mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add external API key scopes (#19916)
# Add support for low-level API key scopes This PR adds support for fine-grained API key scopes based on RBAC resource:action pairs. It includes: 1. A new endpoint `/api/v2/auth/scopes` to list all public low-level API key scopes 2. Generated constants in the SDK for all public scopes 3. Tests to verify scope validation during token creation 4. Updated API documentation to reflect the expanded scope options The implementation allows users to create API keys with specific permissions like `workspace:read` or `template:use` instead of only the legacy `all` or `application_connect` scopes. Fixes #19847
This commit is contained in:
Generated
+94
-11
@@ -324,6 +324,26 @@ const docTemplate = `{
|
||||
}
|
||||
}
|
||||
},
|
||||
"/auth/scopes": {
|
||||
"get": {
|
||||
"produces": [
|
||||
"application/json"
|
||||
],
|
||||
"tags": [
|
||||
"Authorization"
|
||||
],
|
||||
"summary": "List API key scopes",
|
||||
"operationId": "list-api-key-scopes",
|
||||
"responses": {
|
||||
"200": {
|
||||
"description": "OK",
|
||||
"schema": {
|
||||
"$ref": "#/definitions/codersdk.ExternalAPIKeyScopes"
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
},
|
||||
"/authcheck": {
|
||||
"post": {
|
||||
"security": [
|
||||
@@ -11299,11 +11319,71 @@ const docTemplate = `{
|
||||
"type": "string",
|
||||
"enum": [
|
||||
"all",
|
||||
"application_connect"
|
||||
"api_key:*",
|
||||
"api_key:create",
|
||||
"api_key:delete",
|
||||
"api_key:read",
|
||||
"api_key:update",
|
||||
"application_connect",
|
||||
"file:*",
|
||||
"file:create",
|
||||
"file:read",
|
||||
"template:*",
|
||||
"template:create",
|
||||
"template:delete",
|
||||
"template:read",
|
||||
"template:update",
|
||||
"template:use",
|
||||
"user:read_personal",
|
||||
"user:update_personal",
|
||||
"user_secret:*",
|
||||
"user_secret:create",
|
||||
"user_secret:delete",
|
||||
"user_secret:read",
|
||||
"user_secret:update",
|
||||
"workspace:*",
|
||||
"workspace:application_connect",
|
||||
"workspace:create",
|
||||
"workspace:delete",
|
||||
"workspace:read",
|
||||
"workspace:ssh",
|
||||
"workspace:start",
|
||||
"workspace:stop",
|
||||
"workspace:update"
|
||||
],
|
||||
"x-enum-varnames": [
|
||||
"APIKeyScopeAll",
|
||||
"APIKeyScopeApplicationConnect"
|
||||
"APIKeyScopeApiKeyAll",
|
||||
"APIKeyScopeApiKeyCreate",
|
||||
"APIKeyScopeApiKeyDelete",
|
||||
"APIKeyScopeApiKeyRead",
|
||||
"APIKeyScopeApiKeyUpdate",
|
||||
"APIKeyScopeApplicationConnect",
|
||||
"APIKeyScopeFileAll",
|
||||
"APIKeyScopeFileCreate",
|
||||
"APIKeyScopeFileRead",
|
||||
"APIKeyScopeTemplateAll",
|
||||
"APIKeyScopeTemplateCreate",
|
||||
"APIKeyScopeTemplateDelete",
|
||||
"APIKeyScopeTemplateRead",
|
||||
"APIKeyScopeTemplateUpdate",
|
||||
"APIKeyScopeTemplateUse",
|
||||
"APIKeyScopeUserReadPersonal",
|
||||
"APIKeyScopeUserUpdatePersonal",
|
||||
"APIKeyScopeUserSecretAll",
|
||||
"APIKeyScopeUserSecretCreate",
|
||||
"APIKeyScopeUserSecretDelete",
|
||||
"APIKeyScopeUserSecretRead",
|
||||
"APIKeyScopeUserSecretUpdate",
|
||||
"APIKeyScopeWorkspaceAll",
|
||||
"APIKeyScopeWorkspaceApplicationConnect",
|
||||
"APIKeyScopeWorkspaceCreate",
|
||||
"APIKeyScopeWorkspaceDelete",
|
||||
"APIKeyScopeWorkspaceRead",
|
||||
"APIKeyScopeWorkspaceSsh",
|
||||
"APIKeyScopeWorkspaceStart",
|
||||
"APIKeyScopeWorkspaceStop",
|
||||
"APIKeyScopeWorkspaceUpdate"
|
||||
]
|
||||
},
|
||||
"codersdk.AddLicenseRequest": {
|
||||
@@ -12373,15 +12453,7 @@ const docTemplate = `{
|
||||
"type": "integer"
|
||||
},
|
||||
"scope": {
|
||||
"enum": [
|
||||
"all",
|
||||
"application_connect"
|
||||
],
|
||||
"allOf": [
|
||||
{
|
||||
"$ref": "#/definitions/codersdk.APIKeyScope"
|
||||
}
|
||||
]
|
||||
"$ref": "#/definitions/codersdk.APIKeyScope"
|
||||
},
|
||||
"token_name": {
|
||||
"type": "string"
|
||||
@@ -13229,6 +13301,17 @@ const docTemplate = `{
|
||||
"ExperimentAIBridge"
|
