feat: scope allow_list to include resource_type (#19748)

This feature allows the `allow_list` in the scopes to specify the `type`
This commit is contained in:
Steven Masley
2025-09-17 08:32:14 -05:00
committed by GitHub
parent 3df9d8e902
commit 679179f404
6 changed files with 203 additions and 24 deletions
+17 -1
View File
@@ -182,9 +182,25 @@ func (s Scope) regoValue() ast.Value {
if !ok {
panic("developer error: role is not an object")
}
terms := make([]*ast.Term, len(s.AllowIDList))
for i, v := range s.AllowIDList {
terms[i] = ast.NewTerm(ast.NewObject(
[2]*ast.Term{
ast.StringTerm("type"),
ast.StringTerm(v.Type),
},
[2]*ast.Term{
ast.StringTerm("id"),
ast.StringTerm(v.ID),
},
),
)
}
r.Insert(
ast.StringTerm("allow_list"),
ast.NewTerm(regoSliceString(s.AllowIDList...)),
ast.NewTerm(ast.NewArray(terms...)),
)
return r
}