mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: Rbac more coderd endpoints, unit test to confirm (#1437)
* feat: Enforce authorize call on all endpoints - Make 'request()' exported for running custom requests * Rbac users endpoints * 401 -> 403
This commit is contained in:
+5
-13
@@ -50,7 +50,7 @@ type Options struct {
|
||||
SecureAuthCookie bool
|
||||
SSHKeygenAlgorithm gitsshkey.Algorithm
|
||||
TURNServer *turnconn.Server
|
||||
Authorizer *rbac.RegoAuthorizer
|
||||
Authorizer rbac.Authorizer
|
||||
}
|
||||
|
||||
// New constructs the Coder API into an HTTP handler.
|
||||
@@ -83,10 +83,6 @@ func New(options *Options) (http.Handler, func()) {
|
||||
// TODO: @emyrk we should just move this into 'ExtractAPIKey'.
|
||||
authRolesMiddleware := httpmw.ExtractUserRoles(options.Database)
|
||||
|
||||
authorize := func(f http.HandlerFunc, actions rbac.Action) http.HandlerFunc {
|
||||
return httpmw.Authorize(api.Logger, api.Authorizer, actions)(f).ServeHTTP
|
||||
}
|
||||
|
||||
r := chi.NewRouter()
|
||||
|
||||
r.Use(
|
||||
@@ -158,10 +154,7 @@ func New(options *Options) (http.Handler, func()) {
|
||||
})
|
||||
})
|
||||
r.Route("/members", func(r chi.Router) {
|
||||
r.Route("/roles", func(r chi.Router) {
|
||||
r.Use(httpmw.WithRBACObject(rbac.ResourceUserRole))
|
||||
r.Get("/", authorize(api.assignableOrgRoles, rbac.ActionRead))
|
||||
})
|
||||
r.Get("/roles", api.assignableOrgRoles)
|
||||
r.Route("/{user}", func(r chi.Router) {
|
||||
r.Use(
|
||||
httpmw.ExtractUserParam(options.Database),
|
||||
@@ -232,8 +225,7 @@ func New(options *Options) (http.Handler, func()) {
|
||||
r.Get("/", api.users)
|
||||
// These routes query information about site wide roles.
|
||||
r.Route("/roles", func(r chi.Router) {
|
||||
r.Use(httpmw.WithRBACObject(rbac.ResourceUserRole))
|
||||
r.Get("/", authorize(api.assignableSiteRoles, rbac.ActionRead))
|
||||
r.Get("/", api.assignableSiteRoles)
|
||||
})
|
||||
r.Route("/{user}", func(r chi.Router) {
|
||||
r.Use(httpmw.ExtractUserParam(options.Database))
|
||||
@@ -244,8 +236,7 @@ func New(options *Options) (http.Handler, func()) {
|
||||
r.Put("/active", api.putUserStatus(database.UserStatusActive))
|
||||
})
|
||||
r.Route("/password", func(r chi.Router) {
|
||||
r.Use(httpmw.WithRBACObject(rbac.ResourceUserPasswordRole))
|
||||
r.Put("/", authorize(api.putUserPassword, rbac.ActionUpdate))
|
||||
r.Put("/", api.putUserPassword)
|
||||
})
|
||||
r.Get("/organizations", api.organizationsByUser)
|
||||
r.Post("/organizations", api.postOrganizationsByUser)
|
||||
@@ -302,6 +293,7 @@ func New(options *Options) (http.Handler, func()) {
|
||||
r.Route("/workspaces/{workspace}", func(r chi.Router) {
|
||||
r.Use(
|
||||
apiKeyMiddleware,
|
||||
authRolesMiddleware,
|
||||
httpmw.ExtractWorkspaceParam(options.Database),
|
||||
)
|
||||
r.Get("/", api.workspace)
|
||||
|
||||
Reference in New Issue
Block a user