Conversation
Collaborator
🎉 Snyk checks have passed. No issues have been found so far.✅ security/snyk check is complete. No issues have been found. (View Details) |
Contributor
There was a problem hiding this comment.
PR Summary
This PR introduces break-glass bypass functionality for access approval requests, allowing authorized users to bypass normal approval processes in emergency situations.
- Added new
AllowAccessBypasspermission to admin roles with proper enforcement level checks and bypass reason tracking - Implemented email notifications to approvers when requests are bypassed, using
SecretApprovalRequestBypassedTemplate - Added UI components in
ReviewAccessModalfor bypass approval with minimum 10-character reason requirement - Security concern: Ensure bypass functionality is properly restricted through both soft enforcement policy settings and appropriate permissions
- Documentation needs review: Missing
requestTypefield inSecretApprovalRequestBypassedTemplatepreview props could cause TypeScript errors
16 file(s) reviewed, 7 comment(s)
Edit PR Review Bot Settings | Greptile
backend/src/ee/services/access-approval-request/access-approval-request-types.ts
Show resolved
Hide resolved
backend/src/services/smtp/emails/SecretApprovalRequestBypassedTemplate.tsx
Show resolved
Hide resolved
docs/documentation/platform/access-controls/access-requests.mdx
Outdated
Show resolved
Hide resolved
akhilmhdh
requested changes
May 23, 2025
backend/src/ee/services/access-approval-request/access-approval-request-service.ts
Outdated
Show resolved
Hide resolved
backend/src/ee/services/access-approval-request/access-approval-request-service.ts
Outdated
Show resolved
Hide resolved
...ecret-manager/SecretApprovalsPage/components/AccessApprovalRequest/AccessApprovalRequest.tsx
Outdated
Show resolved
Hide resolved
- Review envName from endpoint params and derive it - Use variables in logic blocks - New function on frontend + memoization
akhilmhdh
approved these changes
May 26, 2025
This was referenced Mar 6, 2026
Merged
This was referenced Mar 14, 2026
Merged
This was referenced Mar 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description 📣
Just like Change Requests, Access Requests can now be bypassed in break-glass situations.
Docs changes + new permission added.
Type ✨