feat: allow auditors to read template insights (#10860)

- Adds a template_insights pseudo-resource
- Grants auditor and template admin roles read access on template_insights
- Updates existing RBAC checks to check for read template_insights, falling back to template update permissions where necessary
- Updates TemplateLayout to show Insights tab if can read template_insights or can update template
This commit is contained in:
Cian Johnston
2023-11-24 17:21:32 +00:00
committed by GitHub
parent e73901cf56
commit dd161b172e
11 changed files with 186 additions and 77 deletions
+2
View File
@@ -1882,6 +1882,7 @@ export type RBACResource =
| "replicas"
| "system"
| "template"
| "template_insights"
| "user"
| "user_data"
| "workspace"
@@ -1905,6 +1906,7 @@ export const RBACResources: RBACResource[] = [
"replicas",
"system",
"template",
"template_insights",
"user",
"user_data",
"workspace",
+10 -1
View File
@@ -24,6 +24,12 @@ const templatePermissions = (
},
action: "update",
},
canReadInsights: {
object: {
resource_type: "template_insights",
},
action: "read",
},
});
const fetchTemplate = async (orgId: string, templateName: string) => {
@@ -68,7 +74,10 @@ export const TemplateLayout: FC<{ children?: JSX.Element }> = ({
queryKey: ["template", templateName],
queryFn: () => fetchTemplate(orgId, templateName),
});
const shouldShowInsights = data?.permissions?.canUpdateTemplate;
// Auditors should also be able to view insights, but do not automatically
// have permission to update templates. Need both checks.
const shouldShowInsights =
data?.permissions?.canUpdateTemplate || data?.permissions?.canReadInsights;
if (error) {
return (