mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add lint check for API key scope enum completeness (#19862)
Added a script/linter to ensure all `policy.RBACPermissions` entries are part of the `api_key_scope` enumerated in the `coderd/database/dump.sql` file. Fixes #19846
This commit is contained in:
@@ -0,0 +1,43 @@
|
||||
# check-scopes
|
||||
|
||||
Validates that the DB enum `api_key_scope` contains every `<resource>:<action>` derived from `coderd/rbac/policy/RBACPermissions`.
|
||||
|
||||
- Exits 0 when all scopes are present in `coderd/database/dump.sql`.
|
||||
- Exits 1 and prints missing values with suggested `ALTER TYPE` statements otherwise.
|
||||
|
||||
## Usage
|
||||
|
||||
Ensure the schema dump is up-to-date, then run the check:
|
||||
|
||||
```sh
|
||||
make -B gen/db # forces DB dump regeneration
|
||||
make lint/check-scopes
|
||||
```
|
||||
|
||||
Or directly:
|
||||
|
||||
```sh
|
||||
go run ./tools/check-scopes
|
||||
```
|
||||
|
||||
Optional flags:
|
||||
|
||||
- `-dump path` — override path to `dump.sql` (default `coderd/database/dump.sql`).
|
||||
|
||||
## Remediation
|
||||
|
||||
When the tool reports missing values:
|
||||
|
||||
1. Create a DB migration extending the enum, e.g.:
|
||||
|
||||
```sql
|
||||
ALTER TYPE api_key_scope ADD VALUE IF NOT EXISTS 'template:view_insights';
|
||||
```
|
||||
|
||||
2. Regenerate and re-run:
|
||||
|
||||
```sh
|
||||
make -B gen/db && make lint/check-scopes
|
||||
```
|
||||
|
||||
3. Decide whether each new scope is public (exposed in the catalog) or internal-only (handled by the catalog task).
|
||||
Reference in New Issue
Block a user