From 3a51a455e1e6e58f2f7536b983ed249be0a45633 Mon Sep 17 00:00:00 2001 From: Prowler Bot Date: Mon, 2 Jun 2025 12:17:45 +0200 Subject: [PATCH] fix: set user_id for tenant operations (#7899) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-authored-by: Adrián Jesús Peña Rodríguez Co-authored-by: Pepe Fagoaga --- api/CHANGELOG.md | 1 + api/src/backend/api/base_views.py | 14 ++------------ 2 files changed, 3 insertions(+), 12 deletions(-) diff --git a/api/CHANGELOG.md b/api/CHANGELOG.md index 1b345d5868..8374ddfa11 100644 --- a/api/CHANGELOG.md +++ b/api/CHANGELOG.md @@ -9,6 +9,7 @@ All notable changes to the **Prowler API** are documented in this file. - Fixed Kubernetes UID validation to allow valid context names [(#7871)](https://github.com/prowler-cloud/prowler/pull/7871) - Fixed the connection status verification before launching a scan [(#7831)](https://github.com/prowler-cloud/prowler/pull/7831) - Fixed a race condition when creating background tasks [(#7876)](https://github.com/prowler-cloud/prowler/pull/7876). +- Fixed an error when modifying or retrieving tenants due to missing user UUID in transaction context [(#7890)](https://github.com/prowler-cloud/prowler/pull/7890). --- diff --git a/api/src/backend/api/base_views.py b/api/src/backend/api/base_views.py index 3e965482df..605afe332d 100644 --- a/api/src/backend/api/base_views.py +++ b/api/src/backend/api/base_views.py @@ -109,16 +109,6 @@ class BaseTenantViewset(BaseViewSet): pass # Tenant might not exist, handle gracefully def initial(self, request, *args, **kwargs): - if ( - request.resolver_match.url_name != "tenant-detail" - and request.method != "DELETE" - ): - user_id = str(request.user.id) - - with rls_transaction(value=user_id, parameter=POSTGRES_USER_VAR): - return super().initial(request, *args, **kwargs) - - # TODO: DRY this when we have time if request.auth is None: raise NotAuthenticated @@ -126,8 +116,8 @@ class BaseTenantViewset(BaseViewSet): if tenant_id is None: raise NotAuthenticated("Tenant ID is not present in token") - with rls_transaction(tenant_id): - self.request.tenant_id = tenant_id + user_id = str(request.user.id) + with rls_transaction(value=user_id, parameter=POSTGRES_USER_VAR): return super().initial(request, *args, **kwargs)