mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add allow list to API keys (#19972)
Add API key allow list to the SDK This PR adds an allow list to API keys in the SDK. The allow list is a list of targets that the API key is allowed to access. If the allow list is empty, a default allow list with a single entry that allows access to all resources is created. The changes include: - Adding a default allow list when generating an API key if none is provided - Adding allow list to the API key response in the SDK - Converting database allow list entries to SDK format in the API response - Adding tests to verify the default allow list behavior Fixes #19854
This commit is contained in:
@@ -0,0 +1,3 @@
|
||||
-- Drop all CHECK constraints added in the up migration
|
||||
ALTER TABLE api_keys
|
||||
DROP CONSTRAINT api_keys_allow_list_not_empty;
|
||||
@@ -0,0 +1,10 @@
|
||||
-- Defensively update any API keys with empty allow_list to have default '*:*'
|
||||
-- This ensures all existing keys have at least one entry before adding the constraint
|
||||
UPDATE api_keys
|
||||
SET allow_list = ARRAY['*:*']
|
||||
WHERE allow_list = ARRAY[]::text[] OR array_length(allow_list, 1) IS NULL;
|
||||
|
||||
-- Add CHECK constraint to ensure allow_list array is never empty
|
||||
ALTER TABLE api_keys
|
||||
ADD CONSTRAINT api_keys_allow_list_not_empty
|
||||
CHECK (array_length(allow_list, 1) > 0);
|
||||
Reference in New Issue
Block a user