mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore: remove organization_id suffix from org_member roles in database (#13473)
Organization member's table is already scoped to an organization. Rolename should avoid having the org_id appended. Wipes all existing organization role assignments, which should not be used anyway.
This commit is contained in:
@@ -153,7 +153,7 @@ func TestUpsertCustomRoles(t *testing.T) {
|
||||
UUID: uuid.New(),
|
||||
Valid: true,
|
||||
},
|
||||
subject: merge(canAssignRole, rbac.RoleOrgAdmin(orgID.UUID)),
|
||||
subject: merge(canAssignRole, rbac.ScopedRoleOrgAdmin(orgID.UUID)),
|
||||
org: codersdk.CreatePermissions(map[codersdk.RBACResource][]codersdk.RBACAction{
|
||||
codersdk.ResourceWorkspace: {codersdk.ActionRead},
|
||||
}),
|
||||
@@ -162,7 +162,7 @@ func TestUpsertCustomRoles(t *testing.T) {
|
||||
{
|
||||
name: "user-escalation",
|
||||
// These roles do not grant user perms
|
||||
subject: merge(canAssignRole, rbac.RoleOrgAdmin(orgID.UUID)),
|
||||
subject: merge(canAssignRole, rbac.ScopedRoleOrgAdmin(orgID.UUID)),
|
||||
user: codersdk.CreatePermissions(map[codersdk.RBACResource][]codersdk.RBACAction{
|
||||
codersdk.ResourceWorkspace: {codersdk.ActionRead},
|
||||
}),
|
||||
@@ -190,7 +190,7 @@ func TestUpsertCustomRoles(t *testing.T) {
|
||||
},
|
||||
{
|
||||
name: "read-workspace-in-org",
|
||||
subject: merge(canAssignRole, rbac.RoleOrgAdmin(orgID.UUID)),
|
||||
subject: merge(canAssignRole, rbac.ScopedRoleOrgAdmin(orgID.UUID)),
|
||||
organizationID: orgID,
|
||||
org: codersdk.CreatePermissions(map[codersdk.RBACResource][]codersdk.RBACAction{
|
||||
codersdk.ResourceWorkspace: {codersdk.ActionRead},
|
||||
|
||||
@@ -2472,7 +2472,7 @@ func (q *querier) InsertOrganization(ctx context.Context, arg database.InsertOrg
|
||||
|
||||
func (q *querier) InsertOrganizationMember(ctx context.Context, arg database.InsertOrganizationMemberParams) (database.OrganizationMember, error) {
|
||||
// All roles are added roles. Org member is always implied.
|
||||
addedRoles := append(arg.Roles, rbac.RoleOrgMember(arg.OrganizationID))
|
||||
addedRoles := append(arg.Roles, rbac.ScopedRoleOrgMember(arg.OrganizationID))
|
||||
err := q.canAssignRoles(ctx, &arg.OrganizationID, addedRoles, []string{})
|
||||
if err != nil {
|
||||
return database.OrganizationMember{}, err
|
||||
@@ -2847,8 +2847,22 @@ func (q *querier) UpdateMemberRoles(ctx context.Context, arg database.UpdateMemb
|
||||
return database.OrganizationMember{}, err
|
||||
}
|
||||
|
||||
// The 'rbac' package expects role names to be scoped.
|
||||
// Convert the argument roles for validation.
|
||||
scopedGranted := make([]string, 0, len(arg.GrantedRoles))
|
||||
for _, grantedRole := range arg.GrantedRoles {
|
||||
// This check is a developer safety check. Old code might try to invoke this code path with
|
||||
// organization id suffixes. Catch this and return a nice error so it can be fixed.
|
||||
_, foundOrg, _ := rbac.RoleSplit(grantedRole)
|
||||
if foundOrg != "" {
|
||||
return database.OrganizationMember{}, xerrors.Errorf("attempt to assign a role %q, remove the ':<organization_id> suffix", grantedRole)
|
||||
}
|
||||
|
||||
scopedGranted = append(scopedGranted, rbac.RoleName(grantedRole, arg.OrgID.String()))
|
||||
}
|
||||
|
||||
// The org member role is always implied.
|
||||
impliedTypes := append(arg.GrantedRoles, rbac.RoleOrgMember(arg.OrgID))
|
||||
impliedTypes := append(scopedGranted, rbac.ScopedRoleOrgMember(arg.OrgID))
|
||||
added, removed := rbac.ChangeRoleSet(member.Roles, impliedTypes)
|
||||
err = q.canAssignRoles(ctx, &arg.OrgID, added, removed)
|
||||
if err != nil {
|
||||
|
||||
@@ -636,7 +636,7 @@ func (s *MethodTestSuite) TestOrganization() {
|
||||
check.Args(database.InsertOrganizationMemberParams{
|
||||
OrganizationID: o.ID,
|
||||
UserID: u.ID,
|
||||
Roles: []string{rbac.RoleOrgAdmin(o.ID)},
|
||||
Roles: []string{rbac.ScopedRoleOrgAdmin(o.ID)},
|
||||
}).Asserts(
|
||||
rbac.ResourceAssignRole.InOrg(o.ID), policy.ActionAssign,
|
||||
rbac.ResourceOrganizationMember.InOrg(o.ID).WithID(u.ID), policy.ActionCreate)
|
||||
@@ -664,7 +664,7 @@ func (s *MethodTestSuite) TestOrganization() {
|
||||
mem := dbgen.OrganizationMember(s.T(), db, database.OrganizationMember{
|
||||
OrganizationID: o.ID,
|
||||
UserID: u.ID,
|
||||
Roles: []string{rbac.RoleOrgAdmin(o.ID)},
|
||||
Roles: []string{rbac.ScopedRoleOrgAdmin(o.ID)},
|
||||
})
|
||||
out := mem
|
||||
out.Roles = []string{}
|
||||
|
||||
Reference in New Issue
Block a user