SpiceDB: Checks involving relations with caveats can result in unconditional permission when conditional permission is expected
Under concurrency, CheckPermission and CheckBulkPermissions can return PERMISSIONSHIP_HAS_PERMISSION for a (resource, permission, subject) whose correct answer is PERMISSIONSHIP_CONDITIONAL_PERMISSION.
You are impacted if all of the following hold:
definition user {}
caveat some_caveat(somecondition int) { somecondition == 42 }
definition document {
relation reader: user | user with some_caveat
relation writer: user
relation banned: user
permission has_permission = (reader & writer) - banned
}
document:firstdoc#reader@user:caveatedreader[some_caveat]
document:firstdoc#writer@user:caveatedreader
LookupResources with a context request parameter, concurrently with CheckPermission/CheckBulkPermissions for the same subject/resource, andWhen all of the above are true, there is an intermittent window in which:
CheckPermission(document:firstdoc, has_permission, user:caveatedreader) → HAS_PERMISSION (incorrect; should be CONDITIONAL_PERMISSION)
CheckPermission(document:firstdoc, has_permission, user:caveatedreader, context = {"somecondition": 41}) → HAS_PERMISSION (incorrect; should be NO_PERMISSION)
v1.54.0
Disable the dispatch result cache (ClusterDispatchCacheConfig and DispatchCacheConfig)
为什么是这个 VPI(可解释·实验性)
VPI 计算依据
| 影响度 | 37.00 |
| 利用信号(无额外利用信号) | ×1.00 |
| VPI | 37.00 |
VPI 公式 vpi-v1