Visitar URL original
searchquery: user: filter rejects usernames the requester cannot read while owner: accepts them · Issue #29961 · coder/coder · GitHub
Skip to content

searchquery: user: filter rejects usernames the requester cannot read while owner: accepts them #29961

Description

@tracyjohnsonux

The workspace search accepts owner:<username> for any username, but user:<username> resolves the username with the requester's permissions (parseUser in coderd/searchquery/search.go) and returns a 400 when the requester cannot read that user. The same owner filter therefore works as owner:alice and fails as user:alice for members without permission to read other users.

This affects the Workspaces Owner filter from #29872: its "Include workspaces shared with {owner}" switch rewrites owner:<name> to user:<name>. #29872 commits typed owners under owner: so the default path works, but turning the switch on for an owner the requester cannot read still returns a 400.

Options:

  • Let user: fall back to matching by username (owner) plus shares when the lookup is unauthorized, or resolve it with a system context limited to the ID lookup.
  • Or have the frontend disable the switch when the applied owner cannot be read.

Raised by the Coder Agents review on #29872.

Generated by Coder Agents

Activity

  1. linear-code commented on Sep 26, 2026

    @linear-code
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions