chore: remove rbac psuedo resources, add custom verbs (#13276)

Removes our pseudo rbac resources like `WorkspaceApplicationConnect` in favor of additional verbs like `ssh`. This is to make more intuitive permissions for building custom roles.

The source of truth is now `policy.go`
This commit is contained in:
Steven Masley
2024-05-15 11:09:42 -05:00
committed by GitHub
parent cb6b5e8fbd
commit 1f5788feff
48 changed files with 1809 additions and 1053 deletions
+17 -5
View File
@@ -26,11 +26,6 @@ import (
"github.com/coder/coder/v2/coderd/util/slice"
)
// AllActions is a helper function to return all the possible actions types.
func AllActions() []policy.Action {
return []policy.Action{policy.ActionCreate, policy.ActionRead, policy.ActionUpdate, policy.ActionDelete}
}
type AuthCall struct {
Actor Subject
Action policy.Action
@@ -219,6 +214,10 @@ type RegoAuthorizer struct {
authorizeHist *prometheus.HistogramVec
prepareHist prometheus.Histogram
// strict checking also verifies the inputs to the authorizer. Making sure
// the action make sense for the input object.
strict bool
}
var _ Authorizer = (*RegoAuthorizer)(nil)
@@ -240,6 +239,13 @@ func NewCachingAuthorizer(registry prometheus.Registerer) Authorizer {
return Cacher(NewAuthorizer(registry))
}
// NewStrictCachingAuthorizer is mainly just for testing.
func NewStrictCachingAuthorizer(registry prometheus.Registerer) Authorizer {
auth := NewAuthorizer(registry)
auth.strict = true
return Cacher(auth)
}
func NewAuthorizer(registry prometheus.Registerer) *RegoAuthorizer {
queryOnce.Do(func() {
var err error
@@ -326,6 +332,12 @@ type authSubject struct {
// the object.
// If an error is returned, the authorization is denied.
func (a RegoAuthorizer) Authorize(ctx context.Context, subject Subject, action policy.Action, object Object) error {
if a.strict {
if err := object.ValidAction(action); err != nil {
return xerrors.Errorf("strict authz check: %w", err)
}
}
start := time.Now()
ctx, span := tracing.StartSpan(ctx,
trace.WithTimestamp(start), // Reuse the time.Now for metric and trace