Skip to content

Migrate organization and user flows to BaseOrg/BaseUser - #1982

Open
jdalphond-mitre wants to merge 30 commits into
2.9.0-releasefrom
jd_1942_1943
Open

jdalphond-mitre wants to merge 30 commits into
2.9.0-releasefrom
jd_1942_1943

Conversation

@jdalphond-mitre

@jdalphond-mitre jdalphond-mitre commented Aug 27, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

#1942
#1943
Migrates CVE, CVE-ID, organization, and user flows away from legacy repository dual-writes while preserving legacy-format compatibility where required.

Important Changes

src/repositories/baseOrgRepository.js / src/repositories/baseUserRepository.js

  • Moved organization and user reads, writes, authorization, and audit lookups to BaseOrg/BaseUser.
  • Removed legacy user dual-write behavior and retired repository factory support.

src/utils/orgCompatibility.js / src/utils/userCompatibility.js

  • Added compatibility projections for legacy organization and user API responses.

src/controller/

  • Updated CVE, CVE-ID, organization, registry, and user controllers to use the consolidated repositories.

src/repositories/userRepository.js / src/scripts/migrate.js

  • Removed retired legacy repository and migration implementations.

test/

  • Updated affected unit and integration tests.
  • Added compatibility and legacy user-write contract coverage.
  • Reorganized organization tests into legacy and registry groups.

Testing

  • 1) Run bash -i -c "npm run test:integration".
  • 2) Verify legacy and registry organization/user endpoints preserve expected response formats.
  • 3) Verify CVE-ID reservation and CVE update flows succeed for CNA and ADP users.

@david-rocca david-rocca left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The factory no longer exposes the legacy repositories, but these artifacts remain:

@david-rocca

Copy link
Copy Markdown
Collaborator

In addition, we need to fix the lint issues.

@jdalphond-mitre

Copy link
Copy Markdown
Collaborator Author

linting fixed
4 files removed

Comment thread test/integration-tests/middleware/authenticatedContextTest.js Dismissed
@david-rocca

Copy link
Copy Markdown
Collaborator

Looks like we have one more linting fix

… out legacy and registry tests to more easily tell which files are which.
…bsolete OrgRepository factory getter and legacy test mocks.
Update legacy user-capacity setup to use BaseOrg membership rather than
legacy User records. Add coverage that verifies legacy user create, update,
read, and reset-secret responses remain compatible while BaseUser and
BaseOrg remain the sources of truth.
Project legacy user reads and write responses directly from BaseUser and
BaseOrg membership/admin data, eliminating UserRepository and RegistryUser
usage from BaseUserRepository create, update, full update, reset-secret,
delete, lookup, and authorization paths.

Normalize legacy dotted user fields during creation and re-read the owning
BaseOrg before projecting legacy responses so names and ADMIN roles match the
persisted BaseUser/BaseOrg state. Avoid logging one-time user secrets in org
creation audit records.

Release BaseOrg reservation locks before sending post-lock CVE-ID responses,
while retaining finally cleanup for exceptions, so an immediately-following
reservation is not incorrectly rejected as in progress.

Update unit and integration tests for BaseUser-only behavior, legacy write
compatibility, and clearer reservation response assertions.
Registry full user updates preserve ADMIN membership when the user remains
in the same organization. When org_short_name changes, the user is removed
from the source admins list and receives destination membership only.

Extend integration coverage for both same-org updates and organization moves.
Use BaseUserRepository when CVE and CVE-ID controllers resolve the
authenticated requester UUID for audit metadata, removing their remaining
UserRepository factory dependency.

Update affected CVE/CVE-ID unit-test factories to provide BaseUserRepository
and update registry user-move coverage to require destination membership
without destination ADMIN access.
Make BaseOrg the sole source of ADMIN membership by removing the legacy
User collection updates from addAdmin() and removeAdmin(). Legacy user
responses continue to derive active_roles from BaseOrg membership through
the compatibility projection.

Expand admin-role integration coverage to verify that:
- legacy grants remain visible through registry reads,
- registry revokes remain visible through both API formats, and
- registry grants remain visible through legacy reads.
Remove the legacy UserRepository factory import and getter now that all
production callers use BaseUserRepository.

Delete the retired UserRepository implementation and its unit coverage.
Update remaining middleware, user-update, and reservation test helpers to
use BaseOrgRepository and BaseUserRepository exclusively.
Seed canonical BaseOrg/BaseUser fixtures directly, including memberships, admin references, discriminator types, and quotas.

Remove the legacy Org/User migration script and obsolete test setup references.

Update population helpers and affected tests to use Base repositories only.

Retain Monday migration support for existing BaseOrg/BaseUser data.
jdalphond-mitre and others added 6 commits October 7, 2026 11:20
Return empty active_roles for disabled organizations and remove the
implicit CNA fallback. Include disabled in legacy read projections,
remove obsolete code, and add regression coverage.
Authentication previously validated organization membership, active user
status, and API keys without checking BaseOrg.disabled. Members of disabled
organizations could therefore authenticate and reach role and ownership
checks using the organization’s stored authority.

Update required and optional authentication to:
- Load the organization UUID and disabled flag from BaseOrg.
- Require disabled to be explicitly false before validating the user.
- Reject missing, null, or non-boolean disabled values.
- Clear authenticated state and cached organization/user UUIDs before
  validation to prevent rejected attempts from retaining stale identity.
- Preserve active-user, membership, API-key, role, and ownership checks.

Required authentication returns 401 for non-enabled organizations. Optional
authentication continues with unauthenticated public response behavior.
Disabled Secretariat organizations receive no exemption.

Add regression coverage for:
- Enabled CNA admins and regular members reserving IDs and publishing
  and editing records owned by their organization.
- Disabled organizations being denied reservation, publication, and editing.
- Missing or malformed disabled flags failing authentication.
- Optional reads redacting protected information for disabled organizations.
- Inactive users, missing active status, invalid keys, and false membership
  claims being rejected.
- Cross-CNA reservation, publication, and editing remaining forbidden.
- Denied edits leaving existing records unchanged.
- Stale optional authentication context being cleared before user lookup.
Default Secretariat organizations to disabled: false and require that
value in model and JSON schema validation.

Protect organization creation and full updates by checking both existing
and requested authority roles. Reject attempts to remove SECRETARIAT and
disable the organization in the same request.

Keep Secretariat organizations enabled when full updates omit disabled,
and enable organizations promoted to Secretariat through registry or
legacy role updates.

Return HTTP 400 for rejected disable attempts, including review approvals.
Abort rejected approvals so the review remains pending.

Preserve normal CNA disabling and existing authentication checks.

Add unit and integration coverage for defaults, validation, role-change
bypasses, omitted flags, CNA disabling, and pending review rollback.
Comment thread test/integration-tests/middleware/authenticatedContextTest.js Dismissed
Comment thread test/unit-tests/middleware/validateUserTest.js Dismissed
Legacy user responses derived the ADMIN role from the owning
organization's admins list without checking the user's status.
Inactive admins therefore returned active_roles: ['ADMIN'], differing
from the previous legacy response behavior.

Require both active status and admin membership when populating
authority.active_roles. Inactive users retain the authority object
with an empty active_roles array.

The shared converter applies this behavior to legacy single-user
and list responses. Stored admin membership remains intact so
reactivated users regain their reported role. Registry role reporting
is unchanged.
@david-rocca david-rocca changed the title WIP - Migrate organization and user flows to BaseOrg/BaseUser Migrate organization and user flows to BaseOrg/BaseUser Oct 8, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants