Split employee devices from DeviceConnection

viewer.enrolledDevices shared DeviceConnection with the admin
org list, so totalCount had to authorize with both
employee-device:list and device:list. Mirror
EmployeeDocumentConnection: a dedicated EmployeeDeviceConnection
without totalCount, and keep DeviceConnection.totalCount for
the org fleet only. Cover assumed-session device:get IDOR in e2e.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
Ludovic Vielle
2026-07-21 15:06:12 +02:00
parent 85864a580c
commit 6cac6a8775
7 changed files with 67 additions and 27 deletions

View File

@@ -66,21 +66,6 @@ func (r *deviceResolver) LatestPostures(ctx context.Context, obj *types.Device)
// TotalCount is the resolver for the DeviceConnection.totalCount field.
func (r *deviceConnectionResolver) TotalCount(ctx context.Context, obj *types.DeviceConnection) (int, error) {
if obj.OwnerID != nil {
scope, err := r.authorize(ctx, obj.ParentID, itam.ActionEmployeeDeviceList)
if err != nil {
return 0, err
}
count, err := r.itam.CountForOrganizationIDAndOwnerID(ctx, scope, obj.ParentID, *obj.OwnerID)
if err != nil {
r.logger.ErrorCtx(ctx, "cannot count devices by owner", log.Error(err))
return 0, gqlutils.Internal(ctx)
}
return count, nil
}
scope, err := r.authorize(ctx, obj.ParentID, itam.ActionDeviceList)
if err != nil {
return 0, err