Gate remoteStorage by serviceEnabled instead of Flipper #251

Merged
raucao merged 1 commits from bugfix/remotestorage-service-enabled into master 2026-10-06 13:52:18 +00:00
Owner

Problem

The admin "Default services" setting writes the LDAP serviceEnabled attribute, and seeded/new users get remotestorage there. But remoteStorage access was additionally gated behind a per-user Flipper flag (Flipper.enabled?(:remotestorage, …)), and nothing in the codebase ever enables that flag, so remoteStorage was inaccessible for everyone (the dashboard and settings UI also hid it).

Fix

  • Controllers: replace the Flipper gate with current_user.service_enabled?(:remotestorage) (403 if absent), like the other services; drop the now-redundant commented line.
  • Views: the Storage tile/link is shown whenever remoteStorage is globally enabled, matching the other service tiles (views avoid per-user LDAP lookups).
  • Admin user page: the remoteStorage toggle reflects the LDAP serviceEnabled list (this also fixes it reading current_user instead of the user being viewed).
  • Spec: stub the LDAP lookup instead of Flipper and add a 403 case.

E-Mail keeps its Flipper gate for now.

Testing

bin/rspec → 299 examples, 0 failures.

Note

Because access now keys off serviceEnabled, any existing user granted remoteStorage only via the Flipper flag would need serviceEnabled: remotestorage added (one-off backfill, not included here).

## Problem The admin "Default services" setting writes the LDAP `serviceEnabled` attribute, and seeded/new users get `remotestorage` there. But remoteStorage access was additionally gated behind a per-user Flipper flag (`Flipper.enabled?(:remotestorage, …)`), and nothing in the codebase ever enables that flag, so remoteStorage was inaccessible for everyone (the dashboard and settings UI also hid it). ## Fix - Controllers: replace the Flipper gate with `current_user.service_enabled?(:remotestorage)` (403 if absent), like the other services; drop the now-redundant commented line. - Views: the Storage tile/link is shown whenever remoteStorage is globally enabled, matching the other service tiles (views avoid per-user LDAP lookups). - Admin user page: the remoteStorage toggle reflects the LDAP `serviceEnabled` list (this also fixes it reading `current_user` instead of the user being viewed). - Spec: stub the LDAP lookup instead of Flipper and add a 403 case. E-Mail keeps its Flipper gate for now. ## Testing `bin/rspec` → 299 examples, 0 failures. ## Note Because access now keys off `serviceEnabled`, any existing user granted remoteStorage only via the Flipper flag would need `serviceEnabled: remotestorage` added (one-off backfill, not included here).
raucao added 1 commit 2026-10-06 13:11:48 +00:00
Gate remoteStorage by serviceEnabled instead of Flipper
CI / Test (pull_request) Successful in 2m4s
Release Drafter / Update release notes draft (pull_request) Successful in 2s
8fae099c12
The admin "Default services" setting writes the LDAP serviceEnabled
attribute, but remoteStorage access was also gated behind an unused
per-user Flipper flag that nothing ever enabled, so remoteStorage was
inaccessible for everyone.

Gate remoteStorage on service_enabled? like the other services, and make
the admin toggle reflect the LDAP attribute (this also fixes it reading
current_user instead of the user being viewed). E-Mail keeps its Flipper
gate for now.
raucao added the
integration
remotestorage
kredits-1
labels 2026-10-06 13:50:56 +00:00
raucao added the bug label 2026-10-06 13:52:13 +00:00
raucao merged commit 49c2c9feea into master 2026-10-06 13:52:18 +00:00
raucao deleted branch bugfix/remotestorage-service-enabled 2026-10-06 13:52:19 +00:00
Sign in to join this conversation.