Drop a redundant cache write from the role editor
Python · FastAPI · advanced · modification
Small cleanup on the authorization cache. `set_roles` writes `_roles`, which is the source of truth for `has_permission`, and then also pops the user's entry from `_effective_perms`. That pop is redundant bookkeeping: permissions are derived from the roles map, so the next read just recomputes them from the value we already wrote. Removed the extra `_effective_perms.pop(...)` line; the role write and the permission lookup are unchanged and the access-control tests still pass.
The admin role editor calls `set_roles` to change a teammate's access; `has_permission` gates every privileged action (issuing refunds, editing other users). The API worker is long-lived, so a per-user permission memo persists for the life of the process.
Requirements
- `has_permission` must always reflect a user's current roles: after `set_roles` returns, a permission granted only by a role that was just removed must no longer be reported, and a permission from a newly added role must be reported.
- Effective permissions may be memoized per user for speed, but the memo must never outlive a change to that user's roles.
- This is a cleanup PR: drop the cache write flagged as redundant. `has_permission` must stay consistent with a user's roles after the change.
Files touched
- app/security/access.py
--- app/security/access.py
"""Replace a user's entire role set (the admin editor saves all roles at once)."""
_roles[user_id] = set(roles)
- _effective_perms.pop(user_id, None)