mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: Add initial AuthzQuerier implementation (#5919)
feat: Add initial AuthzQuerier implementation - Adds package database/dbauthz that adds a database.Store implementation where each method goes through AuthZ checks - Implements all database.Store methods on AuthzQuerier - Updates and fixes unit tests where required - Updates coderd initialization to use AuthzQuerier if codersdk.ExperimentAuthzQuerier is enabled
This commit is contained in:
+27
-1
@@ -1,6 +1,10 @@
|
||||
package rbac
|
||||
|
||||
import "github.com/open-policy-agent/opa/rego"
|
||||
import (
|
||||
"errors"
|
||||
|
||||
"github.com/open-policy-agent/opa/rego"
|
||||
)
|
||||
|
||||
const (
|
||||
// errUnauthorized is the error message that should be returned to
|
||||
@@ -24,6 +28,12 @@ type UnauthorizedError struct {
|
||||
output rego.ResultSet
|
||||
}
|
||||
|
||||
// IsUnauthorizedError is a convenience function to check if err is UnauthorizedError.
|
||||
// It is equivalent to errors.As(err, &UnauthorizedError{}).
|
||||
func IsUnauthorizedError(err error) bool {
|
||||
return errors.As(err, &UnauthorizedError{})
|
||||
}
|
||||
|
||||
// ForbiddenWithInternal creates a new error that will return a simple
|
||||
// "forbidden" to the client, logging internally the more detailed message
|
||||
// provided.
|
||||
@@ -37,6 +47,10 @@ func ForbiddenWithInternal(internal error, subject Subject, action Action, objec
|
||||
}
|
||||
}
|
||||
|
||||
func (e UnauthorizedError) Unwrap() error {
|
||||
return e.internal
|
||||
}
|
||||
|
||||
// Error implements the error interface.
|
||||
func (UnauthorizedError) Error() string {
|
||||
return errUnauthorized
|
||||
@@ -47,6 +61,10 @@ func (e *UnauthorizedError) Internal() error {
|
||||
return e.internal
|
||||
}
|
||||
|
||||
func (e *UnauthorizedError) SetInternal(err error) {
|
||||
e.internal = err
|
||||
}
|
||||
|
||||
func (e *UnauthorizedError) Input() map[string]interface{} {
|
||||
return map[string]interface{}{
|
||||
"subject": e.subject,
|
||||
@@ -59,3 +77,11 @@ func (e *UnauthorizedError) Input() map[string]interface{} {
|
||||
func (e *UnauthorizedError) Output() rego.ResultSet {
|
||||
return e.output
|
||||
}
|
||||
|
||||
// As implements the errors.As interface.
|
||||
func (*UnauthorizedError) As(target interface{}) bool {
|
||||
if _, ok := target.(*UnauthorizedError); ok {
|
||||
return true
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user