mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add api for patching custom org roles (#13357)
* chore: implement patching custom organization roles
This commit is contained in:
@@ -531,12 +531,16 @@ func Role(role rbac.Role) codersdk.Role {
|
||||
if err != nil {
|
||||
roleName = role.Name
|
||||
}
|
||||
|
||||
return codersdk.Role{
|
||||
Name: roleName,
|
||||
OrganizationID: orgIDStr,
|
||||
DisplayName: role.DisplayName,
|
||||
SitePermissions: List(role.Site, Permission),
|
||||
OrganizationPermissions: Map(role.Org, ListLazy(Permission)),
|
||||
Name: roleName,
|
||||
OrganizationID: orgIDStr,
|
||||
DisplayName: role.DisplayName,
|
||||
SitePermissions: List(role.Site, Permission),
|
||||
// This is not perfect. If there are organization permissions in another
|
||||
// organization, they will be omitted. This should not be allowed, so
|
||||
// should never happen.
|
||||
OrganizationPermissions: List(role.Org[orgIDStr], Permission),
|
||||
UserPermissions: List(role.User, Permission),
|
||||
}
|
||||
}
|
||||
@@ -550,11 +554,18 @@ func Permission(permission rbac.Permission) codersdk.Permission {
|
||||
}
|
||||
|
||||
func RoleToRBAC(role codersdk.Role) rbac.Role {
|
||||
orgPerms := map[string][]rbac.Permission{}
|
||||
if role.OrganizationID != "" {
|
||||
orgPerms = map[string][]rbac.Permission{
|
||||
role.OrganizationID: List(role.OrganizationPermissions, PermissionToRBAC),
|
||||
}
|
||||
}
|
||||
|
||||
return rbac.Role{
|
||||
Name: rbac.RoleName(role.Name, role.OrganizationID),
|
||||
DisplayName: role.DisplayName,
|
||||
Site: List(role.SitePermissions, PermissionToRBAC),
|
||||
Org: Map(role.OrganizationPermissions, ListLazy(PermissionToRBAC)),
|
||||
Org: orgPerms,
|
||||
User: List(role.UserPermissions, PermissionToRBAC),
|
||||
}
|
||||
}
|
||||
|
||||
@@ -600,7 +600,7 @@ func (q *querier) canAssignRoles(ctx context.Context, orgID *uuid.UUID, added, r
|
||||
customRoles := make([]string, 0)
|
||||
// Validate that the roles being assigned are valid.
|
||||
for _, r := range grantedRoles {
|
||||
_, isOrgRole := rbac.IsOrgRole(r)
|
||||
roleOrgIDStr, isOrgRole := rbac.IsOrgRole(r)
|
||||
if shouldBeOrgRoles && !isOrgRole {
|
||||
return xerrors.Errorf("Must only update org roles")
|
||||
}
|
||||
@@ -608,6 +608,21 @@ func (q *querier) canAssignRoles(ctx context.Context, orgID *uuid.UUID, added, r
|
||||
return xerrors.Errorf("Must only update site wide roles")
|
||||
}
|
||||
|
||||
if shouldBeOrgRoles {
|
||||
roleOrgID, err := uuid.Parse(roleOrgIDStr)
|
||||
if err != nil {
|
||||
return xerrors.Errorf("role %q has invalid uuid for org: %w", r, err)
|
||||
}
|
||||
|
||||
if orgID == nil {
|
||||
return xerrors.Errorf("should never happen, orgID is nil, but trying to assign an organization role")
|
||||
}
|
||||
|
||||
if roleOrgID != *orgID {
|
||||
return xerrors.Errorf("attempted to assign role from a different org, role %q to %q", r, orgID.String())
|
||||
}
|
||||
}
|
||||
|
||||
// All roles should be valid roles
|
||||
if _, err := rbac.RoleByName(r); err != nil {
|
||||
customRoles = append(customRoles, r)
|
||||
|
||||
Reference in New Issue
Block a user