Allow access requests before NDA signing

ENG-646: requesting private resources must not hit the
NDA gate; keep requireCompletedNDA on protected exports
only.

Signed-off-by: Émile Ré <emile@probo.com>
This commit is contained in:
Émile Ré
2026-07-30 17:20:08 +02:00
parent 34fa2356e1
commit 3c14f9aa53
2 changed files with 2 additions and 17 deletions

View File

@@ -32,7 +32,8 @@ import (
// requireCompletedNDA enforces portal NDA completion for the signed-in identity.
// No-ops when there is no viewer or the portal membership has no NDA signature.
// Callers own authentication and PUBLIC-resource skips.
// Call from protected (non-PUBLIC) export resolvers after authentication.
// Access-request mutations must not call this — requesting is allowed before signing.
func (r *Resolver) requireCompletedNDA(ctx context.Context) error {
identity := authn.IdentityFromContext(ctx)
if identity == nil {