mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
fix: adjust build state permission to require template update (#6472)
This commit is contained in:
@@ -132,8 +132,8 @@ func AGPLRoutes(a *AuthTester) (map[string]string, map[string]RouteCheck) {
|
|||||||
AssertObject: workspaceRBACObj,
|
AssertObject: workspaceRBACObj,
|
||||||
},
|
},
|
||||||
"GET:/api/v2/workspacebuilds/{workspacebuild}/state": {
|
"GET:/api/v2/workspacebuilds/{workspacebuild}/state": {
|
||||||
AssertAction: rbac.ActionRead,
|
AssertAction: rbac.ActionUpdate,
|
||||||
AssertObject: workspaceRBACObj,
|
AssertObject: templateObj,
|
||||||
},
|
},
|
||||||
"GET:/api/v2/workspaceagents/{workspaceagent}": {
|
"GET:/api/v2/workspaceagents/{workspaceagent}": {
|
||||||
AssertAction: rbac.ActionRead,
|
AssertAction: rbac.ActionRead,
|
||||||
|
|||||||
@@ -892,8 +892,18 @@ func (api *API) workspaceBuildState(rw http.ResponseWriter, r *http.Request) {
|
|||||||
})
|
})
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
template, err := api.Database.GetTemplateByID(ctx, workspace.TemplateID)
|
||||||
|
if err != nil {
|
||||||
|
httpapi.Write(ctx, rw, http.StatusInternalServerError, codersdk.Response{
|
||||||
|
Message: "Failed to get template",
|
||||||
|
Detail: err.Error(),
|
||||||
|
})
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
if !api.Authorize(r, rbac.ActionRead, workspace) {
|
// You must have update permissions on the template to get the state.
|
||||||
|
// This matches a push!
|
||||||
|
if !api.Authorize(r, rbac.ActionUpdate, template.RBACObject()) {
|
||||||
httpapi.ResourceNotFound(rw)
|
httpapi.ResourceNotFound(rw)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user