mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: Dbauthz is now default, remove out of experimental (#6650)
* feat: dbauthz always on, out of experimental * Add ability to do rbac checks in unit tests * Remove AuthorizeAllEndpoints * Remove duplicate rbac checks
This commit is contained in:
@@ -38,6 +38,13 @@ func (NotAuthorizedError) Unwrap() error {
|
||||
return sql.ErrNoRows
|
||||
}
|
||||
|
||||
func IsNotAuthorizedError(err error) bool {
|
||||
if err == nil {
|
||||
return false
|
||||
}
|
||||
return xerrors.As(err, &NotAuthorizedError{})
|
||||
}
|
||||
|
||||
func logNotAuthorizedError(ctx context.Context, logger slog.Logger, err error) error {
|
||||
// Only log the errors if it is an UnauthorizedError error.
|
||||
internalError := new(rbac.UnauthorizedError)
|
||||
@@ -50,8 +57,9 @@ func logNotAuthorizedError(ctx context.Context, logger slog.Logger, err error) e
|
||||
//
|
||||
// NotAuthorizedError is == to sql.ErrNoRows, which is not correct
|
||||
// if it's actually a canceled context.
|
||||
internalError.SetInternal(context.Canceled)
|
||||
return internalError
|
||||
contextError := *internalError
|
||||
contextError.SetInternal(context.Canceled)
|
||||
return &contextError
|
||||
}
|
||||
logger.Debug(ctx, "unauthorized",
|
||||
slog.F("internal", internalError.Internal()),
|
||||
|
||||
@@ -21,6 +21,11 @@ import (
|
||||
func TestAsNoActor(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
t.Run("NoError", func(t *testing.T) {
|
||||
t.Parallel()
|
||||
require.False(t, dbauthz.IsNotAuthorizedError(nil), "no error")
|
||||
})
|
||||
|
||||
t.Run("AsRemoveActor", func(t *testing.T) {
|
||||
t.Parallel()
|
||||
_, ok := dbauthz.ActorFromContext(context.Background())
|
||||
@@ -80,6 +85,7 @@ func TestInTX(t *testing.T) {
|
||||
}, nil)
|
||||
require.Error(t, err, "must error")
|
||||
require.ErrorAs(t, err, &dbauthz.NotAuthorizedError{}, "must be an authorized error")
|
||||
require.True(t, dbauthz.IsNotAuthorizedError(err), "must be an authorized error")
|
||||
}
|
||||
|
||||
// TestNew should not double wrap a querier.
|
||||
|
||||
@@ -1068,7 +1068,11 @@ func (q *querier) UpdateUserHashedPassword(ctx context.Context, arg database.Upd
|
||||
|
||||
err = q.authorizeContext(ctx, rbac.ActionUpdate, user.UserDataRBACObject())
|
||||
if err != nil {
|
||||
return err
|
||||
// Admins can update passwords for other users.
|
||||
err = q.authorizeContext(ctx, rbac.ActionUpdate, user.RBACObject())
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
|
||||
return q.db.UpdateUserHashedPassword(ctx, arg)
|
||||
|
||||
Reference in New Issue
Block a user