feat: implement composite API key scopes for workspaces and templates (#19945)

# Add Composite API Key Scopes

This PR adds high-level composite API key scopes to simplify token creation with common permission sets:

- `coder:workspaces.create` - Create and update workspaces
- `coder:workspaces.operate` - Read and update workspaces
- `coder:workspaces.delete` - Read and delete workspaces
- `coder:workspaces.access` - Read, SSH, and connect to workspace applications
- `coder:templates.build` - Read templates and create/read files
- `coder:templates.author` - Full template management with insights
- `coder:apikeys.manage_self` - Manage your own API keys

These composite scopes are persisted in the database and expanded during authorization, providing a more intuitive way to grant permissions compared to the granular resource:action scopes.
This commit is contained in:
Thomas Kosiewski
2025-09-29 13:17:08 +02:00
committed by GitHub
parent 860bcd4d91
commit 79126ab6c7
18 changed files with 267 additions and 7 deletions
+22 -1
View File
@@ -159,6 +159,13 @@ const (
ApiKeyScopeWorkspaceProxyDelete APIKeyScope = "workspace_proxy:delete"
ApiKeyScopeWorkspaceProxyRead APIKeyScope = "workspace_proxy:read"
ApiKeyScopeWorkspaceProxyUpdate APIKeyScope = "workspace_proxy:update"
ApiKeyScopeCoderWorkspacescreate APIKeyScope = "coder:workspaces.create"
ApiKeyScopeCoderWorkspacesoperate APIKeyScope = "coder:workspaces.operate"
ApiKeyScopeCoderWorkspacesdelete APIKeyScope = "coder:workspaces.delete"
ApiKeyScopeCoderWorkspacesaccess APIKeyScope = "coder:workspaces.access"
ApiKeyScopeCoderTemplatesbuild APIKeyScope = "coder:templates.build"
ApiKeyScopeCoderTemplatesauthor APIKeyScope = "coder:templates.author"
ApiKeyScopeCoderApikeysmanageSelf APIKeyScope = "coder:apikeys.manage_self"
)
func (e *APIKeyScope) Scan(src interface{}) error {
@@ -337,7 +344,14 @@ func (e APIKeyScope) Valid() bool {
ApiKeyScopeWorkspaceProxyCreate,
ApiKeyScopeWorkspaceProxyDelete,
ApiKeyScopeWorkspaceProxyRead,
ApiKeyScopeWorkspaceProxyUpdate:
ApiKeyScopeWorkspaceProxyUpdate,
ApiKeyScopeCoderWorkspacescreate,
ApiKeyScopeCoderWorkspacesoperate,
ApiKeyScopeCoderWorkspacesdelete,
ApiKeyScopeCoderWorkspacesaccess,
ApiKeyScopeCoderTemplatesbuild,
ApiKeyScopeCoderTemplatesauthor,
ApiKeyScopeCoderApikeysmanageSelf:
return true
}
return false
@@ -485,6 +499,13 @@ func AllAPIKeyScopeValues() []APIKeyScope {
ApiKeyScopeWorkspaceProxyDelete,
ApiKeyScopeWorkspaceProxyRead,
ApiKeyScopeWorkspaceProxyUpdate,
ApiKeyScopeCoderWorkspacescreate,
ApiKeyScopeCoderWorkspacesoperate,
ApiKeyScopeCoderWorkspacesdelete,
ApiKeyScopeCoderWorkspacesaccess,
ApiKeyScopeCoderTemplatesbuild,
ApiKeyScopeCoderTemplatesauthor,
ApiKeyScopeCoderApikeysmanageSelf,
}
}