Skip to content

feat(tenancy): resolve devices within trusted scope - #28

Merged
KilianBoute merged 2 commits into
mainfrom
feat/scoped-device-resolution
Aug 25, 2026
Merged

KilianBoute merged 2 commits into
mainfrom
feat/scoped-device-resolution

Conversation

@KilianBoute

@KilianBoute KilianBoute commented Aug 25, 2026 •

Copy link
Copy Markdown
Member

Description

This change introduces trusted, scope-aware device resolution for tenancy handling. Device keys are no longer treated as globally unique identifiers, which allows the same non-secret key to safely exist across different projects without creating ambiguous lookups.

The new LoadScopedDevice flow requires trusted server-side context such as organisation, project, or persisted device identity before resolving a device. This improves isolation between tenants, prevents cross-project collisions, and ensures duplicate keys are only rejected within the same trusted scope. Key-only lookups are now explicitly deprecated because they cannot safely distinguish devices in multi-project environments.

The update also simplifies legacy ownership resolution. Legacy owner IDs now deterministically map to the owner’s default organisation instead of attempting to infer secondary organisations. This removes ambiguous ownership behavior, avoids unnecessary organisation queries, and aligns runtime resolution with the identities generated by bootstrap migrations.

Extensive test coverage was added to validate scoped lookups, duplicate handling, fallback behavior for legacy devices, and failure cases when trusted scope information is missing.

Add _id-, project-, organisation-, and legacy-owner-scoped device selection. Permit the same non-secret key outside the trusted scope while rejecting ambiguity within it, and deprecate key-only lookup for new ingress paths.
@codecov

codecov Bot commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 84.84848% with 10 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
pkg/tenancy/device.go 84.84% 5 Missing and 5 partials ⚠️

📢 Thoughts on this report? Let us know!

Resolve owner-only device user_id deterministically as organisationId = projectId = ownerUserId. Preserve stable sub-user-to-master resolution and never infer a secondary organisation from ownership.
@KilianBoute
KilianBoute merged commit 318a557 into main Aug 25, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant