refactor: add wildcard scope entries for API key scopes (#20032)

# Add API Key Scope Wildcards

This PR adds wildcard API key scopes (`resource:*`) for all RBAC resources to ensure every resource has a matching wildcard value. It also adds all individual `resource:action`​ scopes to the API documentation and TypeScript definitions.

The changes include:

- Adding a new database migration (000377) that adds wildcard API key scopes
- Updating the API documentation to include all available scopes
- Enhancing the scope generation scripts to include all resource wildcards
- Updating the TypeScript definitions to match the expanded scope list

These changes make creating API keys with comprehensive permissions for specific resource types easier.
This commit is contained in:
Thomas Kosiewski
2025-10-06 12:08:17 +02:00
committed by GitHub
parent d17dd5d787
commit b60ae0a0c4
12 changed files with 1551 additions and 141 deletions
+19 -5
View File
@@ -58,23 +58,37 @@ func main() {
os.Exit(1)
}
// expectedFromRBAC returns the set of <resource>:<action> pairs derived from RBACPermissions.
// expectedFromRBAC returns the set of scope names the DB enum must support.
func expectedFromRBAC() map[string]struct{} {
want := make(map[string]struct{})
// Low-level <resource>:<action>
add := func(name string) {
if name == "" {
return
}
want[name] = struct{}{}
}
// Low-level <resource>:<action> and synthesized <resource>:* wildcards
for resource, def := range policy.RBACPermissions {
if resource == policy.WildcardSymbol {
// Ignore wildcard entry; it has no concrete <resource>:<action> pairs.
continue
}
add(resource + ":" + policy.WildcardSymbol)
for action := range def.Actions {
key := resource + ":" + string(action)
want[key] = struct{}{}
add(resource + ":" + string(action))
}
}
// Composite coder:* names
for _, n := range rbac.CompositeScopeNames() {
want[n] = struct{}{}
add(n)
}
// Built-in coder-prefixed scopes such as coder:all
for _, n := range rbac.BuiltinScopeNames() {
s := string(n)
if !strings.Contains(s, ":") {
continue
}
add(s)
}
return want
}