Conversation
Members can now create automations and manage their own. The automation service enforces ownership checks: members can only edit/delete automations where automation.user_id == user.user_id. Admins and owners can edit/delete any automation in their organization. Changes: - Add MANAGE_AUTOMATIONS to RoleName.MEMBER permission set - Update comments to clarify ownership-based access control model - Update tests to expect MANAGE_AUTOMATIONS for members Fixes the bug where org members could not create automations at all. Co-authored-by: openhands <openhands@all-hands.dev>
Coverage reportClick to see where and how coverage changed
This report was generated by python-coverage-comment-action |
||||||||||||||||||||||||
Add MANAGE_ALL_AUTOMATIONS permission to distinguish between: - Members: can manage their own automations only - Admins/Owners: can manage any automation in the org This approach is OSS-compatible because OSS deployments can grant all permissions without needing to understand organizational roles. Changes: - Add Permission.MANAGE_ALL_AUTOMATIONS to authorization.py - Grant to owner and admin roles only (not members) - Update tests to verify permission distribution Co-authored-by: openhands <openhands@all-hands.dev>
6 tasks
lilagrc
marked this pull request as draft
September 17, 2026 19:36
This was referenced Sep 18, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes the bug where organization members cannot create automations.
After PR #415 in the automation service split permissions into
view_automationsandmanage_automations, the enterprise repo only granted membersVIEW_AUTOMATIONS. This prevented members from creating automations because the automation service requiresmanage_automationspermission on the create endpoint.Solution
This PR introduces a three-tier permission model for automations:
VIEW_AUTOMATIONS- Read-only access (all roles)MANAGE_AUTOMATIONS- Create and manage own automations (all roles)MANAGE_ALL_AUTOMATIONS- Manage any automation in the org (admins/owners only)Permission Distribution
VIEW_AUTOMATIONSMANAGE_AUTOMATIONSMANAGE_ALL_AUTOMATIONSWhy This Approach?
This permission split is OSS-compatible:
Changes in This PR
server/auth/authorization.pyMANAGE_ALL_AUTOMATIONSpermission enumserver/auth/authorization.pyMANAGE_AUTOMATIONSto members, admins, ownersserver/auth/authorization.pyMANAGE_ALL_AUTOMATIONSto admins and owners onlytests/unit/test_authorization.pyRequired Changes in Automation Service
Repository:
OpenHands/automationFile:
openhands/automation/router.pyThe automation service needs to update ownership checks to use
manage_all_automationsinstead of relying solely onuser_idmatching:1. Update
update_automationendpointCurrent code (from PR #427):
Should become:
2. Update
delete_automationendpointCurrently uses
_assert_can_managewhich allows anyone withmanage_automations. After this PR, members will have that permission, so we need to add an ownership check:3. Update
dispatch_automationendpointSame pattern - add ownership check:
4. Update
cancel_runendpointSame pattern:
5. Update tests
File:
tests/test_router.pyUpdate the test fixtures and add new tests:
manage_all_automationsin permissions for admin/ownerTestPermissionEnforcementthat expect admins/owners to be blockedExpected Behavior After Both PRs
Related Issues
manage_all_automationsTest Plan
This PR was created by an AI agent (OpenHands) on behalf of the user.
Enterprise server image for this PR: