ref: Begin deprecating category from localities - #123250
2 issues
Medium
Single-tenant locality org-creation guard dropped for default-open signup_visible - `src/sentry/core/endpoints/organization_index.py:108-109`
Non-staff org creation now allows any locality with visible and signup_visible true, and no longer rejects SINGLE_TENANT by category. Because signup_visible defaults to true, a visible single-tenant locality name in dataStorageLocation can be used to provision orgs into dedicated cells unless every ST locality is explicitly configured signup_visible=false.
Single-tenant locality org-creation guard dropped for default-open signup_visible - `src/sentry/core/endpoints/organization_index.py:108-109`
In deployments retaining legacy SINGLE_TENANT locality configurations without an explicit signup_visible value, non-staff users can submit that locality through dataStorageLocation and provision organizations into its dedicated cell. The locality parser defaults omitted signup_visible to true, while the org-creation validator checks only visible and signup_visible and no longer enforces the single-tenant category boundary.
7 skills analyzed
| Skill | Findings | Duration | Cost |
|---|---|---|---|
| security-review | 1 | 5m 8s | $1.72 |
| sentry-backend-bugs | 0 | 5m 15s | $0.75 |
| wrdn-pii | 0 | 6m 4s | $0.71 |
| wrdn-authz | 1 | 11m | $2.17 |
| wrdn-code-execution | 0 | 10m 10s | $0.25 |
| wrdn-data-exfil | 0 | 9m 34s | $1.33 |
| wrdn-dos-review | 0 | 6m 41s | $0.27 |
⏱ 53m 51s · 9.6M in / 290.4k out · $7.20