mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
Change NewRole to use V5 by default, old consumers now user NewRoleV3. (#10884)
This commit is contained in:
+9
-12
@@ -159,11 +159,11 @@ type Role interface {
|
||||
GetSessionPolicySet() SessionTrackerPolicySet
|
||||
}
|
||||
|
||||
// NewRole constructs new standard V3 role.
|
||||
// This is mostly a legacy function and will create a role with V3 RBAC semantics.
|
||||
// NewRole constructs new standard V5 role.
|
||||
// This creates a V5 role with V4+ RBAC semantics.
|
||||
func NewRole(name string, spec RoleSpecV5) (Role, error) {
|
||||
role := RoleV5{
|
||||
Version: V3,
|
||||
Version: V5,
|
||||
Metadata: Metadata{
|
||||
Name: name,
|
||||
},
|
||||
@@ -175,11 +175,11 @@ func NewRole(name string, spec RoleSpecV5) (Role, error) {
|
||||
return &role, nil
|
||||
}
|
||||
|
||||
// NewRoleV5 constructs new standard V5 role.
|
||||
// This creates a V5 role with V4+ RBAC semantics. This should be preferred over `NewRole`.
|
||||
func NewRoleV5(name string, spec RoleSpecV5) (Role, error) {
|
||||
// NewRoleV3 constructs new standard V3 role.
|
||||
// This is mostly a legacy function and will create a role with V3 RBAC semantics.
|
||||
func NewRoleV3(name string, spec RoleSpecV5) (Role, error) {
|
||||
role := RoleV5{
|
||||
Version: V5,
|
||||
Version: V3,
|
||||
Metadata: Metadata{
|
||||
Name: name,
|
||||
},
|
||||
@@ -604,11 +604,8 @@ func (r *RoleV5) SetRules(rct RoleConditionType, in []Rule) {
|
||||
// setStaticFields sets static resource header and metadata fields.
|
||||
func (r *RoleV5) setStaticFields() {
|
||||
r.Kind = KindRole
|
||||
// TODO(Joerger/nklaassen) Role should default to V4
|
||||
// but shouldn't overwrite V3. For now, this does the
|
||||
// opposite due to an internal reliance on V3 defaults.
|
||||
if r.Version != V4 && r.Version != V5 {
|
||||
r.Version = V3
|
||||
if r.Version != V3 && r.Version != V4 {
|
||||
r.Version = V5
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -1179,7 +1179,7 @@ func runDisconnectTest(t *testing.T, suite *integrationTestSuite, tc disconnectT
|
||||
teleport := suite.newTeleportInstance()
|
||||
|
||||
username := suite.me.Username
|
||||
role, err := types.NewRole("devs", types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3("devs", types.RoleSpecV5{
|
||||
Options: tc.options,
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{username},
|
||||
@@ -1741,7 +1741,7 @@ func testMapRoles(t *testing.T, suite *integrationTestSuite) {
|
||||
|
||||
// main cluster has a local user and belongs to role "main-devs"
|
||||
mainDevs := "main-devs"
|
||||
role, err := types.NewRole(mainDevs, types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3(mainDevs, types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{username},
|
||||
},
|
||||
@@ -1769,7 +1769,7 @@ func testMapRoles(t *testing.T, suite *integrationTestSuite) {
|
||||
// using trusted clusters, so remote user will be allowed to assume
|
||||
// role specified by mapping remote role "devs" to local role "local-devs"
|
||||
auxDevs := "aux-devs"
|
||||
role, err = types.NewRole(auxDevs, types.RoleSpecV5{
|
||||
role, err = types.NewRoleV3(auxDevs, types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{username},
|
||||
},
|
||||
@@ -2051,7 +2051,7 @@ func trustedClusters(t *testing.T, suite *integrationTestSuite, test trustedClus
|
||||
|
||||
// main cluster has a local user and belongs to role "main-devs" and "main-admins"
|
||||
mainDevs := "main-devs"
|
||||
devsRole, err := types.NewRole(mainDevs, types.RoleSpecV5{
|
||||
devsRole, err := types.NewRoleV3(mainDevs, types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{username},
|
||||
},
|
||||
@@ -2066,7 +2066,7 @@ func trustedClusters(t *testing.T, suite *integrationTestSuite, test trustedClus
|
||||
require.NoError(t, err)
|
||||
|
||||
mainAdmins := "main-admins"
|
||||
adminsRole, err := types.NewRole(mainAdmins, types.RoleSpecV5{
|
||||
adminsRole, err := types.NewRoleV3(mainAdmins, types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{"superuser"},
|
||||
},
|
||||
@@ -2077,7 +2077,7 @@ func trustedClusters(t *testing.T, suite *integrationTestSuite, test trustedClus
|
||||
|
||||
// Ops users can only access remote clusters with label 'access': 'ops'
|
||||
mainOps := "main-ops"
|
||||
mainOpsRole, err := types.NewRole(mainOps, types.RoleSpecV5{
|
||||
mainOpsRole, err := types.NewRoleV3(mainOps, types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{username},
|
||||
ClusterLabels: types.Labels{"access": []string{"ops"}},
|
||||
@@ -2106,7 +2106,7 @@ func trustedClusters(t *testing.T, suite *integrationTestSuite, test trustedClus
|
||||
// using trusted clusters, so remote user will be allowed to assume
|
||||
// role specified by mapping remote role "devs" to local role "local-devs"
|
||||
auxDevs := "aux-devs"
|
||||
auxRole, err := types.NewRole(auxDevs, types.RoleSpecV5{
|
||||
auxRole, err := types.NewRoleV3(auxDevs, types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{username},
|
||||
},
|
||||
@@ -2298,7 +2298,7 @@ func testTrustedTunnelNode(t *testing.T, suite *integrationTestSuite) {
|
||||
|
||||
// main cluster has a local user and belongs to role "main-devs"
|
||||
mainDevs := "main-devs"
|
||||
role, err := types.NewRole(mainDevs, types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3(mainDevs, types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{username},
|
||||
},
|
||||
@@ -2326,7 +2326,7 @@ func testTrustedTunnelNode(t *testing.T, suite *integrationTestSuite) {
|
||||
// using trusted clusters, so remote user will be allowed to assume
|
||||
// role specified by mapping remote role "devs" to local role "local-devs"
|
||||
auxDevs := "aux-devs"
|
||||
role, err = types.NewRole(auxDevs, types.RoleSpecV5{
|
||||
role, err = types.NewRoleV3(auxDevs, types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{username},
|
||||
},
|
||||
@@ -3947,7 +3947,7 @@ func testRotateTrustedClusters(t *testing.T, suite *integrationTestSuite) {
|
||||
|
||||
// main cluster has a local user and belongs to role "main-devs"
|
||||
mainDevs := "main-devs"
|
||||
role, err := types.NewRole(mainDevs, types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3(mainDevs, types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{suite.me.Username},
|
||||
},
|
||||
@@ -3965,7 +3965,7 @@ func testRotateTrustedClusters(t *testing.T, suite *integrationTestSuite) {
|
||||
// using trusted clusters, so remote user will be allowed to assume
|
||||
// role specified by mapping remote role "devs" to local role "local-devs"
|
||||
auxDevs := "aux-devs"
|
||||
role, err = types.NewRole(auxDevs, types.RoleSpecV5{
|
||||
role, err = types.NewRoleV3(auxDevs, types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{suite.me.Username},
|
||||
},
|
||||
@@ -4619,7 +4619,7 @@ func testList(t *testing.T, suite *integrationTestSuite) {
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.inRoleName, func(t *testing.T) {
|
||||
// Create role with logins and labels for this test.
|
||||
role, err := types.NewRole(tt.inRoleName, types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3(tt.inRoleName, types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{tt.inLogin},
|
||||
NodeLabels: tt.inLabels,
|
||||
@@ -5352,7 +5352,7 @@ func testSessionStartContainsAccessRequest(t *testing.T, suite *integrationTestS
|
||||
authServer := main.Process.GetAuthServer()
|
||||
|
||||
// Create new request role
|
||||
requestedRole, err := types.NewRole(requestedRoleName, types.RoleSpecV5{
|
||||
requestedRole, err := types.NewRoleV3(requestedRoleName, types.RoleSpecV5{
|
||||
Options: types.RoleOptions{},
|
||||
Allow: types.RoleConditions{},
|
||||
})
|
||||
@@ -5362,7 +5362,7 @@ func testSessionStartContainsAccessRequest(t *testing.T, suite *integrationTestS
|
||||
require.NoError(t, err)
|
||||
|
||||
// Create user role with ability to request role
|
||||
userRole, err := types.NewRole(userRoleName, types.RoleSpecV5{
|
||||
userRole, err := types.NewRoleV3(userRoleName, types.RoleSpecV5{
|
||||
Options: types.RoleOptions{},
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{
|
||||
|
||||
@@ -182,7 +182,7 @@ func testKubeExec(t *testing.T, suite *KubeSuite) {
|
||||
username := suite.me.Username
|
||||
kubeGroups := []string{testImpersonationGroup}
|
||||
kubeUsers := []string{"alice@example.com"}
|
||||
role, err := types.NewRole("kubemaster", types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3("kubemaster", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{username},
|
||||
KubeGroups: kubeGroups,
|
||||
@@ -351,7 +351,7 @@ func testKubeDeny(t *testing.T, suite *KubeSuite) {
|
||||
username := suite.me.Username
|
||||
kubeGroups := []string{testImpersonationGroup}
|
||||
kubeUsers := []string{"alice@example.com"}
|
||||
role, err := types.NewRole("kubemaster", types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3("kubemaster", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{username},
|
||||
KubeGroups: kubeGroups,
|
||||
@@ -402,7 +402,7 @@ func testKubePortForward(t *testing.T, suite *KubeSuite) {
|
||||
|
||||
username := suite.me.Username
|
||||
kubeGroups := []string{testImpersonationGroup}
|
||||
role, err := types.NewRole("kubemaster", types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3("kubemaster", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{username},
|
||||
KubeGroups: kubeGroups,
|
||||
@@ -498,7 +498,7 @@ func testKubeTrustedClustersClientCert(t *testing.T, suite *KubeSuite) {
|
||||
// main cluster has a role and user called main-kube
|
||||
username := suite.me.Username
|
||||
mainKubeGroups := []string{testImpersonationGroup}
|
||||
mainRole, err := types.NewRole("main-kube", types.RoleSpecV5{
|
||||
mainRole, err := types.NewRoleV3("main-kube", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{username},
|
||||
KubeGroups: mainKubeGroups,
|
||||
@@ -533,7 +533,7 @@ func testKubeTrustedClustersClientCert(t *testing.T, suite *KubeSuite) {
|
||||
// using trusted clusters, so remote user will be allowed to assume
|
||||
// role specified by mapping remote role "aux-kube" to local role "main-kube"
|
||||
auxKubeGroups := []string{teleport.TraitInternalKubeGroupsVariable}
|
||||
auxRole, err := types.NewRole("aux-kube", types.RoleSpecV5{
|
||||
auxRole, err := types.NewRoleV3("aux-kube", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{username},
|
||||
// Note that main cluster can pass it's kubernetes groups
|
||||
@@ -749,7 +749,7 @@ func testKubeTrustedClustersSNI(t *testing.T, suite *KubeSuite) {
|
||||
// main cluster has a role and user called main-kube
|
||||
username := suite.me.Username
|
||||
mainKubeGroups := []string{testImpersonationGroup}
|
||||
mainRole, err := types.NewRole("main-kube", types.RoleSpecV5{
|
||||
mainRole, err := types.NewRoleV3("main-kube", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{username},
|
||||
KubeGroups: mainKubeGroups,
|
||||
@@ -788,7 +788,7 @@ func testKubeTrustedClustersSNI(t *testing.T, suite *KubeSuite) {
|
||||
// using trusted clusters, so remote user will be allowed to assume
|
||||
// role specified by mapping remote role "aux-kube" to local role "main-kube"
|
||||
auxKubeGroups := []string{teleport.TraitInternalKubeGroupsVariable}
|
||||
auxRole, err := types.NewRole("aux-kube", types.RoleSpecV5{
|
||||
auxRole, err := types.NewRoleV3("aux-kube", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{username},
|
||||
// Note that main cluster can pass it's kubernetes groups
|
||||
@@ -1023,7 +1023,7 @@ func runKubeDisconnectTest(t *testing.T, suite *KubeSuite, tc disconnectTestCase
|
||||
|
||||
username := suite.me.Username
|
||||
kubeGroups := []string{testImpersonationGroup}
|
||||
role, err := types.NewRole("kubemaster", types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3("kubemaster", types.RoleSpecV5{
|
||||
Options: tc.options,
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{username},
|
||||
@@ -1109,7 +1109,7 @@ func testKubeTransportProtocol(t *testing.T, suite *KubeSuite) {
|
||||
|
||||
username := suite.me.Username
|
||||
kubeGroups := []string{testImpersonationGroup}
|
||||
role, err := types.NewRole("kubemaster", types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3("kubemaster", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{username},
|
||||
KubeGroups: kubeGroups,
|
||||
@@ -1523,7 +1523,7 @@ func testKubeJoin(t *testing.T, suite *KubeSuite) {
|
||||
participantUsername := suite.me.Username + "-participant"
|
||||
kubeGroups := []string{testImpersonationGroup}
|
||||
kubeUsers := []string{"alice@example.com"}
|
||||
role, err := types.NewRole("kubemaster", types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3("kubemaster", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{hostUsername},
|
||||
KubeGroups: kubeGroups,
|
||||
|
||||
@@ -277,7 +277,7 @@ func withLeafClusterPorts(ports *InstancePorts) proxySuiteOptionsFunc {
|
||||
}
|
||||
|
||||
func newRole(t *testing.T, roleName string, username string) types.Role {
|
||||
role, err := types.NewRole(roleName, types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3(roleName, types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{username},
|
||||
},
|
||||
|
||||
@@ -254,7 +254,7 @@ func TestALPNSNIProxyKube(t *testing.T) {
|
||||
KubeUsers: []string{k8User},
|
||||
},
|
||||
}
|
||||
kubeRole, err := types.NewRole(k8RoleName, kubeRoleSpec)
|
||||
kubeRole, err := types.NewRoleV3(k8RoleName, kubeRoleSpec)
|
||||
require.NoError(t, err)
|
||||
|
||||
suite := newProxySuite(t,
|
||||
@@ -306,7 +306,7 @@ func TestALPNSNIProxyKubeV2Leaf(t *testing.T) {
|
||||
KubeUsers: []string{k8User},
|
||||
},
|
||||
}
|
||||
kubeRole, err := types.NewRole(k8RoleName, kubeRoleSpec)
|
||||
kubeRole, err := types.NewRoleV3(k8RoleName, kubeRoleSpec)
|
||||
require.NoError(t, err)
|
||||
|
||||
suite := newProxySuite(t,
|
||||
|
||||
@@ -35,7 +35,7 @@ func TestUpsertDeleteRoleEventsEmitted(t *testing.T) {
|
||||
require.NoError(t, err)
|
||||
|
||||
// test create new role
|
||||
role, err := types.NewRole("test-role", types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3("test-role", types.RoleSpecV5{
|
||||
Options: types.RoleOptions{},
|
||||
Allow: types.RoleConditions{},
|
||||
})
|
||||
|
||||
@@ -323,7 +323,7 @@ func TestGenerateUserCertsWithRoleRequest(t *testing.T) {
|
||||
})
|
||||
require.NoError(t, err)
|
||||
|
||||
dummyUserRole, err := types.NewRole("dummy-user-role", types.RoleSpecV5{})
|
||||
dummyUserRole, err := types.NewRoleV3("dummy-user-role", types.RoleSpecV5{})
|
||||
require.NoError(t, err)
|
||||
|
||||
dummyUser, err := CreateUser(srv.Auth(), "dummy-user", dummyUserRole)
|
||||
@@ -1893,7 +1893,7 @@ func TestKindClusterConfig(t *testing.T) {
|
||||
})
|
||||
|
||||
t.Run("with KindClusterConfig privilege", func(t *testing.T) {
|
||||
role, err := types.NewRole("test-role", types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3("test-role", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Rules: []types.Rule{
|
||||
types.NewRule(types.KindClusterConfig, []string{types.VerbRead}),
|
||||
@@ -1917,7 +1917,7 @@ func TestNoElevatedAccessRequestDeletion(t *testing.T) {
|
||||
require.NoError(t, err)
|
||||
t.Cleanup(func() { srv.Close() })
|
||||
|
||||
deleterRole, err := types.NewRole("deleter", types.RoleSpecV5{
|
||||
deleterRole, err := types.NewRoleV3("deleter", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Rules: []types.Rule{{
|
||||
Resources: []string{"access_request"},
|
||||
@@ -1929,7 +1929,7 @@ func TestNoElevatedAccessRequestDeletion(t *testing.T) {
|
||||
deleterUser, err := CreateUser(srv.AuthServer, "deletey", deleterRole)
|
||||
require.NoError(t, err)
|
||||
|
||||
requesterRole, err := types.NewRole("requester", types.RoleSpecV5{
|
||||
requesterRole, err := types.NewRoleV3("requester", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Request: &types.AccessRequestConditions{
|
||||
Roles: []string{deleterRole.GetName()},
|
||||
|
||||
+1
-1
@@ -44,7 +44,7 @@ func BotResourceName(botName string) string {
|
||||
|
||||
// createBotRole creates a role from a bot template with the given parameters.
|
||||
func createBotRole(ctx context.Context, s *Server, botName string, resourceName string, roleRequests []string) (types.Role, error) {
|
||||
role, err := types.NewRole(resourceName, types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3(resourceName, types.RoleSpecV5{
|
||||
Options: types.RoleOptions{
|
||||
// TODO: inherit TTLs from cert length?
|
||||
MaxSessionTTL: types.Duration(12 * time.Hour),
|
||||
|
||||
+1
-1
@@ -923,7 +923,7 @@ type clt interface {
|
||||
|
||||
// CreateRole creates a role without assigning any users. Used in tests.
|
||||
func CreateRole(ctx context.Context, clt clt, name string, spec types.RoleSpecV5) (types.Role, error) {
|
||||
role, err := types.NewRole(name, spec)
|
||||
role, err := types.NewRoleV3(name, spec)
|
||||
if err != nil {
|
||||
return nil, trace.Wrap(err)
|
||||
}
|
||||
|
||||
@@ -32,9 +32,9 @@ type startTestCase struct {
|
||||
}
|
||||
|
||||
func successStartTestCase(t *testing.T) startTestCase {
|
||||
hostRole, err := types.NewRoleV5("host", types.RoleSpecV5{})
|
||||
hostRole, err := types.NewRole("host", types.RoleSpecV5{})
|
||||
require.NoError(t, err)
|
||||
participantRole, err := types.NewRoleV5("participant", types.RoleSpecV5{})
|
||||
participantRole, err := types.NewRole("participant", types.RoleSpecV5{})
|
||||
require.NoError(t, err)
|
||||
|
||||
hostRole.SetSessionRequirePolicies([]*types.SessionRequirePolicy{{
|
||||
@@ -72,9 +72,9 @@ func successStartTestCase(t *testing.T) startTestCase {
|
||||
}
|
||||
|
||||
func failCountStartTestCase(t *testing.T) startTestCase {
|
||||
hostRole, err := types.NewRoleV5("host", types.RoleSpecV5{})
|
||||
hostRole, err := types.NewRole("host", types.RoleSpecV5{})
|
||||
require.NoError(t, err)
|
||||
participantRole, err := types.NewRoleV5("participant", types.RoleSpecV5{})
|
||||
participantRole, err := types.NewRole("participant", types.RoleSpecV5{})
|
||||
require.NoError(t, err)
|
||||
|
||||
hostRole.SetSessionRequirePolicies([]*types.SessionRequirePolicy{{
|
||||
@@ -111,9 +111,9 @@ func failCountStartTestCase(t *testing.T) startTestCase {
|
||||
}
|
||||
|
||||
func failFilterStartTestCase(t *testing.T) startTestCase {
|
||||
hostRole, err := types.NewRoleV5("host", types.RoleSpecV5{})
|
||||
hostRole, err := types.NewRole("host", types.RoleSpecV5{})
|
||||
require.NoError(t, err)
|
||||
participantRole, err := types.NewRoleV5("participant", types.RoleSpecV5{})
|
||||
participantRole, err := types.NewRole("participant", types.RoleSpecV5{})
|
||||
require.NoError(t, err)
|
||||
|
||||
hostRole.SetSessionRequirePolicies([]*types.SessionRequirePolicy{{
|
||||
@@ -176,9 +176,9 @@ type joinTestCase struct {
|
||||
}
|
||||
|
||||
func successJoinTestCase(t *testing.T) joinTestCase {
|
||||
hostRole, err := types.NewRoleV5("host", types.RoleSpecV5{})
|
||||
hostRole, err := types.NewRole("host", types.RoleSpecV5{})
|
||||
require.NoError(t, err)
|
||||
participantRole, err := types.NewRoleV5("participant", types.RoleSpecV5{})
|
||||
participantRole, err := types.NewRole("participant", types.RoleSpecV5{})
|
||||
require.NoError(t, err)
|
||||
|
||||
participantRole.SetSessionJoinPolicies([]*types.SessionJoinPolicy{{
|
||||
@@ -200,9 +200,9 @@ func successJoinTestCase(t *testing.T) joinTestCase {
|
||||
}
|
||||
|
||||
func failRoleJoinTestCase(t *testing.T) joinTestCase {
|
||||
hostRole, err := types.NewRoleV5("host", types.RoleSpecV5{})
|
||||
hostRole, err := types.NewRole("host", types.RoleSpecV5{})
|
||||
require.NoError(t, err)
|
||||
participantRole, err := types.NewRoleV5("participant", types.RoleSpecV5{})
|
||||
participantRole, err := types.NewRole("participant", types.RoleSpecV5{})
|
||||
require.NoError(t, err)
|
||||
|
||||
return joinTestCase{
|
||||
@@ -218,9 +218,9 @@ func failRoleJoinTestCase(t *testing.T) joinTestCase {
|
||||
}
|
||||
|
||||
func failKindJoinTestCase(t *testing.T) joinTestCase {
|
||||
hostRole, err := types.NewRoleV5("host", types.RoleSpecV5{})
|
||||
hostRole, err := types.NewRole("host", types.RoleSpecV5{})
|
||||
require.NoError(t, err)
|
||||
participantRole, err := types.NewRoleV5("participant", types.RoleSpecV5{})
|
||||
participantRole, err := types.NewRole("participant", types.RoleSpecV5{})
|
||||
require.NoError(t, err)
|
||||
|
||||
participantRole.SetSessionJoinPolicies([]*types.SessionJoinPolicy{{
|
||||
|
||||
@@ -2045,7 +2045,7 @@ func TestGenerateCerts(t *testing.T) {
|
||||
t.Run("ImpersonateAllow", func(t *testing.T) {
|
||||
// Super impersonator impersonate anyone and login as root
|
||||
maxSessionTTL := 300 * time.Hour
|
||||
superImpersonatorRole, err := types.NewRole("superimpersonator", types.RoleSpecV5{
|
||||
superImpersonatorRole, err := types.NewRoleV3("superimpersonator", types.RoleSpecV5{
|
||||
Options: types.RoleOptions{
|
||||
MaxSessionTTL: types.Duration(maxSessionTTL),
|
||||
},
|
||||
@@ -2063,7 +2063,7 @@ func TestGenerateCerts(t *testing.T) {
|
||||
require.NoError(t, err)
|
||||
|
||||
// Impersonator can generate certificates for super impersonator
|
||||
role, err := types.NewRole("impersonate", types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3("impersonate", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{superImpersonator.GetName()},
|
||||
Impersonate: &types.ImpersonateConditions{
|
||||
|
||||
Vendored
+1
-1
@@ -1405,7 +1405,7 @@ func TestRoles(t *testing.T) {
|
||||
p := newPackForNode(t)
|
||||
t.Cleanup(p.Close)
|
||||
|
||||
role, err := types.NewRole("role1", types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3("role1", types.RoleSpecV5{
|
||||
Options: types.RoleOptions{
|
||||
MaxSessionTTL: types.Duration(time.Hour),
|
||||
},
|
||||
|
||||
@@ -186,7 +186,7 @@ func newStandaloneTeleport(t *testing.T, clock clockwork.Clock) *standaloneBundl
|
||||
|
||||
user, err := types.NewUser("llama")
|
||||
require.NoError(t, err)
|
||||
role, err := types.NewRole(user.GetName(), types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3(user.GetName(), types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{user.GetName()},
|
||||
},
|
||||
|
||||
@@ -93,7 +93,7 @@ func createUser(name string, roles []string, traits map[string][]string) (types.
|
||||
}
|
||||
|
||||
func createRole(name string, allowLogins []string, denyLogins []string, allowLabels types.Labels, denyLabels types.Labels) (types.Role, error) {
|
||||
role, err := types.NewRole(name, types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3(name, types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: allowLogins,
|
||||
NodeLabels: allowLabels,
|
||||
|
||||
@@ -176,7 +176,7 @@ func TestReviewThresholds(t *testing.T) {
|
||||
roles := make(map[string]types.Role)
|
||||
|
||||
for name, conditions := range roleDesc {
|
||||
role, err := types.NewRole(name, types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3(name, types.RoleSpecV5{
|
||||
Allow: conditions,
|
||||
})
|
||||
require.NoError(t, err)
|
||||
|
||||
@@ -122,7 +122,7 @@ func NewImplicitRole() types.Role {
|
||||
//
|
||||
// Used in tests only.
|
||||
func RoleForUser(u types.User) types.Role {
|
||||
role, _ := types.NewRole(RoleNameForUser(u.GetName()), types.RoleSpecV5{
|
||||
role, _ := types.NewRoleV3(RoleNameForUser(u.GetName()), types.RoleSpecV5{
|
||||
Options: types.RoleOptions{
|
||||
CertificateFormat: constants.CertificateFormatStandard,
|
||||
MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration),
|
||||
@@ -156,7 +156,7 @@ func RoleForUser(u types.User) types.Role {
|
||||
|
||||
// RoleForCertAuthority creates role using types.CertAuthority.
|
||||
func RoleForCertAuthority(ca types.CertAuthority) types.Role {
|
||||
role, _ := types.NewRole(RoleNameForCertAuthority(ca.GetClusterName()), types.RoleSpecV5{
|
||||
role, _ := types.NewRoleV3(RoleNameForCertAuthority(ca.GetClusterName()), types.RoleSpecV5{
|
||||
Options: types.RoleOptions{
|
||||
MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration),
|
||||
},
|
||||
@@ -730,7 +730,7 @@ type AccessChecker interface {
|
||||
|
||||
// FromSpec returns new RoleSet created from spec
|
||||
func FromSpec(name string, spec types.RoleSpecV5) (RoleSet, error) {
|
||||
role, err := types.NewRole(name, spec)
|
||||
role, err := types.NewRoleV3(name, spec)
|
||||
if err != nil {
|
||||
return nil, trace.Wrap(err)
|
||||
}
|
||||
|
||||
@@ -1506,7 +1506,7 @@ func TestCheckRuleAccess(t *testing.T) {
|
||||
|
||||
func TestGuessIfAccessIsPossible(t *testing.T) {
|
||||
// Examples from https://goteleport.com/docs/access-controls/reference/#rbac-for-sessions.
|
||||
ownSessions, err := types.NewRole("own-sessions", types.RoleSpecV5{
|
||||
ownSessions, err := types.NewRoleV3("own-sessions", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Rules: []types.Rule{
|
||||
{
|
||||
@@ -1518,7 +1518,7 @@ func TestGuessIfAccessIsPossible(t *testing.T) {
|
||||
},
|
||||
})
|
||||
require.NoError(t, err)
|
||||
ownSSHSessions, err := types.NewRole("own-ssh-sessions", types.RoleSpecV5{
|
||||
ownSSHSessions, err := types.NewRoleV3("own-ssh-sessions", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Rules: []types.Rule{
|
||||
{
|
||||
@@ -1540,7 +1540,7 @@ func TestGuessIfAccessIsPossible(t *testing.T) {
|
||||
require.NoError(t, err)
|
||||
|
||||
// Simple, all-or-nothing roles.
|
||||
readAllSessions, err := types.NewRole("all-sessions", types.RoleSpecV5{
|
||||
readAllSessions, err := types.NewRoleV3("all-sessions", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Rules: []types.Rule{
|
||||
{
|
||||
@@ -1551,7 +1551,7 @@ func TestGuessIfAccessIsPossible(t *testing.T) {
|
||||
},
|
||||
})
|
||||
require.NoError(t, err)
|
||||
allowSSHSessions, err := types.NewRole("all-ssh-sessions", types.RoleSpecV5{
|
||||
allowSSHSessions, err := types.NewRoleV3("all-ssh-sessions", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Rules: []types.Rule{
|
||||
{
|
||||
@@ -1562,7 +1562,7 @@ func TestGuessIfAccessIsPossible(t *testing.T) {
|
||||
},
|
||||
})
|
||||
require.NoError(t, err)
|
||||
denySSHSessions, err := types.NewRole("deny-ssh-sessions", types.RoleSpecV5{
|
||||
denySSHSessions, err := types.NewRoleV3("deny-ssh-sessions", types.RoleSpecV5{
|
||||
Deny: types.RoleConditions{
|
||||
Rules: []types.Rule{
|
||||
{
|
||||
@@ -3536,7 +3536,7 @@ func TestRoleSetLockingMode(t *testing.T) {
|
||||
|
||||
missingMode := constants.LockingMode("")
|
||||
newRoleWithLockingMode := func(t *testing.T, mode constants.LockingMode) types.Role {
|
||||
role, err := types.NewRole(uuid.New().String(), types.RoleSpecV5{Options: types.RoleOptions{Lock: mode}})
|
||||
role, err := types.NewRoleV3(uuid.New().String(), types.RoleSpecV5{Options: types.RoleOptions{Lock: mode}})
|
||||
require.NoError(t, err)
|
||||
return role
|
||||
}
|
||||
@@ -3575,14 +3575,14 @@ func TestExtractConditionForIdentifier(t *testing.T) {
|
||||
require.True(t, trace.IsAccessDenied(err))
|
||||
|
||||
allowWhere := func(where string) types.Role {
|
||||
role, err := types.NewRole(uuid.New().String(), types.RoleSpecV5{Allow: types.RoleConditions{
|
||||
role, err := types.NewRoleV3(uuid.New().String(), types.RoleSpecV5{Allow: types.RoleConditions{
|
||||
Rules: []types.Rule{{Resources: []string{types.KindSession}, Verbs: []string{types.VerbList}, Where: where}},
|
||||
}})
|
||||
require.NoError(t, err)
|
||||
return role
|
||||
}
|
||||
denyWhere := func(where string) types.Role {
|
||||
role, err := types.NewRole(uuid.New().String(), types.RoleSpecV5{Deny: types.RoleConditions{
|
||||
role, err := types.NewRoleV3(uuid.New().String(), types.RoleSpecV5{Deny: types.RoleConditions{
|
||||
Rules: []types.Rule{{Resources: []string{types.KindSession}, Verbs: []string{types.VerbList}, Where: where}},
|
||||
}})
|
||||
require.NoError(t, err)
|
||||
|
||||
@@ -1461,7 +1461,7 @@ func (s *ServicesTestSuite) Events(c *check.C) {
|
||||
Kind: types.KindRole,
|
||||
},
|
||||
crud: func(context.Context) types.Resource {
|
||||
role, err := types.NewRole("role1", types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3("role1", types.RoleSpecV5{
|
||||
Options: types.RoleOptions{
|
||||
MaxSessionTTL: types.Duration(time.Hour),
|
||||
},
|
||||
|
||||
@@ -517,7 +517,7 @@ func (s *WebSuite) TestSAMLSuccess(c *C) {
|
||||
err = services.ValidateSAMLConnector(connector)
|
||||
c.Assert(err, IsNil)
|
||||
|
||||
role, err := types.NewRole(connector.GetAttributesToRoles()[0].Roles[0], types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3(connector.GetAttributesToRoles()[0].Roles[0], types.RoleSpecV5{
|
||||
Options: types.RoleOptions{
|
||||
MaxSessionTTL: types.NewDuration(apidefaults.MaxCertDuration),
|
||||
},
|
||||
|
||||
@@ -122,7 +122,7 @@ spec:
|
||||
desktop: true
|
||||
version: v3
|
||||
`
|
||||
role, err := types.NewRole("roleName", types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3("roleName", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{"test"},
|
||||
},
|
||||
@@ -167,7 +167,7 @@ func TestGetRoles(t *testing.T) {
|
||||
m := &mockedResourceAPIGetter{}
|
||||
|
||||
m.mockGetRoles = func(ctx context.Context) ([]types.Role, error) {
|
||||
role, err := types.NewRole("test", types.RoleSpecV5{
|
||||
role, err := types.NewRoleV3("test", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{"test"},
|
||||
},
|
||||
|
||||
@@ -174,7 +174,7 @@ func TestProxySSHDial(t *testing.T) {
|
||||
tmpHomePath := t.TempDir()
|
||||
|
||||
connector := mockConnector(t)
|
||||
sshLoginRole, err := types.NewRole("ssh-login", types.RoleSpecV5{
|
||||
sshLoginRole, err := types.NewRoleV3("ssh-login", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{"alice"},
|
||||
},
|
||||
|
||||
@@ -84,7 +84,7 @@ func (s *suite) setupRootCluster(t *testing.T, options testSuiteOptions) {
|
||||
require.NoError(t, err)
|
||||
|
||||
s.connector = mockConnector(t)
|
||||
sshLoginRole, err := types.NewRole("ssh-login", types.RoleSpecV5{
|
||||
sshLoginRole, err := types.NewRoleV3("ssh-login", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{user.Username},
|
||||
},
|
||||
@@ -143,7 +143,7 @@ func (s *suite) setupLeafCluster(t *testing.T) {
|
||||
require.NoError(t, err)
|
||||
|
||||
cfg.Proxy.DisableWebInterface = true
|
||||
sshLoginRole, err := types.NewRole("ssh-login", types.RoleSpecV5{
|
||||
sshLoginRole, err := types.NewRoleV3("ssh-login", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Logins: []string{user.Username},
|
||||
},
|
||||
|
||||
@@ -153,7 +153,7 @@ func TestOIDCLogin(t *testing.T) {
|
||||
|
||||
// set up an initial role with `request_access: always` in order to
|
||||
// trigger automatic post-login escalation.
|
||||
populist, err := types.NewRole("populist", types.RoleSpecV5{
|
||||
populist, err := types.NewRoleV3("populist", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Request: &types.AccessRequestConditions{
|
||||
Roles: []string{"dictator"},
|
||||
@@ -166,7 +166,7 @@ func TestOIDCLogin(t *testing.T) {
|
||||
require.NoError(t, err)
|
||||
|
||||
// empty role which serves as our escalation target
|
||||
dictator, err := types.NewRole("dictator", types.RoleSpecV5{})
|
||||
dictator, err := types.NewRoleV3("dictator", types.RoleSpecV5{})
|
||||
require.NoError(t, err)
|
||||
|
||||
alice, err := types.NewUser("alice@example.com")
|
||||
@@ -444,7 +444,7 @@ func TestAccessRequestOnLeaf(t *testing.T) {
|
||||
lib.SetInsecureDevMode(isInsecure)
|
||||
})
|
||||
|
||||
requester, err := types.NewRole("requester", types.RoleSpecV5{
|
||||
requester, err := types.NewRoleV3("requester", types.RoleSpecV5{
|
||||
Allow: types.RoleConditions{
|
||||
Request: &types.AccessRequestConditions{
|
||||
Roles: []string{"access"},
|
||||
|
||||
Reference in New Issue
Block a user