BP-2428: Environment targeted access control#236
BP-2428: Environment targeted access control#236jeff-matthews wants to merge 8 commits intorelease/v9.0.0from
Conversation
|
Preview deployment for your docs. Learn more about Mintlify Previews.
|
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
WalkthroughDocumentation updates across six files add comprehensive information about Environment Targeted Access Control (ETAC) functionality in BloodHound Enterprise. Changes explain how ETAC restricts environment visibility while preserving baseline role permissions, and introduce a new dedicated ETAC configuration guide with navigation integration. Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@docs/manage-bloodhound/auth/environment-targeted-access-control.mdx`:
- Line 30: Update the sentence that begins "On the **Explore** page, users can
access data from assigned environments only..." to read "shows a subset of
results from authorized environments only" (add the missing article "a") so the
full line becomes: On the **Explore** page, users can access data from assigned
environments only. If a search returns results from unauthorized environments,
the graph shows a subset of results from authorized environments only, and a
message indicates that role-based access filtering is applied.
- Around line 39-41: Update the Privilege Zones copy to remove the implication
that ETAC-scoped users have unrestricted management rights: change the phrase
"see and manage zones" on the Privilege Zones page to clarify they can "view
zones" and that any management actions are limited by their baseline role
permissions and only apply to objects from environments they are authorized for
(referencing the Privilege Zones page text, the ETAC/User/Read-only mention, and
the baseline role permissions lines).
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: e8bc3f70-8514-4dc5-aea0-edaf1904d62d
⛔ Files ignored due to path filters (2)
docs/images/manage/etac-controls.pngis excluded by!**/*.pngdocs/images/manage/etac-hidden-objects.pngis excluded by!**/*.png
📒 Files selected for processing (7)
docs/analyze-data/accept-findings.mdxdocs/analyze-data/explore/search.mdxdocs/analyze-data/posture-page.mdxdocs/docs.jsondocs/manage-bloodhound/auth/environment-targeted-access-control.mdxdocs/manage-bloodhound/auth/overview.mdxdocs/manage-bloodhound/auth/users-and-roles.mdx
docs/manage-bloodhound/auth/environment-targeted-access-control.mdx
Outdated
Show resolved
Hide resolved
docs/manage-bloodhound/auth/environment-targeted-access-control.mdx
Outdated
Show resolved
Hide resolved
docs/manage-bloodhound/auth/environment-targeted-access-control.mdx
Outdated
Show resolved
Hide resolved
docs/manage-bloodhound/auth/environment-targeted-access-control.mdx
Outdated
Show resolved
Hide resolved
rtippitt-specterops
left a comment
There was a problem hiding this comment.
Dropped a couple comments in line.
|
Thanks @rtippitt-specterops! I just pushed a change to address your comments. |
|
We are removing the toast message on the PZ builder page that says "Permission Denied" Instead, we are adding the same filtering applied message to the top of the screen that is on the explore page. |
Purpose
This pull request (PR) documents the new environment targeted access control (ETAC) feature as described in BP-2428.
Staging
https://specterops-bp-2428-etac.mintlify.app/manage-bloodhound/auth/environment-targeted-access-control