Skip to content

Guard app access replacements with an expected revision - #6

Closed
nathan-thillairajah wants to merge 1 commit into
mainfrom
nthillairajah/apps-viewer-grants
Closed

nathan-thillairajah wants to merge 1 commit into
mainfrom
nthillairajah/apps-viewer-grants

Conversation

@nathan-thillairajah

@nathan-thillairajah nathan-thillairajah commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

An owner or agent can read an app's viewer list, edit it, and unknowingly overwrite a change made in the meantime. bl apps access set --expected-revision lets them require that the policy still matches the version they reviewed.

The CLI refuses the update if the server doesn't support that guarantee. A conflict requires reading and reviewing the policy again; it never retries with an unguarded replacement. Existing commands without the flag keep their current behavior.

@nathan-thillairajah
nathan-thillairajah marked this pull request as ready for review September 24, 2026 17:50
@nathan-thillairajah
nathan-thillairajah requested a review from a team as a code owner September 24, 2026 17:50
@nathan-thillairajah

Copy link
Copy Markdown
Contributor Author

🤖 Closing this PR because it guards the existing account-ID viewer command, while the pilot CLI should grant access to a non-personal Builderlab workspace. The existing access set --viewer command remains on main and must not be used as the pilot sharing flow.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants