• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

zentralopensource / zentral / 26761988008
88%

Build:
DEFAULT BRANCH: main
Ran 01 Jun 2026 02:50PM UTC
Jobs 1
Files 964
Run time 2min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

01 Jun 2026 02:41PM UTC coverage: 88.078% (+0.03%) from 88.046%
26761988008

push

github

web-flow
Prevent role escalation in user/service-account forms (#1493)

A non-superuser editing another user's groups can now only add groups
they themselves belong to — the escalation-prevention pattern from K8s
RBAC and AWS permission boundaries. Implemented as
RoleMembershipGrantMixin shared by UpdateUserForm and
ServiceAccountForm: rejects added groups in clean() and renders them
as disabled options in the multi-select. Removals are unrestricted by
design — escalation risk is granting, not revoking.

Also relabels the auto-generated M2M field as "Roles" to match the
rest of the UI, drops the auth-default help text that referenced
permissions, widens the widget, and moves the disabled-options
SelectMultiple to zentral/utils/forms.py for reuse.

Co-authored-by: Sebastian Fuchs <sebastian@zentral.com>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>

67 of 67 new or added lines in 3 files covered. (100.0%)

46329 of 52600 relevant lines covered (88.08%)

0.88 hits per line

Jobs
ID Job ID Ran Files Coverage
1 26761988008.1 01 Jun 2026 02:50PM UTC 964
88.08
GitHub Action Run
Source Files on build 26761988008
  • Tree
  • List 964
  • Changed 4
  • Source Changed 3
  • Coverage Changed 4
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #26761988008
  • 1511a926 on github
  • Prev Build on main (#26713944733)
  • Next Build on main (#26809471676)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc