Skip to content

feat(security): enforce SpectorRoles and SpectorScopes across endpoints (#1049) - #1076

Merged
sbharatjoshi merged 4 commits into
mainfrom
feat/1049-enforce-spector-roles
Oct 7, 2026
Merged

sbharatjoshi merged 4 commits into
mainfrom
feat/1049-enforce-spector-roles

Conversation

@jarvispectrayan

Copy link
Copy Markdown
Collaborator

Summary

Closes #1049.

Enforces SpectorRoles and SpectorScopes across administrative, configuration, and infrastructure endpoints in synapse/spector-synapse. Establishes the two-tier admin model distinguishing Platform Operator (super-admin) from Tenant Admin (admin), and guarantees memory content endpoints authorize strictly by namespace grant, never by admin role bypass.

Key Changes

  1. Two-Tier Admin Model Enforcement:
    • Platform Operator (super-admin): Restricted access to hardware diagnostics (/api/v1/system/hardware), JVM metrics (/api/v1/system/metrics), and batch migration export (/api/v1/migration/**).
    • Tenant Admin (admin & super-admin): Access to cache management (/api/v1/admin/cache, /api/v1/cache), scheduler tasks (/tasks/**, /api/v1/tasks/**), LLM providers (/providers/**, /api/v1/providers/**), config mutations (/api/v1/config/**), salience adjustments (/api/v1/config/salience/**), connectors (/api/v1/connectors/**), credentials (/api/v1/credentials/**), token usage (/api/v1/usage/**), plugins (/api/v1/plugins/**), user management (/api/v1/auth/users/**), actuator routes (/actuator/**), and agent approval (/api/v1/agent-approvals/**).
  2. Content-Free Admin Isolation:
    • Memory content endpoints (/api/v1/memory/table, /api/v1/memory/recall, etc.) authorize callers strictly by namespace grant or ownership.
    • Admin and super-admin callers receive HTTP 403 Forbidden (SPE-800-002) when attempting to access namespaces they do not own and lack explicit grants for.
  3. Authority Normalization & Mapping:
    • Introduced SpectorAuthorityMapper to cleanly map user roles (ROLE_<role>, case- and delimiter-insensitive) and scopes (SCOPE_<scope>) without polluting role namespaces.
    • Wired NamespaceResolutionFilter directly into the SecurityFilterChain immediately following AuthorizationFilter.
    • Seeded admin accounts in UserAccountStore and catalogs updated to canonical SpectorScopes.
  4. Comprehensive Security Matrix Verification:
    • Added ControllerSecurityMatrixTest with 15 tests verifying:
      • Automatic introspection of administrative and infrastructure controllers ensuring all methods declare explicit security rules.
      • Rejection of admin and super-admin callers accessing ungranted memory namespaces via headers or query parameters.
      • Non-admin callers (viewer, agent, editor) receive HTTP 403 on administrative and infrastructure endpoints.
      • Two-tier admin differentiation between Platform Operator and Tenant Admin endpoints.

Verification Record

  • Test Suite:
    • mvn test -pl synapse/spector-synapse -Dtest=ControllerSecurityMatrixTest: 15/15 passed (0 failures).
    • mvn clean test -pl synapse/spector-synapse: 1654/1654 passed (0 failures, 5 skipped).
    • mvn test -pl synapse/spector-synapse -Dtest=ApiKeyAuthenticationFilterTest: 17/17 passed.
    • mvn test -pl synapse/spector-synapse -Dtest=JdbcUserDetailsServiceTest: 7/7 passed.
    • mvn test -pl synapse/spector-synapse -Dtest=TaskManagementControllerTest: 7/7 passed.
    • mvn test -pl synapse/spector-synapse -Dtest=ConfigAndObservabilityTest: 8/8 passed.
    • mvn test -pl synapse/spector-synapse -Dtest=AgentCardApiTest: 4/4 passed.
  • License Compliance:
    • mvn license:check: 100% compliant across all 29 modules.

— Forge (Maintainer)

…ts (#1049)

Enforce SpectorRoles and SpectorScopes across administrative,
configuration, and infrastructure controllers in spector-synapse:
- Establish the two-tier admin model distinguishing Platform Operator
  (super-admin) from Tenant Admin (admin).
- Restrict hardware diagnostics, JVM metrics, and batch data migration
  to super-admin.
- Protect cache, scheduler tasks, AI providers, config mutations,
  salience adjustments, connectors, credentials, token usage, plugins,
  and agent approval under admin and super-admin roles.
- Enforce strict namespace grant authorization on memory recall and table
  endpoints without admin bypass, returning HTTP 403 (SPE-800-002) for
  ungranted accesses.
- Wire NamespaceResolutionFilter directly into SecurityFilterChain after
  AuthorizationFilter.
- Introduce SpectorAuthorityMapper to normalize role (ROLE_*) and scope
  (SCOPE_*) authorities without polluting role namespaces.
- Add comprehensive ControllerSecurityMatrixTest covering introspection,
  ungranted namespace isolation, non-admin rejection, and two-tier admin
  differentiation.

Co-authored-by: Bharat Joshi <bharatjoshi@spectrayan.com>
Signed-off-by: Forge <forge@spectrayan.com>
@jarvispectrayan
jarvispectrayan requested review from a team as code owners October 6, 2026 23:59
forgespectrayan and others added 3 commits October 6, 2026 19:28
… salience endpoints, and harden test coverage (#1049)

- Map owning user roles and scopes to Spring Security authorities in ApiKeyAuthenticationFilter
- Configure BearerTokenResolver in SecurityConfig to prevent BearerTokenAuthenticationFilter from failing active API keys
- Enforce admin role authorization on ObservabilityController and UserSalienceController mutating endpoints
- Add Prometheus actuator, observability, user salience mutations, unauthenticated 401 gating, and API key role and namespace isolation tests in ControllerSecurityMatrixTest

Co-authored-by: Bharat Joshi <bharatjoshi@spectrayan.com>
Signed-off-by: Forge <forge@spectrayan.com>
…vals gating (#1049)

Co-authored-by: Bharat Joshi <bharatjoshi@spectrayan.com>
Signed-off-by: Forge <forge@spectrayan.com>
…, and matrix tests (#1049)

- Prevent tenant admin privilege escalation via untrimmed roles, scope assignment, and API key creation
- Support robust loop-based prefix stripping (role- and scope-) for admin and super-admin targets
- Normalize single-word uppercase, camelCase, and prefixed roles/scopes in SpectorAuthorityMapper
- Make SecurityUtils.hasRole, getRoles, and getScopes symmetric across camelCase and prefixed authorities
- Enforce Platform Operator requirement for global/system configuration in ConfigController
- Support spector:admin mapping in ApiKeyAuthenticationFilter
- Expand ControllerSecurityMatrixTest, SpectorAuthorityMapperTest, and SecurityUtilsTest

Co-authored-by: Bharat Joshi <bharatjoshi@spectrayan.com>
Signed-off-by: Forge <forge@spectrayan.com>
@sbharatjoshi
sbharatjoshi merged commit bf60787 into main Oct 7, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(security): enforce SpectorRoles/SpectorScopes on admin & infrastructure endpoints

3 participants