mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: Implement allow_list for scopes for resource specific permissions (#5769)
* feat: Implement allow_list for scopes for resource specific permissions Feature that adds an allow_list for scopes to specify particular resources. This enables workspace agent tokens to use the same RBAC system as users. - Add ID to compileSQL matchers * Plumb through WithID on rbac objects * Rename Scope -> ScopeName * Update input.json with scope allow_list Co-authored-by: Cian Johnston <cian@coder.com>
This commit is contained in:
co-authored by
Cian Johnston
parent
f0df0686f9
commit
08cce81ac8
+37
-20
@@ -6,41 +6,58 @@ import (
|
||||
"golang.org/x/xerrors"
|
||||
)
|
||||
|
||||
type Scope string
|
||||
type ScopeName string
|
||||
|
||||
// Scope acts the exact same as a Role with the addition that is can also
|
||||
// apply an AllowIDList. Any resource being checked against a Scope will
|
||||
// reject any resource that is not in the AllowIDList.
|
||||
// To not use an AllowIDList to reject authorization, use a wildcard for the
|
||||
// AllowIDList. Eg: 'AllowIDList: []string{WildcardSymbol}'
|
||||
type Scope struct {
|
||||
Role
|
||||
AllowIDList []string `json:"allow_list"`
|
||||
}
|
||||
|
||||
const (
|
||||
ScopeAll Scope = "all"
|
||||
ScopeApplicationConnect Scope = "application_connect"
|
||||
ScopeAll ScopeName = "all"
|
||||
ScopeApplicationConnect ScopeName = "application_connect"
|
||||
)
|
||||
|
||||
var builtinScopes map[Scope]Role = map[Scope]Role{
|
||||
// TODO: Support passing in scopeID list for allowlisting resources.
|
||||
var builtinScopes = map[ScopeName]Scope{
|
||||
// ScopeAll is a special scope that allows access to all resources. During
|
||||
// authorize checks it is usually not used directly and skips scope checks.
|
||||
ScopeAll: {
|
||||
Name: fmt.Sprintf("Scope_%s", ScopeAll),
|
||||
DisplayName: "All operations",
|
||||
Site: permissions(map[string][]Action{
|
||||
ResourceWildcard.Type: {WildcardSymbol},
|
||||
}),
|
||||
Org: map[string][]Permission{},
|
||||
User: []Permission{},
|
||||
Role: Role{
|
||||
Name: fmt.Sprintf("Scope_%s", ScopeAll),
|
||||
DisplayName: "All operations",
|
||||
Site: permissions(map[string][]Action{
|
||||
ResourceWildcard.Type: {WildcardSymbol},
|
||||
}),
|
||||
Org: map[string][]Permission{},
|
||||
User: []Permission{},
|
||||
},
|
||||
AllowIDList: []string{WildcardSymbol},
|
||||
},
|
||||
|
||||
ScopeApplicationConnect: {
|
||||
Name: fmt.Sprintf("Scope_%s", ScopeApplicationConnect),
|
||||
DisplayName: "Ability to connect to applications",
|
||||
Site: permissions(map[string][]Action{
|
||||
ResourceWorkspaceApplicationConnect.Type: {ActionCreate},
|
||||
}),
|
||||
Org: map[string][]Permission{},
|
||||
User: []Permission{},
|
||||
Role: Role{
|
||||
Name: fmt.Sprintf("Scope_%s", ScopeApplicationConnect),
|
||||
DisplayName: "Ability to connect to applications",
|
||||
Site: permissions(map[string][]Action{
|
||||
ResourceWorkspaceApplicationConnect.Type: {ActionCreate},
|
||||
}),
|
||||
Org: map[string][]Permission{},
|
||||
User: []Permission{},
|
||||
},
|
||||
AllowIDList: []string{WildcardSymbol},
|
||||
},
|
||||
}
|
||||
|
||||
func ScopeRole(scope Scope) (Role, error) {
|
||||
func ExpandScope(scope ScopeName) (Scope, error) {
|
||||
role, ok := builtinScopes[scope]
|
||||
if !ok {
|
||||
return Role{}, xerrors.Errorf("no scope named %q", scope)
|
||||
return Scope{}, xerrors.Errorf("no scope named %q", scope)
|
||||
}
|
||||
return role, nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user