Skip to content

Conversation

@KevLehman
Copy link
Member

Proposed changes (including videos or screenshots)

Issue(s)

Steps to test or reproduce

Further comments

@dionisio-bot
Copy link
Contributor

dionisio-bot bot commented Dec 16, 2025

Looks like this PR is not ready to merge, because of the following issues:

  • This PR is missing the 'stat: QA assured' label
  • This PR is missing the required milestone or project

Please fix the issues and try again

If you have any trouble, please check the PR guidelines

@changeset-bot
Copy link

changeset-bot bot commented Dec 16, 2025

⚠️ No Changeset found

Latest commit: 7b4b75f

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai
Copy link
Contributor

coderabbitai bot commented Dec 16, 2025

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/ownership

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions
Copy link
Contributor

📦 Docker Image Size Report

📈 Changes

Service Current Baseline Change Percent
sum of all images 1.2GiB 1.2GiB +12MiB
rocketchat 358MiB 347MiB +12MiB
omnichannel-transcript-service 132MiB 132MiB -739B
queue-worker-service 132MiB 132MiB +3.8KiB
ddp-streamer-service 126MiB 126MiB +445B
account-service 113MiB 113MiB -4.5KiB
authorization-service 111MiB 110MiB +56KiB
stream-hub-service 110MiB 110MiB -7.6KiB
presence-service 110MiB 110MiB -7.7KiB

📊 Historical Trend

---
config:
  theme: "dark"
  xyChart:
    width: 900
    height: 400
---
xychart
  title "Image Size Evolution by Service (Last 30 Days + This PR)"
  x-axis ["11/15 22:28", "11/16 01:28", "11/17 23:50", "11/18 22:53", "11/19 23:02", "11/21 16:49", "11/24 17:34", "11/27 22:32", "11/28 19:05", "12/01 23:01", "12/02 21:57", "12/03 21:00", "12/04 18:17", "12/05 21:56", "12/08 20:15", "12/09 22:17", "12/10 23:26", "12/11 21:56", "12/12 22:45", "12/13 01:34", "12/15 22:31", "12/16 22:18", "12/16 22:58 (PR)"]
  y-axis "Size (GB)" 0 --> 0.5
  line "account-service" [0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11]
  line "authorization-service" [0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11]
  line "ddp-streamer-service" [0.12, 0.12, 0.12, 0.12, 0.12, 0.12, 0.12, 0.12, 0.12, 0.12, 0.12, 0.12, 0.12, 0.12, 0.12, 0.12, 0.12, 0.12, 0.12, 0.12, 0.12, 0.12, 0.12]
  line "omnichannel-transcript-service" [0.14, 0.14, 0.14, 0.14, 0.14, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13]
  line "presence-service" [0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11]
  line "queue-worker-service" [0.14, 0.14, 0.14, 0.14, 0.14, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13, 0.13]
  line "rocketchat" [0.36, 0.36, 0.35, 0.35, 0.35, 0.34, 0.34, 0.34, 0.34, 0.34, 0.34, 0.34, 0.34, 0.34, 0.34, 0.34, 0.34, 0.34, 0.34, 0.34, 0.34, 0.34, 0.35]
  line "stream-hub-service" [0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11, 0.11]
Loading

Statistics (last 22 days):

  • 📊 Average: 1.5GiB
  • ⬇️ Minimum: 1.2GiB
  • ⬆️ Maximum: 1.6GiB
  • 🎯 Current PR: 1.2GiB
ℹ️ About this report

This report compares Docker image sizes from this build against the develop baseline.

  • Tag: pr-37842
  • Baseline: develop
  • Timestamp: 2025-12-16 22:58:44 UTC
  • Historical data points: 22

Updated: Tue, 16 Dec 2025 22:58:44 GMT

@codecov
Copy link

codecov bot commented Dec 16, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (feat/abac@064f6d1). Learn more about missing BASE report.

Additional details and impacted files

Impacted file tree graph

@@             Coverage Diff              @@
##             feat/abac   #37842   +/-   ##
============================================
  Coverage             ?   54.35%           
============================================
  Files                ?     2639           
  Lines                ?    50102           
  Branches             ?    11212           
============================================
  Hits                 ?    27232           
  Misses               ?    20696           
  Partials             ?     2174           
Flag Coverage Δ
e2e 57.34% <ø> (?)
e2e-api 43.72% <ø> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a critical issue with room ownership management when users are automatically removed from rooms due to ABAC (Attribute-Based Access Control) policy violations. When non-compliant owners are removed, the system now intelligently promotes remaining compliant members to maintain room ownership.

Key changes:

  • Added ownership transfer logic that promotes the oldest remaining member when all owners are removed
  • Implemented helper methods to check for owner presence in subscription sets
  • Enhanced user removal logic to handle ownership transitions before removing users

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated 7 comments.

Show a summary per file
File Description
packages/models/src/models/Subscriptions.ts Added three new database methods for ownership management: promoting oldest member to owner, and checking for owner presence in/excluding user ID sets
packages/model-typings/src/models/ISubscriptionsModel.ts Added type definitions for the three new subscription model methods
ee/packages/abac/src/index.ts Implemented core ownership handling logic in removeUsersFromRoomWithOwnershipHandling method and integrated it into user removal flows; updated type signatures to include usersCount
ee/packages/abac/src/helper.ts Updated getAbacRoom return type and projection to include usersCount field
ee/packages/abac/src/can-access-object.spec.ts Added mock implementations for the three new subscription methods in unit tests
ee/packages/abac/src/user-auto-removal.spec.ts Added comprehensive integration tests covering three ownership scenarios: promoting remaining members, handling last owner removal, and maintaining existing compliant owners; moved Subscriptions import to module level

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

removalPromises.push(limit(() => this.removeUserFromRoom(room, user, reason)));
const roomForRemoval: Pick<IRoom, '_id' | 'usersCount'> = {
_id: room._id,
usersCount: room.usersCount,
Copy link

Copilot AI Dec 17, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Similar to line 553, usersCount may be undefined here. While line 599 uses room.usersCount || 0, the type signature on line 567 declares usersCount as required (not optional). However, IRoom's usersCount field is likely optional in the actual type definition. Consider using the nullish coalescing operator ?? instead of || to handle the case where usersCount is legitimately 0 (though this would be a valid count), or ensure the type signature reflects that usersCount is optional.

