Skip to content

feat(authz): add authorization error codes - #13213

Draft
sk593 wants to merge 4 commits into
sk593-authz-modes-foundationfrom
sk593-authz-error-codes
Draft

sk593 wants to merge 4 commits into
sk593-authz-modes-foundationfrom
sk593-authz-error-codes

Conversation

@sk593

@sk593 sk593 commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Layer 2 of 5 in the Stack 0 foundation stack for #13086, stacked on #13212 (sk593-authz-modes-foundation). Adds authorization error codes, HTTP status mappings, and ARM response conversion. Nothing is wired into a request path.

Public denial messages include the requested action and target but omit internal diagnostic reasons. ErrorResponse() returns (v1.ErrorResponse, error) and Response() returns (rest.Response, error); both fail explicitly when action or target is blank.

Reason for change

Implements the error-code foundation from design #13086. Reuses InvalidAuthenticationInfo and maps codes to 401/403/409/503, with unknown codes returning 500. An empty denial code defaults to AuthorizationFailed.

The handshake codes PeerCertificateInvalid and CertificateExpired live in pkg/authz, not ARM error codes, because failed handshakes have no HTTP response. They are for logs/metrics only; accidental HTTP status lookup returns 500.

How to test

Unit-test only; no manual verification needed. Tests were committed before implementation, including regression tests for private reasons and missing request context.

  • go test ./pkg/authz/... ./pkg/armrpc/api/v1/... — passed.
  • golangci-lint run ./pkg/authz/... ./pkg/armrpc/api/v1/... — passed, 0 issues using repository-pinned v2.14.0 installed in session storage. The global binary was incompatible with the repository's Go version.

Tests cover every code-to-status mapping, ARM response serialization, suppression of a private identity and unrelated resource ID contained in diagnostic reasons, and errors for missing or whitespace-only action/target values.

File change summary

File Summary of change
pkg/armrpc/api/v1/errorcodes.go Add nine authorization error codes with documented meanings and statuses.
pkg/authz/decision.go Carry requested action/target through denials; alias the default code to the ARM constant; document diagnostics as internal.
pkg/authz/errors.go Add log-only handshake codes, status mapping, and ARM/rest conversion with private reasons excluded and required context validated.
pkg/authz/errors_test.go Cover mappings, serialization, context propagation, privacy, and invalid-context errors.
pkg/authz/doc.go Document the response-conversion contract.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Unit Tests

    2 files  ± 0    461 suites  ±0   15m 31s ⏱️ +2s
7 340 tests +30  7 338 ✅ +30  2 💤 ±0  0 ❌ ±0 
8 819 runs  +30  8 817 ✅ +30  2 💤 ±0  0 ❌ ±0 

Results for commit e580d4b. ± Comparison against base commit 12cfd85.

♻️ This comment has been updated with latest results.

@codecov

codecov Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 93.93939% with 2 lines in your changes missing coverage. Please review.
✅ Project coverage is 60.48%. Comparing base (12cfd85) to head (e580d4b).

Files with missing lines Patch % Lines
pkg/authz/errors.go 93.75% 2 Missing ⚠️
Additional details and impacted files
@@                       Coverage Diff                        @@
##           sk593-authz-modes-foundation   #13213      +/-   ##
================================================================
+ Coverage                         60.46%   60.48%   +0.02%     
================================================================
  Files                               776      777       +1     
  Lines                             45715    45747      +32     
================================================================
+ Hits                              27641    27670      +29     
- Misses                            18074    18077       +3     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@sk593
sk593 force-pushed the sk593-authz-error-codes branch from 6694a8e to 0d81c5e Compare October 6, 2026 20:14
@github-actions github-actions Bot added the pr:needs-rebase The pull request has merge conflicts label Oct 6, 2026
@sk593 sk593 added the pr:standard Ongoing maintenance, minor improvements, documentation updates, and routine development work label Oct 6, 2026
@sk593 sk593 changed the title authz: add authorization error codes feat(authz): add authorization error codes Oct 6, 2026
sk593 and others added 2 commits October 6, 2026 15:27
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: sk593 <shruthikumar@microsoft.com>
Add the internal component authorization error codes to the ARM error
codes, a code-to-HTTP-status mapping in pkg/authz, and conversion from
DeniedError to an ARM error response. Not wired into any request path.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: sk593 <shruthikumar@microsoft.com>
@sk593
sk593 force-pushed the sk593-authz-error-codes branch from 0d81c5e to 7cd77e5 Compare October 6, 2026 22:29
@github-actions github-actions Bot removed the pr:needs-rebase The pull request has merge conflicts label Oct 6, 2026
sk593 and others added 2 commits October 6, 2026 16:16
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: sk593 <shruthikumar@microsoft.com>
Require nonblank request action and target when converting denials and propagate conversion errors explicitly.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: sk593 <shruthikumar@microsoft.com>
@radius-functional-tests

radius-functional-tests Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Radius functional test overview

🔍 Go to test action run

Click here to see the test run details
Name Value
Repository radius-project/radius
Commit ref e580d4b
Unique ID funca103dd0a33
Image tag pr-funca103dd0a33
  • Dapr: 1.14.4
  • Azure KeyVault CSI driver: 1.4.2
  • Azure Workload identity webhook: 1.3.0
  • Bicep recipe location ghcr.io/radius-project/dev/test/testrecipes/test-bicep-recipes/<name>:pr-funca103dd0a33
  • Terraform recipe location http://tf-module-server.radius-test-tf-module-server.svc.cluster.local/<name>.zip (in cluster)
  • applications-rp test image location: ghcr.io/radius-project/dev/applications-rp:pr-funca103dd0a33
  • dynamic-rp test image location: ghcr.io/radius-project/dev/dynamic-rp:pr-funca103dd0a33
  • controller test image location: ghcr.io/radius-project/dev/controller:pr-funca103dd0a33
  • ucp test image location: ghcr.io/radius-project/dev/ucpd:pr-funca103dd0a33
  • deployment-engine test image location: ghcr.io/radius-project/deployment-engine:latest

Test Status

⌛ Building Radius and pushing container images for functional tests...
✅ Container images build succeeded
⌛ Publishing Bicep Recipes for functional tests...
✅ Recipe publishing succeeded
⌛ Starting corerp-cloud functional tests...
⌛ Starting ucp-cloud functional tests...
✅ ucp-cloud functional tests succeeded
✅ corerp-cloud functional tests succeeded

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr:standard Ongoing maintenance, minor improvements, documentation updates, and routine development work

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant