mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: Check permissions endpoint (#1389)
* feat: Check permissions endpoint Allows FE to query backend for permission capabilities. Batch requests supported
This commit is contained in:
+86
-13
@@ -12,6 +12,91 @@ import (
|
||||
"github.com/coder/coder/codersdk"
|
||||
)
|
||||
|
||||
func TestPermissionCheck(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
client := coderdtest.New(t, nil)
|
||||
// Create admin, member, and org admin
|
||||
admin := coderdtest.CreateFirstUser(t, client)
|
||||
member := coderdtest.CreateAnotherUser(t, client, admin.OrganizationID)
|
||||
orgAdmin := coderdtest.CreateAnotherUser(t, client, admin.OrganizationID, rbac.RoleOrgAdmin(admin.OrganizationID))
|
||||
|
||||
// With admin, member, and org admin
|
||||
const (
|
||||
allUsers = "read-all-users"
|
||||
readOrgWorkspaces = "read-org-workspaces"
|
||||
myself = "read-myself"
|
||||
myWorkspace = "read-my-workspace"
|
||||
)
|
||||
params := map[string]codersdk.UserPermissionCheck{
|
||||
allUsers: {
|
||||
Object: codersdk.UserPermissionCheckObject{
|
||||
ResourceType: "users",
|
||||
},
|
||||
Action: "read",
|
||||
},
|
||||
myself: {
|
||||
Object: codersdk.UserPermissionCheckObject{
|
||||
ResourceType: "users",
|
||||
OwnerID: "me",
|
||||
},
|
||||
Action: "read",
|
||||
},
|
||||
myWorkspace: {
|
||||
Object: codersdk.UserPermissionCheckObject{
|
||||
ResourceType: "workspaces",
|
||||
OwnerID: "me",
|
||||
},
|
||||
Action: "read",
|
||||
},
|
||||
readOrgWorkspaces: {
|
||||
Object: codersdk.UserPermissionCheckObject{
|
||||
ResourceType: "workspaces",
|
||||
OrganizationID: admin.OrganizationID.String(),
|
||||
},
|
||||
Action: "read",
|
||||
},
|
||||
}
|
||||
|
||||
testCases := []struct {
|
||||
Name string
|
||||
Client *codersdk.Client
|
||||
Check codersdk.UserPermissionCheckResponse
|
||||
}{
|
||||
{
|
||||
Name: "Admin",
|
||||
Client: client,
|
||||
Check: map[string]bool{
|
||||
allUsers: true, myself: true, myWorkspace: true, readOrgWorkspaces: true,
|
||||
},
|
||||
},
|
||||
{
|
||||
Name: "Member",
|
||||
Client: member,
|
||||
Check: map[string]bool{
|
||||
allUsers: false, myself: true, myWorkspace: true, readOrgWorkspaces: false,
|
||||
},
|
||||
},
|
||||
{
|
||||
Name: "OrgAdmin",
|
||||
Client: orgAdmin,
|
||||
Check: map[string]bool{
|
||||
allUsers: false, myself: true, myWorkspace: true, readOrgWorkspaces: true,
|
||||
},
|
||||
},
|
||||
}
|
||||
|
||||
for _, c := range testCases {
|
||||
c := c
|
||||
t.Run(c.Name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
resp, err := c.Client.CheckPermissions(context.Background(), codersdk.UserPermissionCheckRequest{Checks: params})
|
||||
require.NoError(t, err, "check perms")
|
||||
require.Equal(t, resp, c.Check)
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestListRoles(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
@@ -20,19 +105,7 @@ func TestListRoles(t *testing.T) {
|
||||
// Create admin, member, and org admin
|
||||
admin := coderdtest.CreateFirstUser(t, client)
|
||||
member := coderdtest.CreateAnotherUser(t, client, admin.OrganizationID)
|
||||
|
||||
orgAdmin := coderdtest.CreateAnotherUser(t, client, admin.OrganizationID)
|
||||
orgAdminUser, err := orgAdmin.User(ctx, codersdk.Me)
|
||||
require.NoError(t, err)
|
||||
|
||||
// TODO: @emyrk switch this to the admin when getting non-personal users is
|
||||
// supported. `client.UpdateOrganizationMemberRoles(...)`
|
||||
_, err = orgAdmin.UpdateOrganizationMemberRoles(ctx, admin.OrganizationID, orgAdminUser.ID,
|
||||
codersdk.UpdateRoles{
|
||||
Roles: []string{rbac.RoleOrgMember(admin.OrganizationID), rbac.RoleOrgAdmin(admin.OrganizationID)},
|
||||
},
|
||||
)
|
||||
require.NoError(t, err, "update org member roles")
|
||||
orgAdmin := coderdtest.CreateAnotherUser(t, client, admin.OrganizationID, rbac.RoleOrgAdmin(admin.OrganizationID))
|
||||
|
||||
otherOrg, err := client.CreateOrganization(ctx, admin.UserID, codersdk.CreateOrganizationRequest{
|
||||
Name: "other",
|
||||
|
||||
Reference in New Issue
Block a user