mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore: create type for unique role names (#13506)
* chore: create type for unique role names Using `string` was confusing when something should be combined with org context, and when not to. Naming this new name, "RoleIdentifier"
This commit is contained in:
@@ -496,7 +496,7 @@ func (api *API) writeEntitlementWarningsHeader(a rbac.Subject, header http.Heade
|
||||
// The member role is implied, and not assignable.
|
||||
// If there is no display name, then the role is also unassigned.
|
||||
// This is not the ideal logic, but works for now.
|
||||
if role.Name == rbac.RoleMember() || (role.DisplayName == "") {
|
||||
if role.Identifier == rbac.RoleMember() || (role.DisplayName == "") {
|
||||
continue
|
||||
}
|
||||
nonMemberRoles++
|
||||
|
||||
@@ -497,7 +497,7 @@ func testDBAuthzRole(ctx context.Context) context.Context {
|
||||
ID: uuid.Nil.String(),
|
||||
Roles: rbac.Roles([]rbac.Role{
|
||||
{
|
||||
Name: "testing",
|
||||
Identifier: rbac.RoleIdentifier{Name: "testing"},
|
||||
DisplayName: "Unit Tests",
|
||||
Site: rbac.Permissions(map[string][]policy.Action{
|
||||
rbac.ResourceWildcard.Type: {policy.WildcardSymbol},
|
||||
|
||||
@@ -78,15 +78,15 @@ func TestTemplateInsightsWithRole(t *testing.T) {
|
||||
|
||||
type test struct {
|
||||
interval codersdk.InsightsReportInterval
|
||||
role string
|
||||
role rbac.RoleIdentifier
|
||||
allowed bool
|
||||
}
|
||||
|
||||
tests := []test{
|
||||
{codersdk.InsightsReportIntervalDay, rbac.RoleTemplateAdmin(), true},
|
||||
{"", rbac.RoleTemplateAdmin(), true},
|
||||
{codersdk.InsightsReportIntervalDay, "auditor", true},
|
||||
{"", "auditor", true},
|
||||
{codersdk.InsightsReportIntervalDay, rbac.RoleAuditor(), true},
|
||||
{"", rbac.RoleAuditor(), true},
|
||||
{codersdk.InsightsReportIntervalDay, rbac.RoleUserAdmin(), false},
|
||||
{"", rbac.RoleUserAdmin(), false},
|
||||
{codersdk.InsightsReportIntervalDay, rbac.RoleMember(), false},
|
||||
|
||||
@@ -9,6 +9,7 @@ import (
|
||||
"github.com/stretchr/testify/require"
|
||||
|
||||
"github.com/coder/coder/v2/coderd/coderdtest"
|
||||
"github.com/coder/coder/v2/coderd/rbac"
|
||||
"github.com/coder/coder/v2/codersdk"
|
||||
"github.com/coder/coder/v2/enterprise/coderd/coderdenttest"
|
||||
"github.com/coder/coder/v2/enterprise/coderd/license"
|
||||
@@ -57,7 +58,7 @@ func TestCustomOrganizationRole(t *testing.T) {
|
||||
require.NoError(t, err, "upsert role")
|
||||
|
||||
// Assign the custom template admin role
|
||||
tmplAdmin, _ := coderdtest.CreateAnotherUser(t, owner, first.OrganizationID, role.FullName())
|
||||
tmplAdmin, _ := coderdtest.CreateAnotherUser(t, owner, first.OrganizationID, rbac.RoleIdentifier{Name: role.Name, OrganizationID: first.OrganizationID})
|
||||
|
||||
// Assert the role exists
|
||||
// TODO: At present user roles are not returned by the user endpoints.
|
||||
@@ -124,7 +125,7 @@ func TestCustomOrganizationRole(t *testing.T) {
|
||||
require.ErrorContains(t, err, "roles are not enabled")
|
||||
|
||||
// Assign the custom template admin role
|
||||
tmplAdmin, _ := coderdtest.CreateAnotherUser(t, owner, first.OrganizationID, role.FullName())
|
||||
tmplAdmin, _ := coderdtest.CreateAnotherUser(t, owner, first.OrganizationID, rbac.RoleIdentifier{Name: role.Name, OrganizationID: first.OrganizationID})
|
||||
|
||||
// Try to create a template version, eg using the custom role
|
||||
coderdtest.CreateTemplateVersion(t, tmplAdmin, first.OrganizationID, nil)
|
||||
@@ -152,7 +153,7 @@ func TestCustomOrganizationRole(t *testing.T) {
|
||||
require.NoError(t, err, "upsert role")
|
||||
|
||||
// Assign the custom template admin role
|
||||
tmplAdmin, _ := coderdtest.CreateAnotherUser(t, owner, first.OrganizationID, role.FullName())
|
||||
tmplAdmin, _ := coderdtest.CreateAnotherUser(t, owner, first.OrganizationID, rbac.RoleIdentifier{Name: role.Name, OrganizationID: first.OrganizationID})
|
||||
|
||||
// Try to create a template version, eg using the custom role
|
||||
coderdtest.CreateTemplateVersion(t, tmplAdmin, first.OrganizationID, nil)
|
||||
|
||||
@@ -66,7 +66,7 @@ func TestUserOIDC(t *testing.T) {
|
||||
cfg.AllowSignups = true
|
||||
cfg.UserRoleField = "roles"
|
||||
cfg.UserRoleMapping = map[string][]string{
|
||||
oidcRoleName: {rbac.RoleTemplateAdmin()},
|
||||
oidcRoleName: {rbac.RoleTemplateAdmin().String()},
|
||||
}
|
||||
},
|
||||
})
|
||||
@@ -79,7 +79,7 @@ func TestUserOIDC(t *testing.T) {
|
||||
"roles": oidcRoleName,
|
||||
})
|
||||
require.Equal(t, http.StatusOK, resp.StatusCode)
|
||||
runner.AssertRoles(t, "alice", []string{rbac.RoleTemplateAdmin()})
|
||||
runner.AssertRoles(t, "alice", []string{rbac.RoleTemplateAdmin().String()})
|
||||
})
|
||||
|
||||
// A user has some roles, then on an oauth refresh will lose said
|
||||
@@ -92,12 +92,12 @@ func TestUserOIDC(t *testing.T) {
|
||||
|
||||
const oidcRoleName = "TemplateAuthor"
|
||||
runner := setupOIDCTest(t, oidcTestConfig{
|
||||
Userinfo: jwt.MapClaims{oidcRoleName: []string{rbac.RoleTemplateAdmin(), rbac.RoleUserAdmin()}},
|
||||
Userinfo: jwt.MapClaims{oidcRoleName: []string{rbac.RoleTemplateAdmin().String(), rbac.RoleUserAdmin().String()}},
|
||||
Config: func(cfg *coderd.OIDCConfig) {
|
||||
cfg.AllowSignups = true
|
||||
cfg.UserRoleField = "roles"
|
||||
cfg.UserRoleMapping = map[string][]string{
|
||||
oidcRoleName: {rbac.RoleTemplateAdmin(), rbac.RoleUserAdmin()},
|
||||
oidcRoleName: {rbac.RoleTemplateAdmin().String(), rbac.RoleUserAdmin().String()},
|
||||
}
|
||||
},
|
||||
})
|
||||
@@ -105,10 +105,10 @@ func TestUserOIDC(t *testing.T) {
|
||||
// User starts with the owner role
|
||||
client, resp := runner.Login(t, jwt.MapClaims{
|
||||
"email": "alice@coder.com",
|
||||
"roles": []string{"random", oidcRoleName, rbac.RoleOwner()},
|
||||
"roles": []string{"random", oidcRoleName, rbac.RoleOwner().String()},
|
||||
})
|
||||
require.Equal(t, http.StatusOK, resp.StatusCode)
|
||||
runner.AssertRoles(t, "alice", []string{rbac.RoleTemplateAdmin(), rbac.RoleUserAdmin(), rbac.RoleOwner()})
|
||||
runner.AssertRoles(t, "alice", []string{rbac.RoleTemplateAdmin().String(), rbac.RoleUserAdmin().String(), rbac.RoleOwner().String()})
|
||||
|
||||
// Now refresh the oauth, and check the roles are removed.
|
||||
// Force a refresh, and assert nothing has changes
|
||||
@@ -126,12 +126,12 @@ func TestUserOIDC(t *testing.T) {
|
||||
|
||||
const oidcRoleName = "TemplateAuthor"
|
||||
runner := setupOIDCTest(t, oidcTestConfig{
|
||||
Userinfo: jwt.MapClaims{oidcRoleName: []string{rbac.RoleTemplateAdmin(), rbac.RoleUserAdmin()}},
|
||||
Userinfo: jwt.MapClaims{oidcRoleName: []string{rbac.RoleTemplateAdmin().String(), rbac.RoleUserAdmin().String()}},
|
||||
Config: func(cfg *coderd.OIDCConfig) {
|
||||
cfg.AllowSignups = true
|
||||
cfg.UserRoleField = "roles"
|
||||
cfg.UserRoleMapping = map[string][]string{
|
||||
oidcRoleName: {rbac.RoleTemplateAdmin(), rbac.RoleUserAdmin()},
|
||||
oidcRoleName: {rbac.RoleTemplateAdmin().String(), rbac.RoleUserAdmin().String()},
|
||||
}
|
||||
},
|
||||
})
|
||||
@@ -139,10 +139,10 @@ func TestUserOIDC(t *testing.T) {
|
||||
// User starts with the owner role
|
||||
_, resp := runner.Login(t, jwt.MapClaims{
|
||||
"email": "alice@coder.com",
|
||||
"roles": []string{"random", oidcRoleName, rbac.RoleOwner()},
|
||||
"roles": []string{"random", oidcRoleName, rbac.RoleOwner().String()},
|
||||
})
|
||||
require.Equal(t, http.StatusOK, resp.StatusCode)
|
||||
runner.AssertRoles(t, "alice", []string{rbac.RoleTemplateAdmin(), rbac.RoleUserAdmin(), rbac.RoleOwner()})
|
||||
runner.AssertRoles(t, "alice", []string{rbac.RoleTemplateAdmin().String(), rbac.RoleUserAdmin().String(), rbac.RoleOwner().String()})
|
||||
|
||||
// Now login with oauth again, and check the roles are removed.
|
||||
_, resp = runner.Login(t, jwt.MapClaims{
|
||||
@@ -175,7 +175,7 @@ func TestUserOIDC(t *testing.T) {
|
||||
ctx := testutil.Context(t, testutil.WaitShort)
|
||||
_, err := runner.AdminClient.UpdateUserRoles(ctx, "alice", codersdk.UpdateRoles{
|
||||
Roles: []string{
|
||||
rbac.RoleTemplateAdmin(),
|
||||
rbac.RoleTemplateAdmin().String(),
|
||||
},
|
||||
})
|
||||
require.Error(t, err)
|
||||
|
||||
Reference in New Issue
Block a user