[PR #5482] [management] Move permissions management from managers to API handlers #28022

Open
opened 2026-08-05 07:09:33 -04:00 by saavagebueno · 0 comments
Owner

Original Pull Request: https://github.com/netbirdio/netbird/pull/5482

State: closed
Merged: No


Describe your changes

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (explain why)

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/__

Summary by CodeRabbit

  • Refactor

    • Permission checks centralized into HTTP middleware; backend modules no longer perform inline permission gating and manager wiring simplified.
  • Behavior

    • Handlers now receive resolved user authentication consistently, yielding uniform access control behavior across endpoints.
  • Tests

    • Added integration tests and test fixtures; unit/integration tests updated to exercise the centralized permission wrapper and expanded account scenarios.
**Original Pull Request:** https://github.com/netbirdio/netbird/pull/5482 **State:** closed **Merged:** No --- ## Describe your changes ## Issue ticket number and link ## Stack <!-- branch-stack --> ### Checklist - [ ] Is it a bug fix - [ ] Is a typo/documentation fix - [ ] Is a feature enhancement - [x] It is a refactor - [ ] Created tests that fail without the change (if possible) > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (explain why) ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Permission checks centralized into HTTP middleware; backend modules no longer perform inline permission gating and manager wiring simplified. * **Behavior** * Handlers now receive resolved user authentication consistently, yielding uniform access control behavior across endpoints. * **Tests** * Added integration tests and test fixtures; unit/integration tests updated to exercise the centralized permission wrapper and expanded account scenarios. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
saavagebueno added the pull-request label 2026-08-05 07:09:33 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#28022