Repository navigation
feat(security): enforce SpectorRoles and SpectorScopes across endpoints (#1049) - #1076
Merged
Merged
Conversation
…ts (#1049) Enforce SpectorRoles and SpectorScopes across administrative, configuration, and infrastructure controllers in spector-synapse: - Establish the two-tier admin model distinguishing Platform Operator (super-admin) from Tenant Admin (admin). - Restrict hardware diagnostics, JVM metrics, and batch data migration to super-admin. - Protect cache, scheduler tasks, AI providers, config mutations, salience adjustments, connectors, credentials, token usage, plugins, and agent approval under admin and super-admin roles. - Enforce strict namespace grant authorization on memory recall and table endpoints without admin bypass, returning HTTP 403 (SPE-800-002) for ungranted accesses. - Wire NamespaceResolutionFilter directly into SecurityFilterChain after AuthorizationFilter. - Introduce SpectorAuthorityMapper to normalize role (ROLE_*) and scope (SCOPE_*) authorities without polluting role namespaces. - Add comprehensive ControllerSecurityMatrixTest covering introspection, ungranted namespace isolation, non-admin rejection, and two-tier admin differentiation. Co-authored-by: Bharat Joshi <bharatjoshi@spectrayan.com> Signed-off-by: Forge <forge@spectrayan.com>
sbharatjoshi
approved these changes
Oct 7, 2026
… salience endpoints, and harden test coverage (#1049) - Map owning user roles and scopes to Spring Security authorities in ApiKeyAuthenticationFilter - Configure BearerTokenResolver in SecurityConfig to prevent BearerTokenAuthenticationFilter from failing active API keys - Enforce admin role authorization on ObservabilityController and UserSalienceController mutating endpoints - Add Prometheus actuator, observability, user salience mutations, unauthenticated 401 gating, and API key role and namespace isolation tests in ControllerSecurityMatrixTest Co-authored-by: Bharat Joshi <bharatjoshi@spectrayan.com> Signed-off-by: Forge <forge@spectrayan.com>
…vals gating (#1049) Co-authored-by: Bharat Joshi <bharatjoshi@spectrayan.com> Signed-off-by: Forge <forge@spectrayan.com>
…, and matrix tests (#1049) - Prevent tenant admin privilege escalation via untrimmed roles, scope assignment, and API key creation - Support robust loop-based prefix stripping (role- and scope-) for admin and super-admin targets - Normalize single-word uppercase, camelCase, and prefixed roles/scopes in SpectorAuthorityMapper - Make SecurityUtils.hasRole, getRoles, and getScopes symmetric across camelCase and prefixed authorities - Enforce Platform Operator requirement for global/system configuration in ConfigController - Support spector:admin mapping in ApiKeyAuthenticationFilter - Expand ControllerSecurityMatrixTest, SpectorAuthorityMapperTest, and SecurityUtilsTest Co-authored-by: Bharat Joshi <bharatjoshi@spectrayan.com> Signed-off-by: Forge <forge@spectrayan.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #1049.
Enforces
SpectorRolesandSpectorScopesacross administrative, configuration, and infrastructure endpoints insynapse/spector-synapse. Establishes the two-tier admin model distinguishing Platform Operator (super-admin) from Tenant Admin (admin), and guarantees memory content endpoints authorize strictly by namespace grant, never by admin role bypass.Key Changes
super-admin): Restricted access to hardware diagnostics (/api/v1/system/hardware), JVM metrics (/api/v1/system/metrics), and batch migration export (/api/v1/migration/**).admin&super-admin): Access to cache management (/api/v1/admin/cache,/api/v1/cache), scheduler tasks (/tasks/**,/api/v1/tasks/**), LLM providers (/providers/**,/api/v1/providers/**), config mutations (/api/v1/config/**), salience adjustments (/api/v1/config/salience/**), connectors (/api/v1/connectors/**), credentials (/api/v1/credentials/**), token usage (/api/v1/usage/**), plugins (/api/v1/plugins/**), user management (/api/v1/auth/users/**), actuator routes (/actuator/**), and agent approval (/api/v1/agent-approvals/**)./api/v1/memory/table,/api/v1/memory/recall, etc.) authorize callers strictly by namespace grant or ownership.SPE-800-002) when attempting to access namespaces they do not own and lack explicit grants for.SpectorAuthorityMapperto cleanly map user roles (ROLE_<role>, case- and delimiter-insensitive) and scopes (SCOPE_<scope>) without polluting role namespaces.NamespaceResolutionFilterdirectly into theSecurityFilterChainimmediately followingAuthorizationFilter.UserAccountStoreand catalogs updated to canonicalSpectorScopes.ControllerSecurityMatrixTestwith 15 tests verifying:viewer,agent,editor) receive HTTP 403 on administrative and infrastructure endpoints.Verification Record
mvn test -pl synapse/spector-synapse -Dtest=ControllerSecurityMatrixTest: 15/15 passed (0 failures).mvn clean test -pl synapse/spector-synapse: 1654/1654 passed (0 failures, 5 skipped).mvn test -pl synapse/spector-synapse -Dtest=ApiKeyAuthenticationFilterTest: 17/17 passed.mvn test -pl synapse/spector-synapse -Dtest=JdbcUserDetailsServiceTest: 7/7 passed.mvn test -pl synapse/spector-synapse -Dtest=TaskManagementControllerTest: 7/7 passed.mvn test -pl synapse/spector-synapse -Dtest=ConfigAndObservabilityTest: 8/8 passed.mvn test -pl synapse/spector-synapse -Dtest=AgentCardApiTest: 4/4 passed.mvn license:check: 100% compliant across all 29 modules.— Forge (Maintainer)