Skip to content

fix(workspace): scope workspace API tokens to granular resource endpoints and rate-limit independently #1387

Description

@Pcmhacker-hero

Description

Workspace API tokens generated in backend/app/routers/workspace_api_tokens.py are granted full read/write privileges across all workspace resources. There is no scope restriction (e.g. projects:read, milestones:write), and requests authenticated via workspace API tokens share the global user rate limit bucket instead of an isolated token rate limiter.

Steps to Reproduce

  1. Create a workspace token intended only for a CI/CD GitHub Action to post project milestone updates.
  2. Use the token to delete an organization member or modify billing settings.
  3. Request succeeds because token scopes are not enforced per endpoint.

Expected Behavior

  • Backend: Require and validate granular token scopes on all router endpoints using dependency Security(require_scopes(['projects:write'])).
  • Backend: Apply independent per-token rate limiters (e.g., 100 req/min per API token) in middleware/rate_limit.py.

Implementation Hints

Backend (backend/app/routers/workspace_api_tokens.py & backend/app/core/rbac.py):

def require_token_scope(required_scope: str):
    async def dependency(
        token_data: TokenPayload = Depends(get_current_token_payload)
    ):
        if "admin:all" in token_data.scopes:
            return token_data
        if required_scope not in token_data.scopes:
            raise HTTPException(
                status_code=403,
                detail=f"Token missing required scope: {required_scope}"
            )
        return token_data
    return dependency

Affected Files

  • backend/app/routers/workspace_api_tokens.py
  • backend/app/core/rbac.py
  • backend/app/middleware/rate_limit.py

Labels
type:bug, level:advanced, GSSoC-26

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions