feat: implement API key scopes database migration (#19861)

Added database migration for API key scopes.

Fixes #19845
This commit is contained in:
Thomas Kosiewski
2025-09-22 19:26:51 +02:00
committed by GitHub
parent a30c30724b
commit fb0ce389a6
26 changed files with 1252 additions and 71 deletions
+1 -1
View File
@@ -434,7 +434,7 @@ func ExtractAPIKey(rw http.ResponseWriter, r *http.Request, cfg ExtractAPIKeyCon
// If the key is valid, we also fetch the user roles and status.
// The roles are used for RBAC authorize checks, and the status
// is to block 'suspended' users from accessing the platform.
actor, userStatus, err := UserRBACSubject(ctx, cfg.DB, key.UserID, rbac.ScopeName(key.Scope))
actor, userStatus, err := UserRBACSubject(ctx, cfg.DB, key.UserID, key.Scopes)
if err != nil {
return write(http.StatusUnauthorized, codersdk.Response{
Message: internalErrorMessage,
+2 -2
View File
@@ -313,7 +313,7 @@ func TestAPIKey(t *testing.T) {
_, token = dbgen.APIKey(t, db, database.APIKey{
UserID: user.ID,
ExpiresAt: dbtime.Now().AddDate(0, 0, 1),
Scope: database.APIKeyScopeApplicationConnect,
Scopes: database.APIKeyScopes{database.APIKeyScopeApplicationConnect},
})
r = httptest.NewRequest("GET", "/", nil)
@@ -330,7 +330,7 @@ func TestAPIKey(t *testing.T) {
})(http.HandlerFunc(func(rw http.ResponseWriter, r *http.Request) {
// Checks that it exists on the context!
apiKey := httpmw.APIKey(r)
assert.Equal(t, database.APIKeyScopeApplicationConnect, apiKey.Scope)
assert.Equal(t, database.APIKeyScopeApplicationConnect, apiKey.Scopes[0])
assertActorOk(t, r)
httpapi.Write(r.Context(), rw, http.StatusOK, codersdk.Response{
+2 -1
View File
@@ -172,7 +172,8 @@ func addUser(t *testing.T, db database.Store, roles ...string) (database.User, s
LastUsed: dbtime.Now(),
ExpiresAt: dbtime.Now().Add(time.Minute),
LoginType: database.LoginTypePassword,
Scope: database.APIKeyScopeAll,
Scopes: database.APIKeyScopes{database.APIKeyScopeAll},
AllowList: database.AllowList{database.AllowListWildcard()},
IPAddress: pqtype.Inet{
IPNet: net.IPNet{
IP: net.ParseIP("0.0.0.0"),
+2 -1
View File
@@ -66,7 +66,8 @@ func TestWorkspaceParam(t *testing.T) {
LastUsed: dbtime.Now(),
ExpiresAt: dbtime.Now().Add(time.Minute),
LoginType: database.LoginTypePassword,
Scope: database.APIKeyScopeAll,
Scopes: database.APIKeyScopes{database.APIKeyScopeAll},
AllowList: database.AllowList{database.AllowListWildcard()},
IPAddress: pqtype.Inet{
IPNet: net.IPNet{
IP: net.IPv4(127, 0, 0, 1),