Skip to content

fix(template): register Organization and Team as shared resource consumers#33

Open
cshiels-ie wants to merge 1 commit into
ansible:develfrom
cshiels-ie:fix/core-resource-api-shared-types
Open

fix(template): register Organization and Team as shared resource consumers#33
cshiels-ie wants to merge 1 commit into
ansible:develfrom
cshiels-ie:fix/core-resource-api-shared-types

Conversation

@cshiels-ie

Copy link
Copy Markdown

Summary

  • Flip Organization and Team in templates/core/resource_api.py.jinja from is_provider=True, serializer=None to is_provider=False with OrganizationType/TeamType serializers.

Problem

Services generated by this framework are consumers of org/team data from the AAP gateway, not providers. With is_provider=True, DAB registers them as <service>.organization / <service>.team instead of shared.organization / shared.team. This mismatch breaks gateway JWT auth for role assignments — the gateway exposes the shared variants, so claims validation fails with HTTP 403 for users who have role assignments.

Discovered via the same fix applied to metrics-service in ansible/metrics-service#320.

AI Assistance

This change was developed with assistance from Claude Code (Claude Sonnet 4.6).
All generated code was reviewed, tested, and validated before merging.

…umers

Services built from this framework are consumers of org/team data from
the gateway, not providers. is_provider=True caused them to register as
metrics.organization/team instead of the correct shared.organization/team,
breaking gateway JWT auth for role assignments.

Discovered via ansible/metrics-service#320.

Assisted-by: Claude Code (claude-sonnet-4-6)
Co-Authored-By: Claude Sonnet 4.6 (1M context) <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant