Skip to content

Conversation

@demarna1
Copy link

@demarna1 demarna1 commented Nov 26, 2025

closes: #172

View the linked issue for additional context and reproduction of the issue.

Test evidence

User has access to activity in the namespace "serving-test-mlzone" but lacks access to "serving-test-s3":

Screenshot 2025-11-26 at 4 27 31 PM

Requesting /api/activities/serving-test-mlzone directly (user has access):

Screenshot 2025-11-26 at 4 27 15 PM

Requesting /api/activities/serving-test-s3 directly (user lacks access and is blocked):

Screenshot 2025-11-26 at 4 27 08 PM

Requesting a namespace that does not exist:

Screenshot 2025-11-26 at 4 26 29 PM

@google-oss-prow
Copy link

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign orfeas-k, thesuperzapper for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@demarna1 demarna1 changed the title Restrict activities API based on namespace access fix(dashboard): restrict activities API based on namespace access Nov 26, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Activities API is not namespace restricted

1 participant