gabriel / musehub public
BREAKING fix/auth-security-sweep-2 #1 / 1
gabriel · 171 days ago · Apr 10, 2026 · Diff

security: enforce write-access checks on proposals/releases/webhooks MCP and REST

- execute_merge_proposal: add actor param + _require_write_access guard (owner or write/admin collaborator) - execute_submit_proposal_review: early 403 if reviewer is empty string - execute_create_release: add _require_write_access guard after repo fetch - releases.py REST: add _guard_repo_owner helper; apply to create_release, attach_release_asset, delete_release_asset - webhooks.py REST: add _guard_repo_owner helper; apply to create_webhook, delete_webhook - dispatcher.py: pass actor= to execute_merge_proposal dispatch - test_mcp_write_tools.py: add TestProposalMergeAccessGuard (forbidden for non-owner + unauthenticated) - test_releases.py: add 3 REST 403 tests (non-owner create/attach-asset/delete-asset) - test_musehub_webhooks.py: add 2 REST 403 tests (non-owner create/delete webhook)

sha256:f8e28b9c5c96be5a63290254406fa457e3b55662f1118e0feec1905a0cbcfdc9 sha
+12 ~15 symbols
sha256:7fd16cbef07c20140182dd0cced8a0fe52679a5271b641eee2668f07f80bda95 snapshot
+12
symbols added
~15
symbols modified
0
dead code introduced
Semantic Changes 27 symbols
~ musehub/api/routes/musehub/releases.py .py 1 symbol added, 3 symbols modified
+ _guard_repo_owner function async_function _guard_repo_owner L50–60
~ musehub/api/routes/musehub/webhooks.py .py 1 symbol added, 2 symbols modified
+ _guard_repo_owner function async_function _guard_repo_owner L37–47
~ musehub/mcp/dispatcher.py .py 1 symbol modified
~ musehub/mcp/write_tools/proposals.py .py 1 symbol added, 2 symbols modified
+ _require_write_access import import _require_write_access L9–9
~ musehub/mcp/write_tools/releases.py .py 1 symbol added, 1 symbol modified
+ _require_write_access import import _require_write_access L9–9
~ tests/test_mcp_write_tools.py .py 3 symbols added, 5 symbols modified
+ TestProposalMergeAccessGuard class class TestProposalMergeAccessGuard L396–442
+ test_merge_forbidden_for_non_owner method async_method test_merge_forbidden_for_non_owner L400–420
+ test_merge_forbidden_when_unauthenticated method async_method test_merge_forbidden_when_unauthenticated L423–442
~ tests/test_musehub_webhooks.py .py 2 symbols added
+ test_create_webhook_forbidden_for_non_owner function async_function test_create_webhook_forbidden_for_non_owner L1204–1230
+ test_delete_webhook_forbidden_for_non_owner function async_function test_delete_webhook_forbidden_for_non_owner L1234–1268
~ tests/test_releases.py .py 3 symbols added, 1 symbol modified
+ test_attach_asset_forbidden_for_non_owner method async_method test_attach_asset_forbidden_for_non_owner L1096–1120
+ test_create_release_forbidden_for_non_owner method async_method test_create_release_forbidden_for_non_owner L1074–1093
+ test_delete_asset_forbidden_for_non_owner method async_method test_delete_asset_forbidden_for_non_owner L1123–1153
← Older Oldest on fix/auth-security-sweep-2
All commits
Newer → Latest on fix/auth-security-sweep-2

0 comments

No comments yet. Be the first to start the discussion.

To add a comment, use the Muse CLI: muse hub commit comment sha256:f8e28b9c5c96be5a63290254406fa457e3b55662f1118e0feec1905a0cbcfdc9 --body "your comment"