mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add schema for key rotation (#14662)
This commit is contained in:
@@ -55,6 +55,16 @@ var (
|
||||
Type: "audit_log",
|
||||
}
|
||||
|
||||
// ResourceCryptoKey
|
||||
// Valid Actions
|
||||
// - "ActionCreate" :: create crypto keys
|
||||
// - "ActionDelete" :: delete crypto keys
|
||||
// - "ActionRead" :: read crypto keys
|
||||
// - "ActionUpdate" :: update crypto keys
|
||||
ResourceCryptoKey = Object{
|
||||
Type: "crypto_key",
|
||||
}
|
||||
|
||||
// ResourceDebugInfo
|
||||
// Valid Actions
|
||||
// - "ActionRead" :: access to debug routes
|
||||
@@ -299,6 +309,7 @@ func AllResources() []Objecter {
|
||||
ResourceAssignOrgRole,
|
||||
ResourceAssignRole,
|
||||
ResourceAuditLog,
|
||||
ResourceCryptoKey,
|
||||
ResourceDebugInfo,
|
||||
ResourceDeploymentConfig,
|
||||
ResourceDeploymentStats,
|
||||
|
||||
@@ -274,6 +274,14 @@ var RBACPermissions = map[string]PermissionDefinition{
|
||||
ActionUpdate: actDef("update notification preferences"),
|
||||
},
|
||||
},
|
||||
"crypto_key": {
|
||||
Actions: map[Action]ActionDefinition{
|
||||
ActionRead: actDef("read crypto keys"),
|
||||
ActionUpdate: actDef("update crypto keys"),
|
||||
ActionDelete: actDef("delete crypto keys"),
|
||||
ActionCreate: actDef("create crypto keys"),
|
||||
},
|
||||
},
|
||||
// idpsync_settings should always be org scoped
|
||||
"idpsync_settings": {
|
||||
Actions: map[Action]ActionDefinition{
|
||||
|
||||
@@ -705,6 +705,15 @@ func TestRolePermissions(t *testing.T) {
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
Name: "CryptoKeys",
|
||||
Actions: []policy.Action{policy.ActionCreate, policy.ActionUpdate, policy.ActionDelete, policy.ActionRead},
|
||||
Resource: rbac.ResourceCryptoKey,
|
||||
AuthorizeMap: map[bool][]hasAuthSubjects{
|
||||
true: {owner},
|
||||
false: {setOtherOrg, setOrgNotMe, memberMe, orgMemberMe, templateAdmin, userAdmin},
|
||||
},
|
||||
},
|
||||
{
|
||||
Name: "IDPSyncSettings",
|
||||
Actions: []policy.Action{policy.ActionRead, policy.ActionUpdate},
|
||||
|
||||
Reference in New Issue
Block a user