mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: Add template-admin + user-admin role for managing templates + users (#3490)
Co-authored-by: Mathias Fredriksson <mafredri@gmail.com>
This commit is contained in:
co-authored by
Mathias Fredriksson
parent
c41261cf6e
commit
40e68cb80b
+18
-7
@@ -13,23 +13,27 @@ import (
|
||||
|
||||
// assignableSiteRoles returns all site wide roles that can be assigned.
|
||||
func (api *API) assignableSiteRoles(rw http.ResponseWriter, r *http.Request) {
|
||||
// TODO: @emyrk in the future, allow granular subsets of roles to be returned based on the
|
||||
// role of the user.
|
||||
|
||||
actorRoles := httpmw.AuthorizationUserRoles(r)
|
||||
if !api.Authorize(r, rbac.ActionRead, rbac.ResourceRoleAssignment) {
|
||||
httpapi.Forbidden(rw)
|
||||
return
|
||||
}
|
||||
|
||||
roles := rbac.SiteRoles()
|
||||
httpapi.Write(rw, http.StatusOK, convertRoles(roles))
|
||||
assignable := make([]rbac.Role, 0)
|
||||
for _, role := range roles {
|
||||
if rbac.CanAssignRole(actorRoles.Roles, role.Name) {
|
||||
assignable = append(assignable, role)
|
||||
}
|
||||
}
|
||||
|
||||
httpapi.Write(rw, http.StatusOK, convertRoles(assignable))
|
||||
}
|
||||
|
||||
// assignableSiteRoles returns all site wide roles that can be assigned.
|
||||
func (api *API) assignableOrgRoles(rw http.ResponseWriter, r *http.Request) {
|
||||
// TODO: @emyrk in the future, allow granular subsets of roles to be returned based on the
|
||||
// role of the user.
|
||||
organization := httpmw.OrganizationParam(r)
|
||||
actorRoles := httpmw.AuthorizationUserRoles(r)
|
||||
|
||||
if !api.Authorize(r, rbac.ActionRead, rbac.ResourceOrgRoleAssignment.InOrg(organization.ID)) {
|
||||
httpapi.Forbidden(rw)
|
||||
@@ -37,7 +41,14 @@ func (api *API) assignableOrgRoles(rw http.ResponseWriter, r *http.Request) {
|
||||
}
|
||||
|
||||
roles := rbac.OrganizationRoles(organization.ID)
|
||||
httpapi.Write(rw, http.StatusOK, convertRoles(roles))
|
||||
assignable := make([]rbac.Role, 0)
|
||||
for _, role := range roles {
|
||||
if rbac.CanAssignRole(actorRoles.Roles, role.Name) {
|
||||
assignable = append(assignable, role)
|
||||
}
|
||||
}
|
||||
|
||||
httpapi.Write(rw, http.StatusOK, convertRoles(assignable))
|
||||
}
|
||||
|
||||
func (api *API) checkPermissions(rw http.ResponseWriter, r *http.Request) {
|
||||
|
||||
Reference in New Issue
Block a user