mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore: verify validity of built in rbac roles (#13296)
Verifies our built in roles are valid according to our policy.go. Working on custom roles requires the dynamic roles to adhere to these rules. Feels fair the built in ones do too.
This commit is contained in:
@@ -1,9 +1,8 @@
|
||||
package rbac
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
|
||||
"github.com/google/uuid"
|
||||
"golang.org/x/xerrors"
|
||||
|
||||
"github.com/coder/coder/v2/coderd/rbac/policy"
|
||||
)
|
||||
@@ -36,10 +35,10 @@ type Object struct {
|
||||
func (z Object) ValidAction(action policy.Action) error {
|
||||
perms, ok := policy.RBACPermissions[z.Type]
|
||||
if !ok {
|
||||
return fmt.Errorf("invalid type %q", z.Type)
|
||||
return xerrors.Errorf("invalid type %q", z.Type)
|
||||
}
|
||||
if _, ok := perms.Actions[action]; !ok {
|
||||
return fmt.Errorf("invalid action %q for type %q", action, z.Type)
|
||||
return xerrors.Errorf("invalid action %q for type %q", action, z.Type)
|
||||
}
|
||||
|
||||
return nil
|
||||
|
||||
Reference in New Issue
Block a user