mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: Implied 'member' roles for site and organization (#1917)
* feat: Member roles are implied and never exlpicitly added * Rename "GetAllUserRoles" to "GetAuthorizationRoles" * feat: Add migration to remove implied roles * rename user auth role middleware
This commit is contained in:
+5
-1
@@ -45,7 +45,7 @@ func (api *API) checkPermissions(rw http.ResponseWriter, r *http.Request) {
|
||||
}
|
||||
|
||||
// use the roles of the user specified, not the person making the request.
|
||||
roles, err := api.Database.GetAllUserRoles(r.Context(), user.ID)
|
||||
roles, err := api.Database.GetAuthorizationUserRoles(r.Context(), user.ID)
|
||||
if err != nil {
|
||||
httpapi.Forbidden(rw)
|
||||
return
|
||||
@@ -91,6 +91,10 @@ func convertRole(role rbac.Role) codersdk.Role {
|
||||
func convertRoles(roles []rbac.Role) []codersdk.Role {
|
||||
converted := make([]codersdk.Role, 0, len(roles))
|
||||
for _, role := range roles {
|
||||
// Roles without display names should never be shown to the ui.
|
||||
if role.DisplayName == "" {
|
||||
continue
|
||||
}
|
||||
converted = append(converted, convertRole(role))
|
||||
}
|
||||
return converted
|
||||
|
||||
Reference in New Issue
Block a user