Skip to content

Fix Filesystem resource and token authorization boundaries - #47

Merged
Icemap merged 2 commits into
mainfrom
cheese/fix-fs-auth-boundaries
Aug 19, 2026
Merged

Fix Filesystem resource and token authorization boundaries#47
Icemap merged 2 commits into
mainfrom
cheese/fix-fs-auth-boundaries

Conversation

@Icemap

@Icemap Icemap commented Aug 19, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • require an explicit File System ID and TiDB Cloud API credentials for resource describe/delete operations, so TI_FS_TOKEN cannot authorize resource deletion
  • allow an owner FS token to derive its File System ID for token inventory, enable, disable, and revoke operations while keeping TiDB Cloud credential flows explicit
  • improve command help and errors, add black-box and service-level coverage, and update the read-only Drive9/fs references used for implementation context

Testing

  • make test
  • make e2e

@ti-chi-bot ti-chi-bot Bot added the size/XL label Aug 19, 2026
@Icemap
Icemap merged commit 2b1d788 into main Aug 19, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant