fix(signup): name the group and the likely cause when a Kanidm group write fails #112
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-web!112
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/signup-group-write-diagnostics"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Sign-up was broken in production for 13 days (2026-07-17..30) and the only evidence was:
That names neither which group failed nor the fact that 404 is ambiguous here — which is most of why
it went unfound.
Why 404 was misleading
Kanidm returns 404 for a denied write, not 403 — it will not confirm the existence of an entry the
caller may not manage. So the 404 had two very different causes and the message implied the wrong one.
The actual cause was the
entry-managed-bydelegation: sign-up moved fromtier_basictotier_participant(ADR 0029) and gainedtier_trial(ADR 0036), but that delegation is a manualkanidm group set-entry-managerstep and was never re-run — so the portal was denied member-write onthe only groups it writes.
The change
groupWriteError()now produces:Applied to both the tier group and the Forgejo access group, which shared the same uninformative
message. The access group is worth the same treatment: a person missing from
forgejo_usersgets zeroOIDC scopes, so every Forgejo login is refused and no account is ever JIT-created — silent-but-broken
in a different way.
Tests
Three regression tests: the group name is present; a 404 explains the delegation possibility; and a
non-404 does not claim a delegation problem. The last one matters — a hint that fires on the wrong
status is worse than no hint, because it sends the next person down the same wrong path this incident
did.
95 tests pass;
pnpm check0 errors;pnpm lintclean.Scope
This is the observability half. The detection and prevention land in bitborg-infra #262: an apply-time
health gate asserting the portal can manage every group it writes, a critical Loki alert on the first
failed registration, and
scripts/signup-drill.shwhich proves the whole chain against real Kanidm.Neither unit tests nor the local e2e harness could have caught the original bug — it is a production
permission mismatch, not logic, and there is no Kanidm locally. Worth being explicit about, since
"add a test" is the instinctive answer and here it would have been false comfort.