fix(iam): policies added to immutably imported role#6090
Merged
mergify[bot] merged 3 commits intomasterfrom Feb 5, 2020
Merged
fix(iam): policies added to immutably imported role#6090mergify[bot] merged 3 commits intomasterfrom
mergify[bot] merged 3 commits intomasterfrom
Conversation
In the refactoring done in #5569, we introduced a bug. The `ImmutableRole` class correctly ignored policies directly added to it, but did not ignore policies added via `Grant.addToPrincipal()`. That's because its `IGrantable#grantPrincipal` field was being used as the principal to grant to, which was pointing to the wrapped role instead of the `ImmutableRole` itself. Fix this oversight and add a test to cement it in. Fixes #5943.
Collaborator
AWS CodeBuild CI Report
Powered by github-codebuild-logs, available on the AWS Serverless Application Repository |
Contributor
|
nice catch! |
NetaNir
approved these changes
Feb 4, 2020
Contributor
|
Thank you for contributing! Your pull request is now being automatically merged. |
Collaborator
AWS CodeBuild CI Report
Powered by github-codebuild-logs, available on the AWS Serverless Application Repository |
Collaborator
AWS CodeBuild CI Report
Powered by github-codebuild-logs, available on the AWS Serverless Application Repository |
Contributor
|
Thank you for contributing! Your pull request is now being automatically merged. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
In the refactoring done in #5569, we introduced a bug. The
ImmutableRoleclass correctly ignored policies directly added to it,but did not ignore policies added via
Grant.addToPrincipal().That's because its
IGrantable#grantPrincipalfield was being usedas the principal to grant to, which was pointing to the wrapped
role instead of the
ImmutableRoleitself.Fix this oversight and add a test to cement it in.
Fixes #5943.
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license