fix(ui): show all teams in policy attachment form for admins (#33628)

The policy attachment form fetched /team/list with the caller's own
user_id, which the backend treats as a membership filter even for proxy
admins. Admins only saw teams they were personally a member of, and the
scope validation added in #32131 then rejected every other valid team
alias as nonexistent. Drop the user_id filter; the policies page is
admin-only and /team/list without user_id returns all teams for admin
roles.

Fixes LIT-4199
This commit is contained in:
ryan-crabbe-berri 2026-07-16 19:22:04 -07:00 • committed by GitHub
parent ecef9e6c9b
commit 07656cf80b
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 11 additions and 1 deletions

View file

@ -18,6 +18,10 @@ vi.mock("./impact_preview_alert", () => ({
React.createElement("div", { "data-testid": "impact-preview" }, `${impactResult.affected_keys_count} keys`),
}));
vi.mock("@/app/(dashboard)/hooks/useAuthorized", () => ({
default: () => ({ userId: "admin-user-id", userRole: "Admin", accessToken: "test-token" }),
}));
const makePolicy = (overrides: Partial<Policy> = {}): Policy => ({
policy_id: "policy-id-1",
policy_name: "test-policy",
@ -71,6 +75,12 @@ describe("AddAttachmentForm", () => {
});
});
it("fetches all teams, not just teams the caller is a member of (LIT-4199)", async () => {
renderWithProviders(<AddAttachmentForm {...defaultProps} />);
await waitFor(() => expect(networking.teamListCall).toHaveBeenCalled());
expect(networking.teamListCall).toHaveBeenCalledWith("test-token", null, null);
});
it("should not fetch teams, keys, or models when accessToken is null", () => {
renderWithProviders(<AddAttachmentForm {...defaultProps} accessToken={null} />);
expect(networking.teamListCall).not.toHaveBeenCalled();

View file

@ -56,7 +56,7 @@ const AddAttachmentForm: React.FC<AddAttachmentFormProps> = ({
setIsLoadingTeams(true);
setTeamsLoaded(false);
try {
const teamsResponse = await teamListCall(accessToken, null, userId);
const teamsResponse = await teamListCall(accessToken, null, null);
const teamsArray = Array.isArray(teamsResponse) ? teamsResponse : teamsResponse?.data || [];
const teamAliases = teamsArray.map((t: any) => t.team_alias).filter(Boolean);
setAvailableTeams(teamAliases);