mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add service_accounts workspace sharing mode (#23093)
Introduce a three-way workspace sharing setting (none, everyone, service_accounts) replacing the boolean workspace_sharing_disabled. In service_accounts mode, only service account-owned workspaces can be shared while regular members' share permissions are removed. Adds a new organization-service-account system role with per-org permissions reconciled alongside the existing organization-member system role. Related to: https://linear.app/codercom/issue/PLAT-28/feat-service-accounts-sharing-mode-and-rbac-role --------- Co-authored-by: Steven Masley <Emyrk@users.noreply.github.com> Co-authored-by: Kayla はな <mckayla@hey.com>
This commit is contained in:
co-authored by
Steven Masley
Kayla はな
parent
6b76e30321
commit
91ec0f1484
@@ -7,19 +7,41 @@ import (
|
||||
"net/http"
|
||||
)
|
||||
|
||||
// ShareableWorkspaceOwners controls whose workspaces can be shared
|
||||
// within an organization.
|
||||
type ShareableWorkspaceOwners string
|
||||
|
||||
const (
|
||||
ShareableWorkspaceOwnersNone ShareableWorkspaceOwners = "none"
|
||||
ShareableWorkspaceOwnersEveryone ShareableWorkspaceOwners = "everyone"
|
||||
ShareableWorkspaceOwnersServiceAccounts ShareableWorkspaceOwners = "service_accounts"
|
||||
)
|
||||
|
||||
// WorkspaceSharingSettings represents workspace sharing settings affecting an
|
||||
// organization.
|
||||
type WorkspaceSharingSettings struct {
|
||||
// SharingGloballyDisabled is true if sharing has been disabled for this
|
||||
// organization because of a deployment-wide setting.
|
||||
SharingGloballyDisabled bool `json:"sharing_globally_disabled"`
|
||||
SharingDisabled bool `json:"sharing_disabled"`
|
||||
// SharingDisabled is deprecated and left for backward compatibility
|
||||
// purposes.
|
||||
// Deprecated: use `ShareableWorkspaceOwners` instead
|
||||
SharingDisabled bool `json:"sharing_disabled"`
|
||||
// ShareableWorkspaceOwners controls whose workspaces can be shared
|
||||
// within the organization.
|
||||
ShareableWorkspaceOwners ShareableWorkspaceOwners `json:"shareable_workspace_owners" enums:"none,everyone,service_accounts"`
|
||||
}
|
||||
|
||||
// UpdateWorkspaceSharingSettingsRequest represents workspace sharing settings
|
||||
// that can be updated for an organization.
|
||||
type UpdateWorkspaceSharingSettingsRequest struct {
|
||||
// SharingDisabled is deprecated and left for backward compatibility
|
||||
// purposes.
|
||||
// Deprecated: use `ShareableWorkspaceOwners` instead
|
||||
SharingDisabled bool `json:"sharing_disabled"`
|
||||
// ShareableWorkspaceOwners controls whose workspaces can be shared
|
||||
// within the organization.
|
||||
ShareableWorkspaceOwners ShareableWorkspaceOwners `json:"shareable_workspace_owners,omitempty" enums:"none,everyone,service_accounts"`
|
||||
}
|
||||
|
||||
// WorkspaceSharingSettings retrieves the workspace sharing settings for an organization.
|
||||
|
||||
Reference in New Issue
Block a user