mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore: refactor roles to support multiple permission sets scoped by org id (#20186)
In preparation for adding the "member" permission level, which will also be grouped by org ID, do a bit of a refactor to make room for it and the existing "org" level to live in the same `map`
This commit is contained in:
@@ -78,8 +78,8 @@ var builtinScopes = map[ScopeName]Scope{
|
||||
Site: Permissions(map[string][]policy.Action{
|
||||
ResourceWildcard.Type: {policy.WildcardSymbol},
|
||||
}),
|
||||
Org: map[string][]Permission{},
|
||||
User: []Permission{},
|
||||
User: []Permission{},
|
||||
ByOrgID: map[string]OrgPermissions{},
|
||||
},
|
||||
AllowIDList: []AllowListElement{AllowListAll()},
|
||||
},
|
||||
@@ -91,8 +91,8 @@ var builtinScopes = map[ScopeName]Scope{
|
||||
Site: Permissions(map[string][]policy.Action{
|
||||
ResourceWorkspace.Type: {policy.ActionApplicationConnect},
|
||||
}),
|
||||
Org: map[string][]Permission{},
|
||||
User: []Permission{},
|
||||
User: []Permission{},
|
||||
ByOrgID: map[string]OrgPermissions{},
|
||||
},
|
||||
AllowIDList: []AllowListElement{AllowListAll()},
|
||||
},
|
||||
@@ -102,8 +102,8 @@ var builtinScopes = map[ScopeName]Scope{
|
||||
Identifier: RoleIdentifier{Name: fmt.Sprintf("Scope_%s", ScopeNoUserData)},
|
||||
DisplayName: "Scope without access to user data",
|
||||
Site: allPermsExcept(ResourceUser),
|
||||
Org: map[string][]Permission{},
|
||||
User: []Permission{},
|
||||
ByOrgID: map[string]OrgPermissions{},
|
||||
},
|
||||
AllowIDList: []AllowListElement{AllowListAll()},
|
||||
},
|
||||
@@ -232,8 +232,8 @@ func ExpandScope(scope ScopeName) (Scope, error) {
|
||||
Identifier: RoleIdentifier{Name: fmt.Sprintf("Scope_%s", scope)},
|
||||
DisplayName: string(scope),
|
||||
Site: site,
|
||||
Org: map[string][]Permission{},
|
||||
User: []Permission{},
|
||||
ByOrgID: map[string]OrgPermissions{},
|
||||
},
|
||||
// Composites are site-level; allow-list empty by default
|
||||
AllowIDList: []AllowListElement{{Type: policy.WildcardSymbol, ID: policy.WildcardSymbol}},
|
||||
@@ -289,8 +289,8 @@ func expandLowLevel(resource string, action policy.Action) Scope {
|
||||
Identifier: RoleIdentifier{Name: fmt.Sprintf("Scope_%s:%s", resource, action)},
|
||||
DisplayName: fmt.Sprintf("%s:%s", resource, action),
|
||||
Site: []Permission{{ResourceType: resource, Action: action}},
|
||||
Org: map[string][]Permission{},
|
||||
User: []Permission{},
|
||||
ByOrgID: map[string]OrgPermissions{},
|
||||
},
|
||||
// Low-level scopes intentionally return a wildcard allow list.
|
||||
AllowIDList: []AllowListElement{{Type: policy.WildcardSymbol, ID: policy.WildcardSymbol}},
|
||||
|
||||
Reference in New Issue
Block a user