shikanime

@shikanime shikanime commented Sep 17, 2026 •

Copy link
Copy Markdown
Member

Issues liées

Refs #2722
Refs #1889


Quel est le comportement actuel ?

POST /api/v1/system/settings est servi par server-nestjs sans garde : ni UserGuard, ni @RequireAdminPermission('ManageSystem'), alors que le router legacy exige AdminAuthorized.ManageSystem. L'écart bloque la bascule nginx-strangler de la route.

Quel est le nouveau comportement ?

Cette PR introduit-elle un breaking change ?

Non pour les clients conformes : les appels légitimes sont faits par un admin authentifié, comme côté legacy. Un appel anonyme recevrait 401 après bascule — comportement voulu (#2722).

Autres informations

Gates : vitest system-settings 3/3 vert, eslint vert sur les deux fichiers.

@shikanime
shikanime marked this pull request as ready for review September 17, 2026 09:08
@shikanime
shikanime requested a review from a team as a code owner September 17, 2026 09:08
@github-actions github-actions Bot added the built label Sep 17, 2026
@shikanime shikanime self-assigned this Sep 17, 2026
@shikanime shikanime added the bug Something isn't working label Sep 17, 2026
@shikanime shikanime modified the milestones: 9.26.0, 9.27.0 Sep 17, 2026
Comment thread apps/server-nestjs/src/modules/system-settings/system-settings.controller.spec.ts Outdated
POST /api/v1/system/settings was served without authentication or
authorization, while the legacy router requires
AdminAuthorized.ManageSystem. The gap blocked the nginx-strangler
cutover of the route (#2722).

- add UserGuard + @RequireAdminPermission('ManageSystem') on upsert,
  mirroring SystemConfigController
- keep GET public (legacy parity)
- lock the guard contract in a controller spec

Refs #2722 #1889

Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr>
Change-Id: I75ca8337943706af3cd577958c5d72db6a6a6964
@shikanime shikanime added the preview Deploy preview app with Argo-cd label Sep 24, 2026
@github-actions

Copy link
Copy Markdown
Contributor

🤖 Hey !

A preview of the application is available at : https://console-pr-2734.dso.cpin-hp.numerique-interieur.fr

Please be patient, deployment may take a few minutes.

shikanime and others added 2 commits September 24, 2026 15:44
UserGuard on the system-settings routes resolves AuthService through the importing module; without AuthModule the backend crashed at boot.

Co-authored-by: Automata <automata@shikanime.studio>
Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr>
…dule

UserGuard resolves UserPermissionService through the importing module as well; the guard crashed at boot with only AuthModule imported.

Co-authored-by: Automata <automata@shikanime.studio>
Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr>
@cloud-pi-native-sonarqube

Copy link
Copy Markdown

@shikanime shikanime removed the preview Deploy preview app with Argo-cd label Sep 28, 2026
@shikanime
shikanime added this pull request to the merge queue Sep 29, 2026
Merged via the queue into main with commit 502a145 Sep 29, 2026
34 checks passed
@shikanime
shikanime deleted the fix/settings-guard branch September 29, 2026 09:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working built

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants