Sitelet https://github.com/inventree/InvenTree/pull/12529
Skip to content

[API] Optional field permissions - #12529

Merged
SchrodingersGat merged 13 commits into
inventree:masterfrom
SchrodingersGat:optional-fields
Aug 3, 2026
Merged

SchrodingersGat merged 13 commits into
inventree:masterfrom
SchrodingersGat:optional-fields

Conversation

@SchrodingersGat

Copy link
Copy Markdown
Member

OptionalFields expose cross-model relations without checking that the user has the correct permissions for the related models.

This PR excludes OptionalFields if the user does not have view permission for the associated model

@SchrodingersGat SchrodingersGat added api Relates to the API security Relates to a security issue labels Aug 1, 2026
@netlify

netlify Bot commented Aug 1, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for inventree-web-pui-preview canceled.

Name Link
🔨 Latest commit d92a965
🔍 Latest deploy log https://app.netlify.com/projects/inventree-web-pui-preview/deploys/6a6e90aa0e2a770008d16932

@SchrodingersGat SchrodingersGat added the breaking Indicates a major update or change which breaks compatibility label Aug 1, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens the REST API’s OptionalField mechanism to avoid leaking cross-model “detail” data (nested serializers) when the requesting user lacks view permission for the embedded model, aligning optional output expansion with the permission system.

Changes:

  • Add embedded-model view-permission gating (with per-request caching) to OptionalField inclusion logic.
  • Update and extend API/unit tests to reflect permission-gated optional fields and adjust required test roles.
  • Document the breaking behavior change in the changelog.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
src/backend/InvenTree/InvenTree/serializers.py Enforces view-permission checks for optional fields that embed other models, with caching and exemptions for permission-metadata models.
src/backend/InvenTree/InvenTree/test_serializers.py Adds a unit test verifying permission-gating behavior for an OptionalField which embeds a model.
src/backend/InvenTree/stock/test_api.py Adds a stock API test covering part_detail visibility based on part-view permissions.
src/backend/InvenTree/part/test_api.py Updates roles and expectations/comments to accommodate permission-gated optional embedded fields and query-count impact.
src/backend/InvenTree/order/test_api.py Expands test roles to include view permissions required for newly gated embedded relations.
src/backend/InvenTree/company/test_api.py Adjusts test roles to include additional view permission needed due to embedded-field gating.
CHANGELOG.md Notes the breaking change: related detail fields are removed when the user lacks view permission.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/backend/InvenTree/InvenTree/serializers.py Outdated
Comment thread src/backend/InvenTree/InvenTree/serializers.py Outdated
Comment thread src/backend/InvenTree/stock/test_api.py
@codecov

codecov Bot commented Aug 1, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 86.75%. Comparing base (d024a3f) to head (d92a965).
⚠️ Report is 1 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master   #12529      +/-   ##
==========================================
+ Coverage   86.71%   86.75%   +0.04%     
==========================================
  Files        1445     1445              
  Lines       96288    96340      +52     
  Branches    11229    11229              
==========================================
+ Hits        83498    83583      +85     
+ Misses      12726    12693      -33     
  Partials       64       64              
Flag Coverage Δ
backend 90.75% <100.00%> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

Components Coverage Δ
Backend Apps 92.15% <100.00%> (+<0.01%) ⬆️
Backend General 93.53% <ø> (ø)
Frontend 79.72% <ø> (+0.09%) ⬆️
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@SchrodingersGat
SchrodingersGat marked this pull request as ready for review August 2, 2026 19:47
@SchrodingersGat
SchrodingersGat merged commit 8998d83 into inventree:master Aug 3, 2026
43 checks passed
@SchrodingersGat
SchrodingersGat deleted the optional-fields branch August 3, 2026 19:03
Lowkey-wizard added a commit to EQUA-AI/InvenTree that referenced this pull request Aug 7, 2026
Post-migration deploy verifier for the 2026-08 upstream sync: duplicate
(part, serial) audit mirroring stock/0126's partial-index condition,
pending-migration report, and inventree#12529 role-coverage audit for the AI
service token account and technician groups. Grants are opt-in flags,
idempotent, and never downgrade. Tests pin the token-authenticated
detail-field contract on the stock list - the coverage gap that let the
inventree#12529 narrowing go undetected.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

api Relates to the API breaking Indicates a major update or change which breaks compatibility performance-run security Relates to a security issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants