mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
Includes db schema and dbauthz layer for upserting custom roles. Unit test in `customroles_test.go` verify against escalating permissions through this feature.
38 lines
837 B
Go
38 lines
837 B
Go
package rolestore
|
|
|
|
import (
|
|
"encoding/json"
|
|
|
|
"golang.org/x/xerrors"
|
|
|
|
"github.com/coder/coder/v2/coderd/database"
|
|
"github.com/coder/coder/v2/coderd/rbac"
|
|
)
|
|
|
|
func ConvertDBRole(dbRole database.CustomRole) (rbac.Role, error) {
|
|
role := rbac.Role{
|
|
Name: dbRole.Name,
|
|
DisplayName: dbRole.DisplayName,
|
|
Site: nil,
|
|
Org: nil,
|
|
User: nil,
|
|
}
|
|
|
|
err := json.Unmarshal(dbRole.SitePermissions, &role.Site)
|
|
if err != nil {
|
|
return role, xerrors.Errorf("unmarshal site permissions: %w", err)
|
|
}
|
|
|
|
err = json.Unmarshal(dbRole.OrgPermissions, &role.Org)
|
|
if err != nil {
|
|
return role, xerrors.Errorf("unmarshal org permissions: %w", err)
|
|
}
|
|
|
|
err = json.Unmarshal(dbRole.UserPermissions, &role.User)
|
|
if err != nil {
|
|
return role, xerrors.Errorf("unmarshal user permissions: %w", err)
|
|
}
|
|
|
|
return role, nil
|
|
}
|