diff --git a/api/types/role.go b/api/types/role.go index 2f4d0ad9af9..0953b122624 100644 --- a/api/types/role.go +++ b/api/types/role.go @@ -159,11 +159,11 @@ type Role interface { GetSessionPolicySet() SessionTrackerPolicySet } -// NewRole constructs new standard V3 role. -// This is mostly a legacy function and will create a role with V3 RBAC semantics. +// NewRole constructs new standard V5 role. +// This creates a V5 role with V4+ RBAC semantics. func NewRole(name string, spec RoleSpecV5) (Role, error) { role := RoleV5{ - Version: V3, + Version: V5, Metadata: Metadata{ Name: name, }, @@ -175,11 +175,11 @@ func NewRole(name string, spec RoleSpecV5) (Role, error) { return &role, nil } -// NewRoleV5 constructs new standard V5 role. -// This creates a V5 role with V4+ RBAC semantics. This should be preferred over `NewRole`. -func NewRoleV5(name string, spec RoleSpecV5) (Role, error) { +// NewRoleV3 constructs new standard V3 role. +// This is mostly a legacy function and will create a role with V3 RBAC semantics. +func NewRoleV3(name string, spec RoleSpecV5) (Role, error) { role := RoleV5{ - Version: V5, + Version: V3, Metadata: Metadata{ Name: name, }, @@ -604,11 +604,8 @@ func (r *RoleV5) SetRules(rct RoleConditionType, in []Rule) { // setStaticFields sets static resource header and metadata fields. func (r *RoleV5) setStaticFields() { r.Kind = KindRole - // TODO(Joerger/nklaassen) Role should default to V4 - // but shouldn't overwrite V3. For now, this does the - // opposite due to an internal reliance on V3 defaults. - if r.Version != V4 && r.Version != V5 { - r.Version = V3 + if r.Version != V3 && r.Version != V4 { + r.Version = V5 } } diff --git a/integration/integration_test.go b/integration/integration_test.go index 0937fb7972d..b4df14cf2a2 100644 --- a/integration/integration_test.go +++ b/integration/integration_test.go @@ -1179,7 +1179,7 @@ func runDisconnectTest(t *testing.T, suite *integrationTestSuite, tc disconnectT teleport := suite.newTeleportInstance() username := suite.me.Username - role, err := types.NewRole("devs", types.RoleSpecV5{ + role, err := types.NewRoleV3("devs", types.RoleSpecV5{ Options: tc.options, Allow: types.RoleConditions{ Logins: []string{username}, @@ -1741,7 +1741,7 @@ func testMapRoles(t *testing.T, suite *integrationTestSuite) { // main cluster has a local user and belongs to role "main-devs" mainDevs := "main-devs" - role, err := types.NewRole(mainDevs, types.RoleSpecV5{ + role, err := types.NewRoleV3(mainDevs, types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{username}, }, @@ -1769,7 +1769,7 @@ func testMapRoles(t *testing.T, suite *integrationTestSuite) { // using trusted clusters, so remote user will be allowed to assume // role specified by mapping remote role "devs" to local role "local-devs" auxDevs := "aux-devs" - role, err = types.NewRole(auxDevs, types.RoleSpecV5{ + role, err = types.NewRoleV3(auxDevs, types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{username}, }, @@ -2051,7 +2051,7 @@ func trustedClusters(t *testing.T, suite *integrationTestSuite, test trustedClus // main cluster has a local user and belongs to role "main-devs" and "main-admins" mainDevs := "main-devs" - devsRole, err := types.NewRole(mainDevs, types.RoleSpecV5{ + devsRole, err := types.NewRoleV3(mainDevs, types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{username}, }, @@ -2066,7 +2066,7 @@ func trustedClusters(t *testing.T, suite *integrationTestSuite, test trustedClus require.NoError(t, err) mainAdmins := "main-admins" - adminsRole, err := types.NewRole(mainAdmins, types.RoleSpecV5{ + adminsRole, err := types.NewRoleV3(mainAdmins, types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{"superuser"}, }, @@ -2077,7 +2077,7 @@ func trustedClusters(t *testing.T, suite *integrationTestSuite, test trustedClus // Ops users can only access remote clusters with label 'access': 'ops' mainOps := "main-ops" - mainOpsRole, err := types.NewRole(mainOps, types.RoleSpecV5{ + mainOpsRole, err := types.NewRoleV3(mainOps, types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{username}, ClusterLabels: types.Labels{"access": []string{"ops"}}, @@ -2106,7 +2106,7 @@ func trustedClusters(t *testing.T, suite *integrationTestSuite, test trustedClus // using trusted clusters, so remote user will be allowed to assume // role specified by mapping remote role "devs" to local role "local-devs" auxDevs := "aux-devs" - auxRole, err := types.NewRole(auxDevs, types.RoleSpecV5{ + auxRole, err := types.NewRoleV3(auxDevs, types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{username}, }, @@ -2298,7 +2298,7 @@ func testTrustedTunnelNode(t *testing.T, suite *integrationTestSuite) { // main cluster has a local user and belongs to role "main-devs" mainDevs := "main-devs" - role, err := types.NewRole(mainDevs, types.RoleSpecV5{ + role, err := types.NewRoleV3(mainDevs, types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{username}, }, @@ -2326,7 +2326,7 @@ func testTrustedTunnelNode(t *testing.T, suite *integrationTestSuite) { // using trusted clusters, so remote user will be allowed to assume // role specified by mapping remote role "devs" to local role "local-devs" auxDevs := "aux-devs" - role, err = types.NewRole(auxDevs, types.RoleSpecV5{ + role, err = types.NewRoleV3(auxDevs, types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{username}, }, @@ -3947,7 +3947,7 @@ func testRotateTrustedClusters(t *testing.T, suite *integrationTestSuite) { // main cluster has a local user and belongs to role "main-devs" mainDevs := "main-devs" - role, err := types.NewRole(mainDevs, types.RoleSpecV5{ + role, err := types.NewRoleV3(mainDevs, types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{suite.me.Username}, }, @@ -3965,7 +3965,7 @@ func testRotateTrustedClusters(t *testing.T, suite *integrationTestSuite) { // using trusted clusters, so remote user will be allowed to assume // role specified by mapping remote role "devs" to local role "local-devs" auxDevs := "aux-devs" - role, err = types.NewRole(auxDevs, types.RoleSpecV5{ + role, err = types.NewRoleV3(auxDevs, types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{suite.me.Username}, }, @@ -4619,7 +4619,7 @@ func testList(t *testing.T, suite *integrationTestSuite) { for _, tt := range tests { t.Run(tt.inRoleName, func(t *testing.T) { // Create role with logins and labels for this test. - role, err := types.NewRole(tt.inRoleName, types.RoleSpecV5{ + role, err := types.NewRoleV3(tt.inRoleName, types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{tt.inLogin}, NodeLabels: tt.inLabels, @@ -5352,7 +5352,7 @@ func testSessionStartContainsAccessRequest(t *testing.T, suite *integrationTestS authServer := main.Process.GetAuthServer() // Create new request role - requestedRole, err := types.NewRole(requestedRoleName, types.RoleSpecV5{ + requestedRole, err := types.NewRoleV3(requestedRoleName, types.RoleSpecV5{ Options: types.RoleOptions{}, Allow: types.RoleConditions{}, }) @@ -5362,7 +5362,7 @@ func testSessionStartContainsAccessRequest(t *testing.T, suite *integrationTestS require.NoError(t, err) // Create user role with ability to request role - userRole, err := types.NewRole(userRoleName, types.RoleSpecV5{ + userRole, err := types.NewRoleV3(userRoleName, types.RoleSpecV5{ Options: types.RoleOptions{}, Allow: types.RoleConditions{ Logins: []string{ diff --git a/integration/kube_integration_test.go b/integration/kube_integration_test.go index cc9292677ad..44dd4a06b8f 100644 --- a/integration/kube_integration_test.go +++ b/integration/kube_integration_test.go @@ -182,7 +182,7 @@ func testKubeExec(t *testing.T, suite *KubeSuite) { username := suite.me.Username kubeGroups := []string{testImpersonationGroup} kubeUsers := []string{"alice@example.com"} - role, err := types.NewRole("kubemaster", types.RoleSpecV5{ + role, err := types.NewRoleV3("kubemaster", types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{username}, KubeGroups: kubeGroups, @@ -351,7 +351,7 @@ func testKubeDeny(t *testing.T, suite *KubeSuite) { username := suite.me.Username kubeGroups := []string{testImpersonationGroup} kubeUsers := []string{"alice@example.com"} - role, err := types.NewRole("kubemaster", types.RoleSpecV5{ + role, err := types.NewRoleV3("kubemaster", types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{username}, KubeGroups: kubeGroups, @@ -402,7 +402,7 @@ func testKubePortForward(t *testing.T, suite *KubeSuite) { username := suite.me.Username kubeGroups := []string{testImpersonationGroup} - role, err := types.NewRole("kubemaster", types.RoleSpecV5{ + role, err := types.NewRoleV3("kubemaster", types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{username}, KubeGroups: kubeGroups, @@ -498,7 +498,7 @@ func testKubeTrustedClustersClientCert(t *testing.T, suite *KubeSuite) { // main cluster has a role and user called main-kube username := suite.me.Username mainKubeGroups := []string{testImpersonationGroup} - mainRole, err := types.NewRole("main-kube", types.RoleSpecV5{ + mainRole, err := types.NewRoleV3("main-kube", types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{username}, KubeGroups: mainKubeGroups, @@ -533,7 +533,7 @@ func testKubeTrustedClustersClientCert(t *testing.T, suite *KubeSuite) { // using trusted clusters, so remote user will be allowed to assume // role specified by mapping remote role "aux-kube" to local role "main-kube" auxKubeGroups := []string{teleport.TraitInternalKubeGroupsVariable} - auxRole, err := types.NewRole("aux-kube", types.RoleSpecV5{ + auxRole, err := types.NewRoleV3("aux-kube", types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{username}, // Note that main cluster can pass it's kubernetes groups @@ -749,7 +749,7 @@ func testKubeTrustedClustersSNI(t *testing.T, suite *KubeSuite) { // main cluster has a role and user called main-kube username := suite.me.Username mainKubeGroups := []string{testImpersonationGroup} - mainRole, err := types.NewRole("main-kube", types.RoleSpecV5{ + mainRole, err := types.NewRoleV3("main-kube", types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{username}, KubeGroups: mainKubeGroups, @@ -788,7 +788,7 @@ func testKubeTrustedClustersSNI(t *testing.T, suite *KubeSuite) { // using trusted clusters, so remote user will be allowed to assume // role specified by mapping remote role "aux-kube" to local role "main-kube" auxKubeGroups := []string{teleport.TraitInternalKubeGroupsVariable} - auxRole, err := types.NewRole("aux-kube", types.RoleSpecV5{ + auxRole, err := types.NewRoleV3("aux-kube", types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{username}, // Note that main cluster can pass it's kubernetes groups @@ -1023,7 +1023,7 @@ func runKubeDisconnectTest(t *testing.T, suite *KubeSuite, tc disconnectTestCase username := suite.me.Username kubeGroups := []string{testImpersonationGroup} - role, err := types.NewRole("kubemaster", types.RoleSpecV5{ + role, err := types.NewRoleV3("kubemaster", types.RoleSpecV5{ Options: tc.options, Allow: types.RoleConditions{ Logins: []string{username}, @@ -1109,7 +1109,7 @@ func testKubeTransportProtocol(t *testing.T, suite *KubeSuite) { username := suite.me.Username kubeGroups := []string{testImpersonationGroup} - role, err := types.NewRole("kubemaster", types.RoleSpecV5{ + role, err := types.NewRoleV3("kubemaster", types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{username}, KubeGroups: kubeGroups, @@ -1523,7 +1523,7 @@ func testKubeJoin(t *testing.T, suite *KubeSuite) { participantUsername := suite.me.Username + "-participant" kubeGroups := []string{testImpersonationGroup} kubeUsers := []string{"alice@example.com"} - role, err := types.NewRole("kubemaster", types.RoleSpecV5{ + role, err := types.NewRoleV3("kubemaster", types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{hostUsername}, KubeGroups: kubeGroups, diff --git a/integration/proxy_helpers_test.go b/integration/proxy_helpers_test.go index bffe58e25c1..74fe3376c29 100644 --- a/integration/proxy_helpers_test.go +++ b/integration/proxy_helpers_test.go @@ -277,7 +277,7 @@ func withLeafClusterPorts(ports *InstancePorts) proxySuiteOptionsFunc { } func newRole(t *testing.T, roleName string, username string) types.Role { - role, err := types.NewRole(roleName, types.RoleSpecV5{ + role, err := types.NewRoleV3(roleName, types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{username}, }, diff --git a/integration/proxy_test.go b/integration/proxy_test.go index e45126e01b6..87516fae4fe 100644 --- a/integration/proxy_test.go +++ b/integration/proxy_test.go @@ -254,7 +254,7 @@ func TestALPNSNIProxyKube(t *testing.T) { KubeUsers: []string{k8User}, }, } - kubeRole, err := types.NewRole(k8RoleName, kubeRoleSpec) + kubeRole, err := types.NewRoleV3(k8RoleName, kubeRoleSpec) require.NoError(t, err) suite := newProxySuite(t, @@ -306,7 +306,7 @@ func TestALPNSNIProxyKubeV2Leaf(t *testing.T) { KubeUsers: []string{k8User}, }, } - kubeRole, err := types.NewRole(k8RoleName, kubeRoleSpec) + kubeRole, err := types.NewRoleV3(k8RoleName, kubeRoleSpec) require.NoError(t, err) suite := newProxySuite(t, diff --git a/lib/auth/access_test.go b/lib/auth/access_test.go index 071ca602016..07312080313 100644 --- a/lib/auth/access_test.go +++ b/lib/auth/access_test.go @@ -35,7 +35,7 @@ func TestUpsertDeleteRoleEventsEmitted(t *testing.T) { require.NoError(t, err) // test create new role - role, err := types.NewRole("test-role", types.RoleSpecV5{ + role, err := types.NewRoleV3("test-role", types.RoleSpecV5{ Options: types.RoleOptions{}, Allow: types.RoleConditions{}, }) diff --git a/lib/auth/auth_with_roles_test.go b/lib/auth/auth_with_roles_test.go index 35909a8060c..5855cf8dab5 100644 --- a/lib/auth/auth_with_roles_test.go +++ b/lib/auth/auth_with_roles_test.go @@ -323,7 +323,7 @@ func TestGenerateUserCertsWithRoleRequest(t *testing.T) { }) require.NoError(t, err) - dummyUserRole, err := types.NewRole("dummy-user-role", types.RoleSpecV5{}) + dummyUserRole, err := types.NewRoleV3("dummy-user-role", types.RoleSpecV5{}) require.NoError(t, err) dummyUser, err := CreateUser(srv.Auth(), "dummy-user", dummyUserRole) @@ -1893,7 +1893,7 @@ func TestKindClusterConfig(t *testing.T) { }) t.Run("with KindClusterConfig privilege", func(t *testing.T) { - role, err := types.NewRole("test-role", types.RoleSpecV5{ + role, err := types.NewRoleV3("test-role", types.RoleSpecV5{ Allow: types.RoleConditions{ Rules: []types.Rule{ types.NewRule(types.KindClusterConfig, []string{types.VerbRead}), @@ -1917,7 +1917,7 @@ func TestNoElevatedAccessRequestDeletion(t *testing.T) { require.NoError(t, err) t.Cleanup(func() { srv.Close() }) - deleterRole, err := types.NewRole("deleter", types.RoleSpecV5{ + deleterRole, err := types.NewRoleV3("deleter", types.RoleSpecV5{ Allow: types.RoleConditions{ Rules: []types.Rule{{ Resources: []string{"access_request"}, @@ -1929,7 +1929,7 @@ func TestNoElevatedAccessRequestDeletion(t *testing.T) { deleterUser, err := CreateUser(srv.AuthServer, "deletey", deleterRole) require.NoError(t, err) - requesterRole, err := types.NewRole("requester", types.RoleSpecV5{ + requesterRole, err := types.NewRoleV3("requester", types.RoleSpecV5{ Allow: types.RoleConditions{ Request: &types.AccessRequestConditions{ Roles: []string{deleterRole.GetName()}, diff --git a/lib/auth/bot.go b/lib/auth/bot.go index cbc0ddc7294..f993db64624 100644 --- a/lib/auth/bot.go +++ b/lib/auth/bot.go @@ -44,7 +44,7 @@ func BotResourceName(botName string) string { // createBotRole creates a role from a bot template with the given parameters. func createBotRole(ctx context.Context, s *Server, botName string, resourceName string, roleRequests []string) (types.Role, error) { - role, err := types.NewRole(resourceName, types.RoleSpecV5{ + role, err := types.NewRoleV3(resourceName, types.RoleSpecV5{ Options: types.RoleOptions{ // TODO: inherit TTLs from cert length? MaxSessionTTL: types.Duration(12 * time.Hour), diff --git a/lib/auth/helpers.go b/lib/auth/helpers.go index 397aeb6d02f..60726b7f124 100644 --- a/lib/auth/helpers.go +++ b/lib/auth/helpers.go @@ -923,7 +923,7 @@ type clt interface { // CreateRole creates a role without assigning any users. Used in tests. func CreateRole(ctx context.Context, clt clt, name string, spec types.RoleSpecV5) (types.Role, error) { - role, err := types.NewRole(name, spec) + role, err := types.NewRoleV3(name, spec) if err != nil { return nil, trace.Wrap(err) } diff --git a/lib/auth/session_access_test.go b/lib/auth/session_access_test.go index 0f2f6187d50..8ce73ef35e0 100644 --- a/lib/auth/session_access_test.go +++ b/lib/auth/session_access_test.go @@ -32,9 +32,9 @@ type startTestCase struct { } func successStartTestCase(t *testing.T) startTestCase { - hostRole, err := types.NewRoleV5("host", types.RoleSpecV5{}) + hostRole, err := types.NewRole("host", types.RoleSpecV5{}) require.NoError(t, err) - participantRole, err := types.NewRoleV5("participant", types.RoleSpecV5{}) + participantRole, err := types.NewRole("participant", types.RoleSpecV5{}) require.NoError(t, err) hostRole.SetSessionRequirePolicies([]*types.SessionRequirePolicy{{ @@ -72,9 +72,9 @@ func successStartTestCase(t *testing.T) startTestCase { } func failCountStartTestCase(t *testing.T) startTestCase { - hostRole, err := types.NewRoleV5("host", types.RoleSpecV5{}) + hostRole, err := types.NewRole("host", types.RoleSpecV5{}) require.NoError(t, err) - participantRole, err := types.NewRoleV5("participant", types.RoleSpecV5{}) + participantRole, err := types.NewRole("participant", types.RoleSpecV5{}) require.NoError(t, err) hostRole.SetSessionRequirePolicies([]*types.SessionRequirePolicy{{ @@ -111,9 +111,9 @@ func failCountStartTestCase(t *testing.T) startTestCase { } func failFilterStartTestCase(t *testing.T) startTestCase { - hostRole, err := types.NewRoleV5("host", types.RoleSpecV5{}) + hostRole, err := types.NewRole("host", types.RoleSpecV5{}) require.NoError(t, err) - participantRole, err := types.NewRoleV5("participant", types.RoleSpecV5{}) + participantRole, err := types.NewRole("participant", types.RoleSpecV5{}) require.NoError(t, err) hostRole.SetSessionRequirePolicies([]*types.SessionRequirePolicy{{ @@ -176,9 +176,9 @@ type joinTestCase struct { } func successJoinTestCase(t *testing.T) joinTestCase { - hostRole, err := types.NewRoleV5("host", types.RoleSpecV5{}) + hostRole, err := types.NewRole("host", types.RoleSpecV5{}) require.NoError(t, err) - participantRole, err := types.NewRoleV5("participant", types.RoleSpecV5{}) + participantRole, err := types.NewRole("participant", types.RoleSpecV5{}) require.NoError(t, err) participantRole.SetSessionJoinPolicies([]*types.SessionJoinPolicy{{ @@ -200,9 +200,9 @@ func successJoinTestCase(t *testing.T) joinTestCase { } func failRoleJoinTestCase(t *testing.T) joinTestCase { - hostRole, err := types.NewRoleV5("host", types.RoleSpecV5{}) + hostRole, err := types.NewRole("host", types.RoleSpecV5{}) require.NoError(t, err) - participantRole, err := types.NewRoleV5("participant", types.RoleSpecV5{}) + participantRole, err := types.NewRole("participant", types.RoleSpecV5{}) require.NoError(t, err) return joinTestCase{ @@ -218,9 +218,9 @@ func failRoleJoinTestCase(t *testing.T) joinTestCase { } func failKindJoinTestCase(t *testing.T) joinTestCase { - hostRole, err := types.NewRoleV5("host", types.RoleSpecV5{}) + hostRole, err := types.NewRole("host", types.RoleSpecV5{}) require.NoError(t, err) - participantRole, err := types.NewRoleV5("participant", types.RoleSpecV5{}) + participantRole, err := types.NewRole("participant", types.RoleSpecV5{}) require.NoError(t, err) participantRole.SetSessionJoinPolicies([]*types.SessionJoinPolicy{{ diff --git a/lib/auth/tls_test.go b/lib/auth/tls_test.go index 5d099723b3f..dbbbde24452 100644 --- a/lib/auth/tls_test.go +++ b/lib/auth/tls_test.go @@ -2045,7 +2045,7 @@ func TestGenerateCerts(t *testing.T) { t.Run("ImpersonateAllow", func(t *testing.T) { // Super impersonator impersonate anyone and login as root maxSessionTTL := 300 * time.Hour - superImpersonatorRole, err := types.NewRole("superimpersonator", types.RoleSpecV5{ + superImpersonatorRole, err := types.NewRoleV3("superimpersonator", types.RoleSpecV5{ Options: types.RoleOptions{ MaxSessionTTL: types.Duration(maxSessionTTL), }, @@ -2063,7 +2063,7 @@ func TestGenerateCerts(t *testing.T) { require.NoError(t, err) // Impersonator can generate certificates for super impersonator - role, err := types.NewRole("impersonate", types.RoleSpecV5{ + role, err := types.NewRoleV3("impersonate", types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{superImpersonator.GetName()}, Impersonate: &types.ImpersonateConditions{ diff --git a/lib/cache/cache_test.go b/lib/cache/cache_test.go index 56ab363baa4..37553c374e8 100644 --- a/lib/cache/cache_test.go +++ b/lib/cache/cache_test.go @@ -1405,7 +1405,7 @@ func TestRoles(t *testing.T) { p := newPackForNode(t) t.Cleanup(p.Close) - role, err := types.NewRole("role1", types.RoleSpecV5{ + role, err := types.NewRoleV3("role1", types.RoleSpecV5{ Options: types.RoleOptions{ MaxSessionTTL: types.Duration(time.Hour), }, diff --git a/lib/client/api_login_test.go b/lib/client/api_login_test.go index 065b274eee9..91c43886a28 100644 --- a/lib/client/api_login_test.go +++ b/lib/client/api_login_test.go @@ -186,7 +186,7 @@ func newStandaloneTeleport(t *testing.T, clock clockwork.Clock) *standaloneBundl user, err := types.NewUser("llama") require.NoError(t, err) - role, err := types.NewRole(user.GetName(), types.RoleSpecV5{ + role, err := types.NewRoleV3(user.GetName(), types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{user.GetName()}, }, diff --git a/lib/datalog/access_test.go b/lib/datalog/access_test.go index 5b0a0c584ae..12f89bee447 100644 --- a/lib/datalog/access_test.go +++ b/lib/datalog/access_test.go @@ -93,7 +93,7 @@ func createUser(name string, roles []string, traits map[string][]string) (types. } func createRole(name string, allowLogins []string, denyLogins []string, allowLabels types.Labels, denyLabels types.Labels) (types.Role, error) { - role, err := types.NewRole(name, types.RoleSpecV5{ + role, err := types.NewRoleV3(name, types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: allowLogins, NodeLabels: allowLabels, diff --git a/lib/services/access_request_test.go b/lib/services/access_request_test.go index f1bbd5584fa..e7a2fe16384 100644 --- a/lib/services/access_request_test.go +++ b/lib/services/access_request_test.go @@ -176,7 +176,7 @@ func TestReviewThresholds(t *testing.T) { roles := make(map[string]types.Role) for name, conditions := range roleDesc { - role, err := types.NewRole(name, types.RoleSpecV5{ + role, err := types.NewRoleV3(name, types.RoleSpecV5{ Allow: conditions, }) require.NoError(t, err) diff --git a/lib/services/role.go b/lib/services/role.go index 9f6276b9f5c..eecfe2c2913 100644 --- a/lib/services/role.go +++ b/lib/services/role.go @@ -122,7 +122,7 @@ func NewImplicitRole() types.Role { // // Used in tests only. func RoleForUser(u types.User) types.Role { - role, _ := types.NewRole(RoleNameForUser(u.GetName()), types.RoleSpecV5{ + role, _ := types.NewRoleV3(RoleNameForUser(u.GetName()), types.RoleSpecV5{ Options: types.RoleOptions{ CertificateFormat: constants.CertificateFormatStandard, MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration), @@ -156,7 +156,7 @@ func RoleForUser(u types.User) types.Role { // RoleForCertAuthority creates role using types.CertAuthority. func RoleForCertAuthority(ca types.CertAuthority) types.Role { - role, _ := types.NewRole(RoleNameForCertAuthority(ca.GetClusterName()), types.RoleSpecV5{ + role, _ := types.NewRoleV3(RoleNameForCertAuthority(ca.GetClusterName()), types.RoleSpecV5{ Options: types.RoleOptions{ MaxSessionTTL: types.NewDuration(defaults.MaxCertDuration), }, @@ -730,7 +730,7 @@ type AccessChecker interface { // FromSpec returns new RoleSet created from spec func FromSpec(name string, spec types.RoleSpecV5) (RoleSet, error) { - role, err := types.NewRole(name, spec) + role, err := types.NewRoleV3(name, spec) if err != nil { return nil, trace.Wrap(err) } diff --git a/lib/services/role_test.go b/lib/services/role_test.go index bf8406ca261..12ec744ab8a 100644 --- a/lib/services/role_test.go +++ b/lib/services/role_test.go @@ -1506,7 +1506,7 @@ func TestCheckRuleAccess(t *testing.T) { func TestGuessIfAccessIsPossible(t *testing.T) { // Examples from https://goteleport.com/docs/access-controls/reference/#rbac-for-sessions. - ownSessions, err := types.NewRole("own-sessions", types.RoleSpecV5{ + ownSessions, err := types.NewRoleV3("own-sessions", types.RoleSpecV5{ Allow: types.RoleConditions{ Rules: []types.Rule{ { @@ -1518,7 +1518,7 @@ func TestGuessIfAccessIsPossible(t *testing.T) { }, }) require.NoError(t, err) - ownSSHSessions, err := types.NewRole("own-ssh-sessions", types.RoleSpecV5{ + ownSSHSessions, err := types.NewRoleV3("own-ssh-sessions", types.RoleSpecV5{ Allow: types.RoleConditions{ Rules: []types.Rule{ { @@ -1540,7 +1540,7 @@ func TestGuessIfAccessIsPossible(t *testing.T) { require.NoError(t, err) // Simple, all-or-nothing roles. - readAllSessions, err := types.NewRole("all-sessions", types.RoleSpecV5{ + readAllSessions, err := types.NewRoleV3("all-sessions", types.RoleSpecV5{ Allow: types.RoleConditions{ Rules: []types.Rule{ { @@ -1551,7 +1551,7 @@ func TestGuessIfAccessIsPossible(t *testing.T) { }, }) require.NoError(t, err) - allowSSHSessions, err := types.NewRole("all-ssh-sessions", types.RoleSpecV5{ + allowSSHSessions, err := types.NewRoleV3("all-ssh-sessions", types.RoleSpecV5{ Allow: types.RoleConditions{ Rules: []types.Rule{ { @@ -1562,7 +1562,7 @@ func TestGuessIfAccessIsPossible(t *testing.T) { }, }) require.NoError(t, err) - denySSHSessions, err := types.NewRole("deny-ssh-sessions", types.RoleSpecV5{ + denySSHSessions, err := types.NewRoleV3("deny-ssh-sessions", types.RoleSpecV5{ Deny: types.RoleConditions{ Rules: []types.Rule{ { @@ -3536,7 +3536,7 @@ func TestRoleSetLockingMode(t *testing.T) { missingMode := constants.LockingMode("") newRoleWithLockingMode := func(t *testing.T, mode constants.LockingMode) types.Role { - role, err := types.NewRole(uuid.New().String(), types.RoleSpecV5{Options: types.RoleOptions{Lock: mode}}) + role, err := types.NewRoleV3(uuid.New().String(), types.RoleSpecV5{Options: types.RoleOptions{Lock: mode}}) require.NoError(t, err) return role } @@ -3575,14 +3575,14 @@ func TestExtractConditionForIdentifier(t *testing.T) { require.True(t, trace.IsAccessDenied(err)) allowWhere := func(where string) types.Role { - role, err := types.NewRole(uuid.New().String(), types.RoleSpecV5{Allow: types.RoleConditions{ + role, err := types.NewRoleV3(uuid.New().String(), types.RoleSpecV5{Allow: types.RoleConditions{ Rules: []types.Rule{{Resources: []string{types.KindSession}, Verbs: []string{types.VerbList}, Where: where}}, }}) require.NoError(t, err) return role } denyWhere := func(where string) types.Role { - role, err := types.NewRole(uuid.New().String(), types.RoleSpecV5{Deny: types.RoleConditions{ + role, err := types.NewRoleV3(uuid.New().String(), types.RoleSpecV5{Deny: types.RoleConditions{ Rules: []types.Rule{{Resources: []string{types.KindSession}, Verbs: []string{types.VerbList}, Where: where}}, }}) require.NoError(t, err) diff --git a/lib/services/suite/suite.go b/lib/services/suite/suite.go index 9d891559fb0..90c9fa64767 100644 --- a/lib/services/suite/suite.go +++ b/lib/services/suite/suite.go @@ -1461,7 +1461,7 @@ func (s *ServicesTestSuite) Events(c *check.C) { Kind: types.KindRole, }, crud: func(context.Context) types.Resource { - role, err := types.NewRole("role1", types.RoleSpecV5{ + role, err := types.NewRoleV3("role1", types.RoleSpecV5{ Options: types.RoleOptions{ MaxSessionTTL: types.Duration(time.Hour), }, diff --git a/lib/web/apiserver_test.go b/lib/web/apiserver_test.go index 59f85de5d61..acaa4e7d810 100644 --- a/lib/web/apiserver_test.go +++ b/lib/web/apiserver_test.go @@ -517,7 +517,7 @@ func (s *WebSuite) TestSAMLSuccess(c *C) { err = services.ValidateSAMLConnector(connector) c.Assert(err, IsNil) - role, err := types.NewRole(connector.GetAttributesToRoles()[0].Roles[0], types.RoleSpecV5{ + role, err := types.NewRoleV3(connector.GetAttributesToRoles()[0].Roles[0], types.RoleSpecV5{ Options: types.RoleOptions{ MaxSessionTTL: types.NewDuration(apidefaults.MaxCertDuration), }, diff --git a/lib/web/resources_test.go b/lib/web/resources_test.go index 97b8b030ea1..929008e0d43 100644 --- a/lib/web/resources_test.go +++ b/lib/web/resources_test.go @@ -122,7 +122,7 @@ spec: desktop: true version: v3 ` - role, err := types.NewRole("roleName", types.RoleSpecV5{ + role, err := types.NewRoleV3("roleName", types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{"test"}, }, @@ -167,7 +167,7 @@ func TestGetRoles(t *testing.T) { m := &mockedResourceAPIGetter{} m.mockGetRoles = func(ctx context.Context) ([]types.Role, error) { - role, err := types.NewRole("test", types.RoleSpecV5{ + role, err := types.NewRoleV3("test", types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{"test"}, }, diff --git a/tool/tsh/proxy_test.go b/tool/tsh/proxy_test.go index ad6a097b574..71ed51fc8b3 100644 --- a/tool/tsh/proxy_test.go +++ b/tool/tsh/proxy_test.go @@ -174,7 +174,7 @@ func TestProxySSHDial(t *testing.T) { tmpHomePath := t.TempDir() connector := mockConnector(t) - sshLoginRole, err := types.NewRole("ssh-login", types.RoleSpecV5{ + sshLoginRole, err := types.NewRoleV3("ssh-login", types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{"alice"}, }, diff --git a/tool/tsh/tsh_helper_test.go b/tool/tsh/tsh_helper_test.go index 823f0f4f481..faac5aae33f 100644 --- a/tool/tsh/tsh_helper_test.go +++ b/tool/tsh/tsh_helper_test.go @@ -84,7 +84,7 @@ func (s *suite) setupRootCluster(t *testing.T, options testSuiteOptions) { require.NoError(t, err) s.connector = mockConnector(t) - sshLoginRole, err := types.NewRole("ssh-login", types.RoleSpecV5{ + sshLoginRole, err := types.NewRoleV3("ssh-login", types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{user.Username}, }, @@ -143,7 +143,7 @@ func (s *suite) setupLeafCluster(t *testing.T) { require.NoError(t, err) cfg.Proxy.DisableWebInterface = true - sshLoginRole, err := types.NewRole("ssh-login", types.RoleSpecV5{ + sshLoginRole, err := types.NewRoleV3("ssh-login", types.RoleSpecV5{ Allow: types.RoleConditions{ Logins: []string{user.Username}, }, diff --git a/tool/tsh/tsh_test.go b/tool/tsh/tsh_test.go index 375554dea57..89563b7cc4a 100644 --- a/tool/tsh/tsh_test.go +++ b/tool/tsh/tsh_test.go @@ -153,7 +153,7 @@ func TestOIDCLogin(t *testing.T) { // set up an initial role with `request_access: always` in order to // trigger automatic post-login escalation. - populist, err := types.NewRole("populist", types.RoleSpecV5{ + populist, err := types.NewRoleV3("populist", types.RoleSpecV5{ Allow: types.RoleConditions{ Request: &types.AccessRequestConditions{ Roles: []string{"dictator"}, @@ -166,7 +166,7 @@ func TestOIDCLogin(t *testing.T) { require.NoError(t, err) // empty role which serves as our escalation target - dictator, err := types.NewRole("dictator", types.RoleSpecV5{}) + dictator, err := types.NewRoleV3("dictator", types.RoleSpecV5{}) require.NoError(t, err) alice, err := types.NewUser("alice@example.com") @@ -444,7 +444,7 @@ func TestAccessRequestOnLeaf(t *testing.T) { lib.SetInsecureDevMode(isInsecure) }) - requester, err := types.NewRole("requester", types.RoleSpecV5{ + requester, err := types.NewRoleV3("requester", types.RoleSpecV5{ Allow: types.RoleConditions{ Request: &types.AccessRequestConditions{ Roles: []string{"access"},