mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore: add aibridge database resources & define RBAC policies (#19796)
Closes https://github.com/coder/internal/issues/986
This commit is contained in:
@@ -77,6 +77,7 @@ const (
|
||||
SubjectTypeSubAgentAPI SubjectType = "sub_agent_api"
|
||||
SubjectTypeFileReader SubjectType = "file_reader"
|
||||
SubjectTypeUsagePublisher SubjectType = "usage_publisher"
|
||||
SubjectAibridged SubjectType = "aibridged"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
@@ -15,6 +15,15 @@ var (
|
||||
Type: "*",
|
||||
}
|
||||
|
||||
// ResourceAibridgeInterception
|
||||
// Valid Actions
|
||||
// - "ActionCreate" :: create aibridge interceptions & related records
|
||||
// - "ActionRead" :: read aibridge interceptions & related records
|
||||
// - "ActionUpdate" :: update aibridge interceptions & related records
|
||||
ResourceAibridgeInterception = Object{
|
||||
Type: "aibridge_interception",
|
||||
}
|
||||
|
||||
// ResourceApiKey
|
||||
// Valid Actions
|
||||
// - "ActionCreate" :: create an api key
|
||||
@@ -391,6 +400,7 @@ var (
|
||||
func AllResources() []Objecter {
|
||||
return []Objecter{
|
||||
ResourceWildcard,
|
||||
ResourceAibridgeInterception,
|
||||
ResourceApiKey,
|
||||
ResourceAssignOrgRole,
|
||||
ResourceAssignRole,
|
||||
|
||||
@@ -358,4 +358,11 @@ var RBACPermissions = map[string]PermissionDefinition{
|
||||
ActionUpdate: "update usage events",
|
||||
},
|
||||
},
|
||||
"aibridge_interception": {
|
||||
Actions: map[Action]ActionDefinition{
|
||||
ActionRead: "read aibridge interceptions & related records",
|
||||
ActionUpdate: "update aibridge interceptions & related records",
|
||||
ActionCreate: "create aibridge interceptions & related records",
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
@@ -888,6 +888,21 @@ func TestRolePermissions(t *testing.T) {
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
Name: "AIBridgeInterceptions",
|
||||
Actions: []policy.Action{policy.ActionCreate, policy.ActionRead, policy.ActionUpdate},
|
||||
Resource: rbac.ResourceAibridgeInterception.WithOwner(currentUser.String()),
|
||||
AuthorizeMap: map[bool][]hasAuthSubjects{
|
||||
true: {owner, memberMe, orgMemberMe},
|
||||
false: {
|
||||
otherOrgMember,
|
||||
orgAdmin, otherOrgAdmin,
|
||||
orgAuditor, otherOrgAuditor,
|
||||
templateAdmin, orgTemplateAdmin, otherOrgTemplateAdmin,
|
||||
userAdmin, orgUserAdmin, otherOrgUserAdmin,
|
||||
},
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
// We expect every permission to be tested above.
|
||||
|
||||
Reference in New Issue
Block a user