feat(coderd/rbac): make organization-member a per-org system custom role (#21359)

Migrated the built-in organization-member role to DB storage so it can be customized per org.

Closes https://github.com/coder/internal/issues/1073 (part 1)
This commit is contained in:
George K
2026-01-12 18:19:19 -08:00
committed by GitHub
parent 2b448c7178
commit cc2efe9e1f
46 changed files with 1845 additions and 438 deletions
+39
View File
@@ -105,12 +105,51 @@ func (s *MethodTestSuite) TearDownSuite() {
var testActorID = uuid.New()
type includeSystemRolesMatcher struct{}
func (includeSystemRolesMatcher) Matches(x any) bool {
p, ok := x.(database.CustomRolesParams)
if !ok {
return false
}
return p.IncludeSystemRoles
}
func (includeSystemRolesMatcher) String() string {
return "CustomRolesParams with IncludeSystemRoles=true"
}
// Mocked runs a subtest with a mocked database. Removing the overhead of a real
// postgres database resulting in much faster tests.
func (s *MethodTestSuite) Mocked(testCaseF func(dmb *dbmock.MockStore, faker *gofakeit.Faker, check *expects)) func() {
t := s.T()
mDB := dbmock.NewMockStore(gomock.NewController(t))
mDB.EXPECT().Wrappers().Return([]string{}).AnyTimes()
// dbauthz now expands DB-backed system roles (e.g. organization-member)
// during role-assignment validation, which triggers a CustomRoles lookup
// with IncludeSystemRoles=true.
mDB.EXPECT().CustomRoles(gomock.Any(), includeSystemRolesMatcher{}).DoAndReturn(func(_ context.Context, arg database.CustomRolesParams) ([]database.CustomRole, error) {
if len(arg.LookupRoles) == 0 {
return []database.CustomRole{}, nil
}
out := make([]database.CustomRole, 0, len(arg.LookupRoles))
for _, pair := range arg.LookupRoles {
// Minimal set of fields that the tested code uses.
out = append(out, database.CustomRole{
Name: pair.Name,
OrganizationID: uuid.NullUUID{
UUID: pair.OrganizationID,
Valid: pair.OrganizationID != uuid.Nil,
},
IsSystem: rbac.SystemRoleName(pair.Name),
ID: uuid.New(),
})
}
return out, nil
}).AnyTimes()
// Use a constant seed to prevent flakes from random data generation.
faker := gofakeit.New(0)