Split employee devices from DeviceConnection

viewer.enrolledDevices shared DeviceConnection with the admin
org list, so totalCount had to authorize with both
employee-device:list and device:list. Mirror
EmployeeDocumentConnection: a dedicated EmployeeDeviceConnection
without totalCount, and keep DeviceConnection.totalCount for
the org fleet only. Cover assumed-session device:get IDOR in e2e.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
Ludovic Vielle
2026-07-21 15:06:12 +02:00
parent 85864a580c
commit 6cac6a8775
7 changed files with 67 additions and 27 deletions

View File

@@ -57,6 +57,8 @@ var ViewerPolicy = policy.NewPolicy(
).WithDescription("Read-only ITAM access for organization viewers")
// EmployeePolicy grants self-enrollment access to organization employees.
// Employee-device list/get mirror core:employee-document:*: a dedicated
// surface so employees can read their own devices without itam:device:list.
var EmployeePolicy = policy.NewPolicy(
"itam:employee",
"ITAM Employee",