Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 6 additions & 14 deletions pkg/connector/group.go
Original file line number Diff line number Diff line change
Expand Up @@ -133,23 +133,15 @@ func (g *groupResourceType) Grants(ctx context.Context, resource *v2.Resource, p
}

memberIDs := mapGroupMembers(groupMembers)
targetMembers, _, err := g.client.GetUsers(
ctx,
servicenow.PaginationVars{
Limit: len(memberIDs),
},
memberIDs,
)
if err != nil {
return nil, "", nil, fmt.Errorf("servicenow-connector: failed to list members under group %s: %w", resource.Id.Resource, err)
if len(memberIDs) == 0 {
return []*v2.Grant{}, nextPageToken, nil, nil
}

var rv []*v2.Grant
for _, member := range targetMembers {
memberCopy := member
ur, err := userResource(&memberCopy)
for _, member := range memberIDs {
rID, err := rs.NewResourceID(resourceTypeUser, member)
if err != nil {
return nil, "", nil, err
return nil, "", nil, fmt.Errorf("baton-servicenow: error creating principal id")
}

// grant group membership
Expand All @@ -158,7 +150,7 @@ func (g *groupResourceType) Grants(ctx context.Context, resource *v2.Resource, p
grant.NewGrant(
resource,
groupMembership,
ur.Id,
rID,
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: Grant Creation Fails for Non-existent Users

The List method now creates grants for all group member IDs without validating if the corresponding users exist, as the GetUsers() call was removed. This can lead to grants for non-existent users. Additionally, if rs.NewResourceID() fails, the error message baton-servicenow: error creating principal id discards the original error details, hindering debugging.

Fix in Cursor Fix in Web

),
)
}
Expand Down
Loading