mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat(coderd): add tasks rbac object (#20234)
This change adds RBAC for tasks. Updates coder/internal#948 Supersedes coder/coder#20212
This commit is contained in:
@@ -286,6 +286,16 @@ var (
|
||||
Type: "tailnet_coordinator",
|
||||
}
|
||||
|
||||
// ResourceTask
|
||||
// Valid Actions
|
||||
// - "ActionCreate" :: create a new task
|
||||
// - "ActionDelete" :: delete task
|
||||
// - "ActionRead" :: read task data or output to view on the UI or CLI
|
||||
// - "ActionUpdate" :: edit task settings or send input to an existing task
|
||||
ResourceTask = Object{
|
||||
Type: "task",
|
||||
}
|
||||
|
||||
// ResourceTemplate
|
||||
// Valid Actions
|
||||
// - "ActionCreate" :: create a template
|
||||
@@ -430,6 +440,7 @@ func AllResources() []Objecter {
|
||||
ResourceReplicas,
|
||||
ResourceSystem,
|
||||
ResourceTailnetCoordinator,
|
||||
ResourceTask,
|
||||
ResourceTemplate,
|
||||
ResourceUsageEvent,
|
||||
ResourceUser,
|
||||
|
||||
@@ -63,6 +63,13 @@ var workspaceActions = map[Action]ActionDefinition{
|
||||
ActionDeleteAgent: "delete an existing workspace agent",
|
||||
}
|
||||
|
||||
var taskActions = map[Action]ActionDefinition{
|
||||
ActionCreate: "create a new task",
|
||||
ActionRead: "read task data or output to view on the UI or CLI",
|
||||
ActionUpdate: "edit task settings or send input to an existing task",
|
||||
ActionDelete: "delete task",
|
||||
}
|
||||
|
||||
// RBACPermissions is indexed by the type
|
||||
var RBACPermissions = map[string]PermissionDefinition{
|
||||
// Wildcard is every object, and the action "*" provides all actions.
|
||||
@@ -86,6 +93,9 @@ var RBACPermissions = map[string]PermissionDefinition{
|
||||
"workspace": {
|
||||
Actions: workspaceActions,
|
||||
},
|
||||
"task": {
|
||||
Actions: taskActions,
|
||||
},
|
||||
// Dormant workspaces have the same perms as workspaces.
|
||||
"workspace_dormant": {
|
||||
Actions: workspaceActions,
|
||||
|
||||
@@ -505,6 +505,15 @@ func TestRolePermissions(t *testing.T) {
|
||||
false: {setOtherOrg, userAdmin, memberMe, orgUserAdmin, orgAuditor, orgMemberMe},
|
||||
},
|
||||
},
|
||||
{
|
||||
Name: "Task",
|
||||
Actions: crud,
|
||||
Resource: rbac.ResourceTask.WithID(uuid.New()).InOrg(orgID).WithOwner(memberMe.Actor.ID),
|
||||
AuthorizeMap: map[bool][]hasAuthSubjects{
|
||||
true: {owner, orgAdmin, orgMemberMe},
|
||||
false: {setOtherOrg, userAdmin, templateAdmin, memberMe, orgTemplateAdmin, orgUserAdmin, orgAuditor},
|
||||
},
|
||||
},
|
||||
// Some admin style resources
|
||||
{
|
||||
Name: "Licenses",
|
||||
|
||||
@@ -50,6 +50,13 @@ var externalLowLevel = map[ScopeName]struct{}{
|
||||
"user_secret:update": {},
|
||||
"user_secret:delete": {},
|
||||
"user_secret:*": {},
|
||||
|
||||
// Tasks
|
||||
"task:create": {},
|
||||
"task:read": {},
|
||||
"task:update": {},
|
||||
"task:delete": {},
|
||||
"task:*": {},
|
||||
}
|
||||
|
||||
// Public composite coder:* scopes exposed to users.
|
||||
|
||||
@@ -95,6 +95,10 @@ const (
|
||||
ScopeTailnetCoordinatorDelete ScopeName = "tailnet_coordinator:delete"
|
||||
ScopeTailnetCoordinatorRead ScopeName = "tailnet_coordinator:read"
|
||||
ScopeTailnetCoordinatorUpdate ScopeName = "tailnet_coordinator:update"
|
||||
ScopeTaskCreate ScopeName = "task:create"
|
||||
ScopeTaskDelete ScopeName = "task:delete"
|
||||
ScopeTaskRead ScopeName = "task:read"
|
||||
ScopeTaskUpdate ScopeName = "task:update"
|
||||
ScopeTemplateCreate ScopeName = "template:create"
|
||||
ScopeTemplateDelete ScopeName = "template:delete"
|
||||
ScopeTemplateRead ScopeName = "template:read"
|
||||
@@ -244,6 +248,10 @@ func (e ScopeName) Valid() bool {
|
||||
ScopeTailnetCoordinatorDelete,
|
||||
ScopeTailnetCoordinatorRead,
|
||||
ScopeTailnetCoordinatorUpdate,
|
||||
ScopeTaskCreate,
|
||||
ScopeTaskDelete,
|
||||
ScopeTaskRead,
|
||||
ScopeTaskUpdate,
|
||||
ScopeTemplateCreate,
|
||||
ScopeTemplateDelete,
|
||||
ScopeTemplateRead,
|
||||
@@ -394,6 +402,10 @@ func AllScopeNameValues() []ScopeName {
|
||||
ScopeTailnetCoordinatorDelete,
|
||||
ScopeTailnetCoordinatorRead,
|
||||
ScopeTailnetCoordinatorUpdate,
|
||||
ScopeTaskCreate,
|
||||
ScopeTaskDelete,
|
||||
ScopeTaskRead,
|
||||
ScopeTaskUpdate,
|
||||
ScopeTemplateCreate,
|
||||
ScopeTemplateDelete,
|
||||
ScopeTemplateRead,
|
||||
|
||||
Reference in New Issue
Block a user