Skip to content

fix: CourseLimitedStaffRole should not be able to access studio. - #96

Merged
johanseto merged 1 commit into
open-release/teak.nelpfrom
jlc/bringmore-security
Sep 30, 2026
Merged

johanseto merged 1 commit into
open-release/teak.nelpfrom
jlc/bringmore-security

Conversation

@johanseto

@johanseto johanseto commented Sep 30, 2026 •

Copy link
Copy Markdown

This pull request enhances the handling and testing of the CourseLimitedStaffRole, ensuring that users with this role do not have unintended access to course listings or Studio permissions. It also introduces stricter role checking in course and permission queries. The main changes are grouped below:

We previously fixed this when the CourseLimitedStaffRole was applied to a course but did not handle the case where the role is applied to a user for a whole org. The underlying issue is that the CourseLimitedStaffRole is a subclass of the CourseStaffRole and much of the system assumes that subclesses are for giving more access not less access.

To prevent that from happening for the case of the CourseLimitedStaffRole, when we do CourseStaffRole access checks, we use the strict_role_checking context manager to ensure that we're not accidentally granting the limited_staff role too much access.

(cherry picked from commit ea63816)

Role Access Control Improvements:

  • Added and tested that users with CourseLimitedStaffRole, whether assigned at the course or organization level, cannot list courses in Studio (test_course_limited_staff_course_listing and test_org_limited_staff_course_listing in test_course_listing.py).
  • Added a test to verify that organization-level limited staff have no Studio read or write access in CMS (test_limited_org_staff_no_studio_access_cms in test_authz.py).

Stricter Role Checking:

  • Wrapped course staff queries in strict_role_checking() in course.py and permission checks in auth.py to enforce stricter access control logic. [1] [2]

Test and Import Updates:

  • Added necessary imports for CourseAccessRole and CourseLimitedStaffRole in test files to support new test cases. [1] [2]
  • Imported strict_role_checking where used. [1] [2]

We previously fixed this when the CourseLimitedStaffRole was applied to
a course but did not handle the case where the role is applied to a user
for a whole org.  The underlying issue is that the CourseLimitedStaffRole
is a subclass of the CourseStaffRole and much of the system assumes that
subclesses are for giving more access not less access.

To prevent that from happening for the case of the CourseLimitedStaffRole,
when we do CourseStaffRole access checks, we use the strict_role_checking
context manager to ensure that we're not accidentally granting the
limited_staff role too much access.

(cherry picked from commit ea63816)
@johanseto
johanseto merged commit fa870d0 into open-release/teak.nelp Sep 30, 2026
47 of 48 checks passed
@johanseto
johanseto deployed to open-release/teak.nelp September 30, 2026 23:16 — with GitHub Actions Active
@johanseto
johanseto deployed to open-release/teak.nelp September 30, 2026 23:16 — with GitHub Actions Active
@andrey-canon

Copy link
Copy Markdown

@johanseto did you include this in the doc ?

@johanseto

Copy link
Copy Markdown
Author

@johanseto did you include this in the doc ?

https://github.com/eduNEXT/edunext-nelp-documentation/pull/31

This branch was successfully deployed

1 active deployment
open-release/teak.nelp — 1f0a1a05 Deployed Sep 30, 2026 by johanseto via create-jira-issue / create_jira_issue #30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants