chore: implement databased backend for custom roles (#13295)

Includes db schema and dbauthz layer for upserting custom roles. Unit test in `customroles_test.go` verify against escalating permissions through this feature.
This commit is contained in:
Steven Masley
2024-05-16 13:11:26 -05:00
committed by GitHub
parent 194be12133
commit cf91eff7cf
21 changed files with 854 additions and 19 deletions
+37
View File
@@ -0,0 +1,37 @@
package rolestore
import (
"encoding/json"
"golang.org/x/xerrors"
"github.com/coder/coder/v2/coderd/database"
"github.com/coder/coder/v2/coderd/rbac"
)
func ConvertDBRole(dbRole database.CustomRole) (rbac.Role, error) {
role := rbac.Role{
Name: dbRole.Name,
DisplayName: dbRole.DisplayName,
Site: nil,
Org: nil,
User: nil,
}
err := json.Unmarshal(dbRole.SitePermissions, &role.Site)
if err != nil {
return role, xerrors.Errorf("unmarshal site permissions: %w", err)
}
err = json.Unmarshal(dbRole.OrgPermissions, &role.Org)
if err != nil {
return role, xerrors.Errorf("unmarshal org permissions: %w", err)
}
err = json.Unmarshal(dbRole.UserPermissions, &role.User)
if err != nil {
return role, xerrors.Errorf("unmarshal user permissions: %w", err)
}
return role, nil
}