workflow-other-collection-refused.json 2.3 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364
  1. {
  2. "name": "verify-workflow-other-collection-refused",
  3. "comment": "Another workflow's private storage is refused even when this workflow's defaultAccess is read-write. defaultAccess is the dangerous case, not an explicit grant: it is a blanket yes to every name the workflow has not listed, so without a check ahead of it a single careless setting reaches every other workflow's data, across projects.\n\nThe control node is the point of the test. It writes, under the same defaultAccess, to an ordinary collection the workflow was never granted by name, and must succeed. That is what makes the refusal above mean something: writes are working and defaultAccess is being honoured, so the wf_ name was refused for being a wf_ name and not because this workflow could not write anywhere. Without the control the case would pass just as happily if storage were broken outright.",
  4. "settings": {
  5. "storagePermissions": {
  6. "defaultAccess": "read-write"
  7. }
  8. },
  9. "nodes": [
  10. {
  11. "id": "n1",
  12. "name": "Trigger",
  13. "type": "click-trigger",
  14. "position": { "x": 0, "y": 0 },
  15. "config": {}
  16. },
  17. {
  18. "id": "other",
  19. "name": "Write to another workflow's storage",
  20. "type": "storage-insert",
  21. "position": { "x": 0, "y": 100 },
  22. "config": {
  23. "collectionSource": "manual",
  24. "collectionManual": "wf_00000000-0000-0000-0000-000000000000",
  25. "documentData": "{\"probe\": \"trespass\"}"
  26. }
  27. },
  28. {
  29. "id": "control",
  30. "name": "Write to an ordinary collection it was never granted by name",
  31. "type": "storage-insert",
  32. "position": { "x": 0, "y": 200 },
  33. "config": {
  34. "collectionSource": "manual",
  35. "collectionManual": "wfprobe_absent_collection",
  36. "documentData": "{\"probe\": \"control\"}"
  37. }
  38. }
  39. ],
  40. "connections": [
  41. {
  42. "sourceNodeId": "n1",
  43. "sourceOutput": "main",
  44. "targetNodeId": "other",
  45. "targetInput": "data"
  46. },
  47. {
  48. "sourceNodeId": "other",
  49. "sourceOutput": "main",
  50. "targetNodeId": "control",
  51. "targetInput": "data"
  52. }
  53. ],
  54. "expect": {
  55. "other": {
  56. "status": "completed",
  57. "output": { "success": false, "error": "No write access to collection: wf_00000000-0000-0000-0000-000000000000" }
  58. },
  59. "control": {
  60. "status": "completed",
  61. "output": { "success": true }
  62. }
  63. }
  64. }