mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: Option to remove WorkspaceExec from owner role (#7050)
* chore: Add AllResources option for listing all RBAC objects * Owners cannot do workspace exec site wide * Fix FE authchecks to valid RBAC resources
This commit is contained in:
+6
@@ -16,6 +16,12 @@ Start a Coder server
|
||||
$CACHE_DIRECTORY is set, it will be used for compatibility with
|
||||
systemd.
|
||||
|
||||
--disable-owner-workspace-access bool, $CODER_DISABLE_OWNER_WORKSPACE_ACCESS
|
||||
Remove the permission for the 'owner' role to have workspace execution
|
||||
on all workspaces. This prevents the 'owner' from ssh, apps, and
|
||||
terminal access based on the 'owner' role. They still have their user
|
||||
permissions to access their own workspaces.
|
||||
|
||||
--disable-path-apps bool, $CODER_DISABLE_PATH_APPS
|
||||
Disable workspace apps that are not served from subdomains. Path-based
|
||||
apps can make requests to the Coder API and pose a security risk when
|
||||
|
||||
+6
@@ -315,6 +315,12 @@ agentFallbackTroubleshootingURL: https://coder.com/docs/coder-oss/latest/templat
|
||||
# --wildcard-access-url is configured.
|
||||
# (default: <unset>, type: bool)
|
||||
disablePathApps: false
|
||||
# Remove the permission for the 'owner' role to have workspace execution on all
|
||||
# workspaces. This prevents the 'owner' from ssh, apps, and terminal access based
|
||||
# on the 'owner' role. They still have their user permissions to access their own
|
||||
# workspaces.
|
||||
# (default: <unset>, type: bool)
|
||||
disableOwnerWorkspaceAccess: false
|
||||
# These options change the behavior of how clients interact with the Coder.
|
||||
# Clients include the coder cli, vs code extension, and the web UI.
|
||||
client:
|
||||
|
||||
Reference in New Issue
Block a user