mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add multi-scope support to API keys (#19917)
# Canonicalize API Key Scopes This PR introduces canonical API key scopes with a `coder:` namespace prefix to avoid collisions with low-level resource:action names. It: 1. Renames special API key scopes in the database: - `all` → `coder:all` - `application_connect` → `coder:application_connect` 2. Adds support for a new `scopes` field in the API key creation request, allowing multiple scopes to be specified while maintaining backward compatibility with the singular `scope` field. 3. Updates the API documentation to reflect these changes, including the new endpoint for listing public API key scopes. 4. Ensures backward compatibility by mapping between legacy and canonical scope names in relevant code paths.
This commit is contained in:
+13
-11
@@ -12,16 +12,17 @@ import (
|
||||
|
||||
// APIKey: do not ever return the HashedSecret
|
||||
type APIKey struct {
|
||||
ID string `json:"id" validate:"required"`
|
||||
UserID uuid.UUID `json:"user_id" validate:"required" format:"uuid"`
|
||||
LastUsed time.Time `json:"last_used" validate:"required" format:"date-time"`
|
||||
ExpiresAt time.Time `json:"expires_at" validate:"required" format:"date-time"`
|
||||
CreatedAt time.Time `json:"created_at" validate:"required" format:"date-time"`
|
||||
UpdatedAt time.Time `json:"updated_at" validate:"required" format:"date-time"`
|
||||
LoginType LoginType `json:"login_type" validate:"required" enums:"password,github,oidc,token"`
|
||||
Scope APIKeyScope `json:"scope" validate:"required" enums:"all,application_connect"`
|
||||
TokenName string `json:"token_name" validate:"required"`
|
||||
LifetimeSeconds int64 `json:"lifetime_seconds" validate:"required"`
|
||||
ID string `json:"id" validate:"required"`
|
||||
UserID uuid.UUID `json:"user_id" validate:"required" format:"uuid"`
|
||||
LastUsed time.Time `json:"last_used" validate:"required" format:"date-time"`
|
||||
ExpiresAt time.Time `json:"expires_at" validate:"required" format:"date-time"`
|
||||
CreatedAt time.Time `json:"created_at" validate:"required" format:"date-time"`
|
||||
UpdatedAt time.Time `json:"updated_at" validate:"required" format:"date-time"`
|
||||
LoginType LoginType `json:"login_type" validate:"required" enums:"password,github,oidc,token"`
|
||||
Scope APIKeyScope `json:"scope" enums:"all,application_connect"` // Deprecated: use Scopes instead.
|
||||
Scopes []APIKeyScope `json:"scopes"`
|
||||
TokenName string `json:"token_name" validate:"required"`
|
||||
LifetimeSeconds int64 `json:"lifetime_seconds" validate:"required"`
|
||||
}
|
||||
|
||||
// LoginType is the type of login used to create the API key.
|
||||
@@ -44,7 +45,8 @@ type APIKeyScope string
|
||||
|
||||
type CreateTokenRequest struct {
|
||||
Lifetime time.Duration `json:"lifetime"`
|
||||
Scope APIKeyScope `json:"scope"`
|
||||
Scope APIKeyScope `json:"scope,omitempty"` // Deprecated: use Scopes instead.
|
||||
Scopes []APIKeyScope `json:"scopes,omitempty"`
|
||||
TokenName string `json:"token_name"`
|
||||
}
|
||||
|
||||
|
||||
@@ -2,13 +2,17 @@
|
||||
package codersdk
|
||||
|
||||
const (
|
||||
APIKeyScopeAll APIKeyScope = "all"
|
||||
// Deprecated: use codersdk.APIKeyScopeCoderAll instead.
|
||||
APIKeyScopeAll APIKeyScope = "all"
|
||||
// Deprecated: use codersdk.APIKeyScopeCoderApplicationConnect instead.
|
||||
APIKeyScopeApplicationConnect APIKeyScope = "application_connect"
|
||||
APIKeyScopeApiKeyAll APIKeyScope = "api_key:*"
|
||||
APIKeyScopeApiKeyCreate APIKeyScope = "api_key:create"
|
||||
APIKeyScopeApiKeyDelete APIKeyScope = "api_key:delete"
|
||||
APIKeyScopeApiKeyRead APIKeyScope = "api_key:read"
|
||||
APIKeyScopeApiKeyUpdate APIKeyScope = "api_key:update"
|
||||
APIKeyScopeApplicationConnect APIKeyScope = "application_connect"
|
||||
APIKeyScopeCoderAll APIKeyScope = "coder:all"
|
||||
APIKeyScopeCoderApplicationConnect APIKeyScope = "coder:application_connect"
|
||||
APIKeyScopeFileAll APIKeyScope = "file:*"
|
||||
APIKeyScopeFileCreate APIKeyScope = "file:create"
|
||||
APIKeyScopeFileRead APIKeyScope = "file:read"
|
||||
@@ -38,13 +42,13 @@ const (
|
||||
|
||||
// PublicAPIKeyScopes lists all public low-level API key scopes.
|
||||
var PublicAPIKeyScopes = []APIKeyScope{
|
||||
APIKeyScopeAll,
|
||||
APIKeyScopeApiKeyAll,
|
||||
APIKeyScopeApiKeyCreate,
|
||||
APIKeyScopeApiKeyDelete,
|
||||
APIKeyScopeApiKeyRead,
|
||||
APIKeyScopeApiKeyUpdate,
|
||||
APIKeyScopeApplicationConnect,
|
||||
APIKeyScopeCoderAll,
|
||||
APIKeyScopeCoderApplicationConnect,
|
||||
APIKeyScopeFileAll,
|
||||
APIKeyScopeFileCreate,
|
||||
APIKeyScopeFileRead,
|
||||
|
||||
Reference in New Issue
Block a user