UI: Fix namespace context in capabilities service - #31276
Merged
hellobontempo merged 4 commits intoJul 15, 2025
Merged
Conversation
|
CI Results: |
hellobontempo
commented
Jul 14, 2025
Contributor
Author
There was a problem hiding this comment.
Added comments and policy examples because namespace context can be very confusing - please let me know if anything needs further clarification
hellobontempo
commented
Jul 14, 2025
| if (!payload.namespace) { | ||
| delete payload.namespace; | ||
| } | ||
| const payload = { paths: paths.map((path) => this.relativeNamespacePath(path)) }; |
Contributor
Author
There was a problem hiding this comment.
hellobontempo
commented
Jul 14, 2025
| module('within namespace', function (hooks) { | ||
| module('within a namespace', function (hooks) { | ||
| // capabilities within namespaces are queried at the user's root namespace with a path that includes | ||
| // the relative namespace. The capabilities record is saved at the path without the namespace. |
Contributor
Author
There was a problem hiding this comment.
removed since we're moving away from ember data models
hellobontempo
marked this pull request as ready for review
July 14, 2025 23:24
|
Build Results: |
Contributor
Author
lane-wetmore
approved these changes
Jul 15, 2025
zofskeez
approved these changes
Jul 15, 2025
zofskeez
left a comment
Contributor
There was a problem hiding this comment.
Thanks for catching this and nice work expanding the test coverage! 🎉
hellobontempo
deleted the
VAULT-37697/revert-api-service-capabilities-request-main
branch
July 15, 2025 17:00
9 tasks
9 tasks
Erfankam
pushed a commit
to Erfankam/vault
that referenced
this pull request
Sep 1, 2025
* test coverage for namespace capabilities checks; * set namespace header with appropriate context * add more test coverage, restore stub * add changelog
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Description
When the capabilities service was refactored to use the api service, the namespace was included in the payload instead of used to set the namespace header. This is likely because the ember data capabilities adapter sends
namespacein anoptionsobject, which makes it seem like it's part of the payload.In actuality, the
namespacekey is used to set the namespace header further up in the application adapter via theaddHeadersmethod here.Added test coverage and comments to hopefully mitigate confusion in the future.
TODO only if you're a HashiCorp employee
backport/label that matches the desired release branch. Note that in the CE repo, the latest release branch will look likebackport/x.x.x, but older release branches will bebackport/ent/x.x.x+ent.of a public function, even if that change is in a CE file, double check that
applying the patch for this PR to the ENT repo and running tests doesn't
break any tests. Sometimes ENT only tests rely on public functions in CE
files.
in the PR description, commit message, or branch name.
description. Also, make sure the changelog is in this PR, not in your ENT PR.
PCI review checklist
Examples of changes to security controls include using new access control methods, adding or removing logging pipelines, etc.