mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: Implement allow_list for scopes for resource specific permissions (#5769)
* feat: Implement allow_list for scopes for resource specific permissions Feature that adds an allow_list for scopes to specify particular resources. This enables workspace agent tokens to use the same RBAC system as users. - Add ID to compileSQL matchers * Plumb through WithID on rbac objects * Rename Scope -> ScopeName * Update input.json with scope allow_list Co-authored-by: Cian Johnston <cian@coder.com>
This commit is contained in:
co-authored by
Cian Johnston
parent
f0df0686f9
commit
08cce81ac8
@@ -142,6 +142,17 @@ func TestRegoQueries(t *testing.T) {
|
||||
ExpectedSQL: p("(false) OR (false)"),
|
||||
VariableConverter: regosql.NoACLConverter(),
|
||||
},
|
||||
{
|
||||
Name: "AllowList",
|
||||
Queries: []string{
|
||||
`input.object.id != "" `,
|
||||
`input.object.id in ["9046b041-58ed-47a3-9c3a-de302577875a"]`,
|
||||
},
|
||||
// Special case where the bool is wrapped
|
||||
ExpectedSQL: p(`(id :: text != '') OR ` +
|
||||
`(id :: text = ANY(ARRAY ['9046b041-58ed-47a3-9c3a-de302577875a']))`),
|
||||
VariableConverter: regosql.NoACLConverter(),
|
||||
},
|
||||
{
|
||||
Name: "TwoExpressions",
|
||||
Queries: []string{
|
||||
|
||||
@@ -2,6 +2,10 @@ package regosql
|
||||
|
||||
import "github.com/coder/coder/coderd/rbac/regosql/sqltypes"
|
||||
|
||||
func resourceIDMatcher() sqltypes.VariableMatcher {
|
||||
return sqltypes.StringVarMatcher("id :: text", []string{"input", "object", "id"})
|
||||
}
|
||||
|
||||
func organizationOwnerMatcher() sqltypes.VariableMatcher {
|
||||
return sqltypes.StringVarMatcher("organization_id :: text", []string{"input", "object", "org_owner"})
|
||||
}
|
||||
@@ -20,6 +24,7 @@ func userACLMatcher(m sqltypes.VariableMatcher) sqltypes.VariableMatcher {
|
||||
|
||||
func TemplateConverter() *sqltypes.VariableConverter {
|
||||
matcher := sqltypes.NewVariableConverter().RegisterMatcher(
|
||||
resourceIDMatcher(),
|
||||
organizationOwnerMatcher(),
|
||||
// Templates have no user owner, only owner by an organization.
|
||||
sqltypes.AlwaysFalse(userOwnerMatcher()),
|
||||
@@ -35,6 +40,7 @@ func TemplateConverter() *sqltypes.VariableConverter {
|
||||
// group or user ACL columns.
|
||||
func NoACLConverter() *sqltypes.VariableConverter {
|
||||
matcher := sqltypes.NewVariableConverter().RegisterMatcher(
|
||||
resourceIDMatcher(),
|
||||
organizationOwnerMatcher(),
|
||||
userOwnerMatcher(),
|
||||
)
|
||||
@@ -48,6 +54,7 @@ func NoACLConverter() *sqltypes.VariableConverter {
|
||||
|
||||
func DefaultVariableConverter() *sqltypes.VariableConverter {
|
||||
matcher := sqltypes.NewVariableConverter().RegisterMatcher(
|
||||
resourceIDMatcher(),
|
||||
organizationOwnerMatcher(),
|
||||
userOwnerMatcher(),
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user