Copilot uses AI. Check for mistakes.
Comment on lines +654 to +664
const [anyOwnerRemoved, anyOwnerStaying] = await Promise.all([
Subscriptions.hasAnyOwnerInUserIds(room._id, idsToRemove, { projection: { _id: 1 } }),
Subscriptions.hasAnyOwnerNotInUserIds(room._id, idsToRemove, { projection: { _id: 1 } }),
]);

if (!anyOwnerRemoved || anyOwnerStaying) {
await Promise.all(users.map((user) => limit(() => this.removeUserFromRoom(room, user, reason))));
return;
}

const remainingMemberSub = await Subscriptions.promoteOldestByRoomIdExcludingUserIdsToOwner(room._id, idsToRemove, {
Copy link

Copilot AI Dec 17, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There is a potential race condition between checking for owners (lines 654-657) and promoting a new owner (line 664). If another process removes or adds owners between these operations, the logic could fail or produce incorrect results. After promoting a new owner, the code does not verify if the promotion was successful before proceeding with user removal. Consider implementing a transaction or adding verification that a new owner was successfully assigned before removing the old owners.

Copilot uses AI. Check for mistakes.
Comment on lines +1170 to +1173
const query = {
'rid': roomId,
'u._id': { $nin: excludedUserIds },
};
Copy link

Copilot AI Dec 17, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The promoteOldestByRoomIdExcludingUserIdsToOwner method does not filter for subscriptions that don't already have the 'owner' role. Using $addToSet will not cause an error if the user is already an owner, but it means the "oldest" member promoted might already be an owner. This could lead to unexpected behavior where an existing owner is selected instead of promoting a regular member. Consider adding a filter to exclude users who already have the 'owner' role: 'roles': { $ne: 'owner' } or 'roles': { $not: { $in: ['owner'] } }.

Copilot uses AI. Check for mistakes.
Comment on lines +668 to +676
if (!remainingMemberSub) {
this.logger.warn({
msg: 'Cannot assign new owner',
rid: room._id,
reason,
});
}

await Promise.all(users.map((user) => limit(() => this.removeUserFromRoom(room, user, reason))));
Copy link

Copilot AI Dec 17, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The warning message states "Cannot assign new owner" when remainingMemberSub is null, but the code still proceeds to remove all users regardless (line 676). This could leave a room without any owner. Consider whether this is the intended behavior, or if the removal should be aborted when no suitable member can be promoted to owner. If rooms without owners are acceptable in this scenario, the warning message should clarify this is expected.

Copilot uses AI. Check for mistakes.
Comment on lines +1192 to +1212
async hasAnyOwnerInUserIds(roomId: string, userIds: IUser['_id'][], options?: FindOptions<ISubscription>): Promise<boolean> {
const query = {
'rid': roomId,
'roles': 'owner',
'u._id': { $in: userIds },
};

const result = await this.findOne(query, options);
return !!result;
}

async hasAnyOwnerNotInUserIds(roomId: string, userIds: IUser['_id'][], options?: FindOptions<ISubscription>): Promise<boolean> {
const query = {
'rid': roomId,
'roles': 'owner',
'u._id': { $nin: userIds },
};

const result = await this.findOne(query, options);
return !!result;
}
Copy link

Copilot AI Dec 17, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

When userIds is an empty array, the queries $in: [] and $nin: [] will behave in specific ways: $in: [] matches nothing (returns false), while $nin: [] matches everything (returns true if any owner exists). Consider adding explicit guards at the beginning of these methods to handle empty arrays appropriately and make the behavior explicit. For hasAnyOwnerInUserIds with an empty array, returning false seems correct, but for hasAnyOwnerNotInUserIds with an empty array, the current behavior might be surprising to callers.

Copilot uses AI. Check for mistakes.
Comment on lines +640 to +641
const currentMembersCount = room.usersCount;
const remainingMembersCount = currentMembersCount - users.length;
Copy link

Copilot AI Dec 17, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The calculation of remaining members count is incorrect when users array contains duplicate user IDs. Line 637 creates a Set of user IDs, but line 641 subtracts users.length (which can include duplicates) from the member count. This should subtract userIdsToRemove.size instead to accurately reflect the number of unique users being removed.

Copilot uses AI. Check for mistakes.
// When a user is not compliant, remove them from the room automatically
await this.removeUserFromRoom(room, fullUser, 'realtime-policy-eval');
await this.removeUsersFromRoomWithOwnershipHandling(
{ _id: room._id, usersCount: room.usersCount },
Copy link

Copilot AI Dec 17, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The usersCount field may be undefined for rooms that were created before this field was added, or if the projection doesn't include it. Line 553 passes room.usersCount directly without a fallback, unlike line 599 which uses room.usersCount || 0. When usersCount is undefined, the calculation on line 641 will result in NaN, causing incorrect logic in the ownership handling. Consider adding a default value like room.usersCount ?? 0 to handle undefined cases consistently.

Copilot uses AI. Check for mistakes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants