mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore: refactor roles to support multiple permission sets scoped by org id (#20186)
In preparation for adding the "member" permission level, which will also be grouped by org ID, do a bit of a refactor to make room for it and the existing "org" level to live in the same `map`
This commit is contained in:
+14
-7
@@ -157,23 +157,30 @@ func (role Role) regoValue() ast.Value {
|
||||
if role.cachedRegoValue != nil {
|
||||
return role.cachedRegoValue
|
||||
}
|
||||
orgMap := ast.NewObject()
|
||||
for k, p := range role.Org {
|
||||
orgMap.Insert(ast.StringTerm(k), ast.NewTerm(regoSlice(p)))
|
||||
byOrgIDMap := ast.NewObject()
|
||||
for k, p := range role.ByOrgID {
|
||||
byOrgIDMap.Insert(ast.StringTerm(k), ast.NewTerm(
|
||||
ast.NewObject(
|
||||
[2]*ast.Term{
|
||||
ast.StringTerm("org"),
|
||||
ast.NewTerm(regoSlice(p.Org)),
|
||||
},
|
||||
),
|
||||
))
|
||||
}
|
||||
return ast.NewObject(
|
||||
[2]*ast.Term{
|
||||
ast.StringTerm("site"),
|
||||
ast.NewTerm(regoSlice(role.Site)),
|
||||
},
|
||||
[2]*ast.Term{
|
||||
ast.StringTerm("org"),
|
||||
ast.NewTerm(orgMap),
|
||||
},
|
||||
[2]*ast.Term{
|
||||
ast.StringTerm("user"),
|
||||
ast.NewTerm(regoSlice(role.User)),
|
||||
},
|
||||
[2]*ast.Term{
|
||||
ast.StringTerm("by_org_id"),
|
||||
ast.NewTerm(byOrgIDMap),
|
||||
},
|
||||
)
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user