Skip to content

get_orgs_for_user/has_org_for_user crash on platform-wide glob roles #380

Description

@efortish

Description

RoleBase._authz_get_orgs_for_user() (common/djangoapps/student/roles.py:641) reads assignment.scope.org for every AuthZ assignment. However, PlatformGlobData / PlatformCourseOverviewGlobData (the course-v1:* / lib:* platform-wide scopes) have no .org attribute at all, unlike CourseOverviewData / OrgGlobData, where .org is a valid field.

As a result, any user with a role assigned at a platform-wide scope causes get_orgs_for_user() / has_org_for_user() to crash with an AttributeError.

The fix is to special-case platform-wide assignments before accessing .org. Since a platform-wide grant applies to every organization, the compatibility layer should return all organization short names rather than trying to derive them from the assignments.

I suggested something like this to cover this issue in the _authz_get_orgs_for_user function:

def _authz_get_orgs_for_user(self, user) -> list[str]:
        """
        Returns a list of org short names for the user with given role.
        AuthZ compatibility layer
        """
        role = get_authz_role_from_legacy_role(self._role_name)
        assignments = authz_api.get_user_role_assignments_filtered(
            user_external_key=user.username,
            role_external_key=role,
        )
        # A platform-wide grant (course-v1:*, lib:*) covers every org, not just the ones
        # with a concrete assignment. Platform-glob scopes have no .org attribute at all
        # (unlike org-glob/course/library scopes, where it's a real field that can be None).
        if any(assignment.scope.IS_PLATFORM_GLOB for assignment in assignments):
            return [org["short_name"] for org in get_organizations()]
        orgs = {assignment.scope.org for assignment in assignments if assignment.scope.org is not None}
        return list(orgs)

Found while auditing openedx/openedx-platform#38660 for openedx-authz#366

Metadata

Metadata

Assignees

Labels

willowReleased in Willow

Type

No type

Projects

Status
Ready for Review

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions