mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add external API key scopes (#19916)
# Add support for low-level API key scopes This PR adds support for fine-grained API key scopes based on RBAC resource:action pairs. It includes: 1. A new endpoint `/api/v2/auth/scopes` to list all public low-level API key scopes 2. Generated constants in the SDK for all public scopes 3. Tests to verify scope validation during token creation 4. Updated API documentation to reflect the expanded scope options The implementation allows users to create API keys with specific permissions like `workspace:read` or `template:use` instead of only the legacy `all` or `application_connect` scopes. Fixes #19847
This commit is contained in:
Generated
+30
@@ -1,5 +1,35 @@
|
||||
# Authorization
|
||||
|
||||
## List API key scopes
|
||||
|
||||
### Code samples
|
||||
|
||||
```shell
|
||||
# Example request using curl
|
||||
curl -X GET http://coder-server:8080/api/v2/auth/scopes \
|
||||
-H 'Accept: application/json'
|
||||
```
|
||||
|
||||
`GET /auth/scopes`
|
||||
|
||||
### Example responses
|
||||
|
||||
> 200 Response
|
||||
|
||||
```json
|
||||
{
|
||||
"external": [
|
||||
"all"
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
### Responses
|
||||
|
||||
| Status | Meaning | Description | Schema |
|
||||
|--------|---------------------------------------------------------|-------------|--------------------------------------------------------------------------|
|
||||
| 200 | [OK](https://tools.ietf.org/html/rfc7231#section-6.3.1) | OK | [codersdk.ExternalAPIKeyScopes](schemas.md#codersdkexternalapikeyscopes) |
|
||||
|
||||
## Check authorization
|
||||
|
||||
### Code samples
|
||||
|
||||
Generated
+50
-11
@@ -468,10 +468,40 @@
|
||||
|
||||
#### Enumerated Values
|
||||
|
||||
| Value |
|
||||
|-----------------------|
|
||||
| `all` |
|
||||
| `application_connect` |
|
||||
| Value |
|
||||
|---------------------------------|
|
||||
| `all` |
|
||||
| `api_key:*` |
|
||||
| `api_key:create` |
|
||||
| `api_key:delete` |
|
||||
| `api_key:read` |
|
||||
| `api_key:update` |
|
||||
| `application_connect` |
|
||||
| `file:*` |
|
||||
| `file:create` |
|
||||
| `file:read` |
|
||||
| `template:*` |
|
||||
| `template:create` |
|
||||
| `template:delete` |
|
||||
| `template:read` |
|
||||
| `template:update` |
|
||||
| `template:use` |
|
||||
| `user:read_personal` |
|
||||
| `user:update_personal` |
|
||||
| `user_secret:*` |
|
||||
| `user_secret:create` |
|
||||
| `user_secret:delete` |
|
||||
| `user_secret:read` |
|
||||
| `user_secret:update` |
|
||||
| `workspace:*` |
|
||||
| `workspace:application_connect` |
|
||||
| `workspace:create` |
|
||||
| `workspace:delete` |
|
||||
| `workspace:read` |
|
||||
| `workspace:ssh` |
|
||||
| `workspace:start` |
|
||||
| `workspace:stop` |
|
||||
| `workspace:update` |
|
||||
|
||||
## codersdk.AddLicenseRequest
|
||||
|
||||
@@ -1756,13 +1786,6 @@ This is required on creation to enable a user-flow of validating a template work
|
||||
| `scope` | [codersdk.APIKeyScope](#codersdkapikeyscope) | false | | |
|
||||
| `token_name` | string | false | | |
|
||||
|
||||
#### Enumerated Values
|
||||
|
||||
| Property | Value |
|
||||
|----------|-----------------------|
|
||||
| `scope` | `all` |
|
||||
| `scope` | `application_connect` |
|
||||
|
||||
## codersdk.CreateUserRequestWithOrgs
|
||||
|
||||
```json
|
||||
@@ -3489,6 +3512,22 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
|
||||
| `workspace-sharing` |
|
||||
| `aibridge` |
|
||||
|
||||
## codersdk.ExternalAPIKeyScopes
|
||||
|
||||
```json
|
||||
{
|
||||
"external": [
|
||||
"all"
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
### Properties
|
||||
|
||||
| Name | Type | Required | Restrictions | Description |
|
||||
|------------|-------------------------------------------------------|----------|--------------|-------------|
|
||||
| `external` | array of [codersdk.APIKeyScope](#codersdkapikeyscope) | false | | |
|
||||
|
||||
## codersdk.ExternalAgentCredentials
|
||||
|
||||
```json
|
||||
|
||||
Reference in New Issue
Block a user