mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore: create type for unique role names (#13506)
* chore: create type for unique role names Using `string` was confusing when something should be combined with org context, and when not to. Naming this new name, "RoleIdentifier"
This commit is contained in:
@@ -39,14 +39,14 @@ func roleCache(ctx context.Context) *syncmap.Map[string, rbac.Role] {
|
||||
}
|
||||
|
||||
// Expand will expand built in roles, and fetch custom roles from the database.
|
||||
func Expand(ctx context.Context, db database.Store, names []string) (rbac.Roles, error) {
|
||||
func Expand(ctx context.Context, db database.Store, names []rbac.RoleIdentifier) (rbac.Roles, error) {
|
||||
if len(names) == 0 {
|
||||
// That was easy
|
||||
return []rbac.Role{}, nil
|
||||
}
|
||||
|
||||
cache := roleCache(ctx)
|
||||
lookup := make([]string, 0)
|
||||
lookup := make([]rbac.RoleIdentifier, 0)
|
||||
roles := make([]rbac.Role, 0, len(names))
|
||||
|
||||
for _, name := range names {
|
||||
@@ -58,7 +58,7 @@ func Expand(ctx context.Context, db database.Store, names []string) (rbac.Roles,
|
||||
}
|
||||
|
||||
// Check custom role cache
|
||||
customRole, ok := cache.Load(name)
|
||||
customRole, ok := cache.Load(name.String())
|
||||
if ok {
|
||||
roles = append(roles, customRole)
|
||||
continue
|
||||
@@ -69,26 +69,11 @@ func Expand(ctx context.Context, db database.Store, names []string) (rbac.Roles,
|
||||
}
|
||||
|
||||
if len(lookup) > 0 {
|
||||
// The set of roles coming in are formatted as 'rolename[:<org_id>]'.
|
||||
// In the database, org roles are scoped with an organization column.
|
||||
lookupArgs := make([]database.NameOrganizationPair, 0, len(lookup))
|
||||
for _, name := range lookup {
|
||||
roleName, orgID, err := rbac.RoleSplit(name)
|
||||
if err != nil {
|
||||
continue
|
||||
}
|
||||
|
||||
parsedOrgID := uuid.Nil // Default to no org ID
|
||||
if orgID != "" {
|
||||
parsedOrgID, err = uuid.Parse(orgID)
|
||||
if err != nil {
|
||||
continue
|
||||
}
|
||||
}
|
||||
|
||||
lookupArgs = append(lookupArgs, database.NameOrganizationPair{
|
||||
Name: roleName,
|
||||
OrganizationID: parsedOrgID,
|
||||
Name: name.Name,
|
||||
OrganizationID: name.OrganizationID,
|
||||
})
|
||||
}
|
||||
|
||||
@@ -111,7 +96,7 @@ func Expand(ctx context.Context, db database.Store, names []string) (rbac.Roles,
|
||||
return nil, xerrors.Errorf("convert db role %q: %w", dbrole.Name, err)
|
||||
}
|
||||
roles = append(roles, converted)
|
||||
cache.Store(dbrole.Name, converted)
|
||||
cache.Store(dbrole.RoleIdentifier().String(), converted)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -133,12 +118,8 @@ func convertPermissions(dbPerms []database.CustomRolePermission) []rbac.Permissi
|
||||
// ConvertDBRole should not be used by any human facing apis. It is used
|
||||
// for authz purposes.
|
||||
func ConvertDBRole(dbRole database.CustomRole) (rbac.Role, error) {
|
||||
name := dbRole.Name
|
||||
if dbRole.OrganizationID.Valid {
|
||||
name = rbac.RoleName(dbRole.Name, dbRole.OrganizationID.UUID.String())
|
||||
}
|
||||
role := rbac.Role{
|
||||
Name: name,
|
||||
Identifier: dbRole.RoleIdentifier(),
|
||||
DisplayName: dbRole.DisplayName,
|
||||
Site: convertPermissions(dbRole.SitePermissions),
|
||||
Org: nil,
|
||||
|
||||
@@ -35,7 +35,7 @@ func TestExpandCustomRoleRoles(t *testing.T) {
|
||||
})
|
||||
|
||||
ctx := testutil.Context(t, testutil.WaitShort)
|
||||
roles, err := rolestore.Expand(ctx, db, []string{rbac.RoleName(roleName, org.ID.String())})
|
||||
roles, err := rolestore.Expand(ctx, db, []rbac.RoleIdentifier{{Name: roleName, OrganizationID: org.ID}})
|
||||
require.NoError(t, err)
|
||||
require.Len(t, roles, 1, "role found")
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user