||||
]
|
||||
},
|
||||
"codersdk.ExternalAPIKeyScopes": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"external": {
|
||||
"type": "array",
|
||||
"items": {
|
||||
"$ref": "#/definitions/codersdk.APIKeyScope"
|
||||
}
|
||||
}
|
||||
}
|
||||
},
|
||||
"codersdk.ExternalAgentCredentials": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
|
||||
Generated
+96
-8
@@ -274,6 +274,22 @@
|
||||
}
|
||||
}
|
||||
},
|
||||
"/auth/scopes": {
|
||||
"get": {
|
||||
"produces": ["application/json"],
|
||||
"tags": ["Authorization"],
|
||||
"summary": "List API key scopes",
|
||||
"operationId": "list-api-key-scopes",
|
||||
"responses": {
|
||||
"200": {
|
||||
"description": "OK",
|
||||
"schema": {
|
||||
"$ref": "#/definitions/codersdk.ExternalAPIKeyScopes"
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
},
|
||||
"/authcheck": {
|
||||
"post": {
|
||||
"security": [
|
||||
@@ -10021,8 +10037,74 @@
|
||||
},
|
||||
"codersdk.APIKeyScope": {
|
||||
"type": "string",
|
||||
"enum": ["all", "application_connect"],
|
||||
"x-enum-varnames": ["APIKeyScopeAll", "APIKeyScopeApplicationConnect"]
|
||||
"enum": [
|
||||
"all",
|
||||
"api_key:*",
|
||||
"api_key:create",
|
||||
"api_key:delete",
|
||||
"api_key:read",
|
||||
"api_key:update",
|
||||
"application_connect",
|
||||
"file:*",
|
||||
"file:create",
|
||||
"file:read",
|
||||
"template:*",
|
||||
"template:create",
|
||||
"template:delete",
|
||||
"template:read",
|
||||
"template:update",
|
||||
"template:use",
|
||||
"user:read_personal",
|
||||
"user:update_personal",
|
||||
"user_secret:*",
|
||||
"user_secret:create",
|
||||
"user_secret:delete",
|
||||
"user_secret:read",
|
||||
"user_secret:update",
|
||||
"workspace:*",
|
||||
"workspace:application_connect",
|
||||
"workspace:create",
|
||||
"workspace:delete",
|
||||
"workspace:read",
|
||||
"workspace:ssh",
|
||||
"workspace:start",
|
||||
"workspace:stop",
|
||||
"workspace:update"
|
||||
],
|
||||
"x-enum-varnames": [
|
||||
"APIKeyScopeAll",
|
||||
"APIKeyScopeApiKeyAll",
|
||||
"APIKeyScopeApiKeyCreate",
|
||||
"APIKeyScopeApiKeyDelete",
|
||||
"APIKeyScopeApiKeyRead",
|
||||
"APIKeyScopeApiKeyUpdate",
|
||||
"APIKeyScopeApplicationConnect",
|
||||
"APIKeyScopeFileAll",
|
||||
"APIKeyScopeFileCreate",
|
||||
"APIKeyScopeFileRead",
|
||||
"APIKeyScopeTemplateAll",
|
||||
"APIKeyScopeTemplateCreate",
|
||||
"APIKeyScopeTemplateDelete",
|
||||
"APIKeyScopeTemplateRead",
|
||||
"APIKeyScopeTemplateUpdate",
|
||||
"APIKeyScopeTemplateUse",
|
||||
"APIKeyScopeUserReadPersonal",
|
||||
"APIKeyScopeUserUpdatePersonal",
|
||||
"APIKeyScopeUserSecretAll",
|
||||
"APIKeyScopeUserSecretCreate",
|
||||
"APIKeyScopeUserSecretDelete",
|
||||
"APIKeyScopeUserSecretRead",
|
||||
"APIKeyScopeUserSecretUpdate",
|
||||
"APIKeyScopeWorkspaceAll",
|
||||
"APIKeyScopeWorkspaceApplicationConnect",
|
||||
"APIKeyScopeWorkspaceCreate",
|
||||
"APIKeyScopeWorkspaceDelete",
|
||||
"APIKeyScopeWorkspaceRead",
|
||||
"APIKeyScopeWorkspaceSsh",
|
||||
"APIKeyScopeWorkspaceStart",
|
||||
"APIKeyScopeWorkspaceStop",
|
||||
"APIKeyScopeWorkspaceUpdate"
|
||||
]
|
||||
},
|
||||
"codersdk.AddLicenseRequest": {
|
||||
"type": "object",
|
||||
@@ -11032,12 +11114,7 @@
|
||||
"type": "integer"
|
||||
},
|
||||
"scope": {
|
||||
"enum": ["all", "application_connect"],
|
||||
"allOf": [
|
||||
{
|
||||
"$ref": "#/definitions/codersdk.APIKeyScope"
|
||||
}
|
||||
]
|
||||
"$ref": "#/definitions/codersdk.APIKeyScope"
|
||||
},
|
||||
"token_name": {
|
||||
"type": "string"
|
||||
@@ -11863,6 +11940,17 @@
|
||||
"ExperimentAIBridge"
|
||||
]
|
||||
},
|
||||
"codersdk.ExternalAPIKeyScopes": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"external": {
|
||||
"type": "array",
|
||||
"items": {
|
||||
"$ref": "#/definitions/codersdk.APIKeyScope"
|
||||
}
|
||||
}
|
||||
}
|
||||
},
|
||||
"codersdk.ExternalAgentCredentials": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
|
||||
Reference in New Issue
Block a user