Include roles in server side match for users (#62466)

This commit is contained in:
Michael
2025-12-23 19:25:21 +00:00
committed by GitHub
parent ae73743316
commit afb05ae3a9
2 changed files with 20 additions and 0 deletions
+1
View File
@@ -260,6 +260,7 @@ func (u *UserV2) SetStaticLabels(sl map[string]string) {
// match against the list of search values.
func (u *UserV2) MatchSearch(values []string) bool {
fieldVals := append(utils.MapToStrings(u.Metadata.Labels), u.GetName())
fieldVals = append(fieldVals, u.GetRoles()...)
return MatchSearch(fieldVals, values, nil)
}
+19
View File
@@ -472,9 +472,19 @@ func TestListUsers(t *testing.T) {
ctx := context.Background()
// Create a role to assign to users for search testing.
accessSvc := env.backend.(interface {
UpsertRole(context.Context, types.Role) (types.Role, error)
})
role, err := types.NewRole("test-role", types.RoleSpecV6{})
require.NoError(t, err, "creating role")
_, err = accessSvc.UpsertRole(ctx, role)
require.NoError(t, err, "upserting role")
llama, err := types.NewUser("llama")
require.NoError(t, err, "creating new user llama")
require.NoError(t, generateUserSecrets(llama), "generating user secrets")
llama.SetRoles([]string{"test-role"})
// Validate that the user does not exist.
resp, err := env.ListUsers(ctx, &userspb.ListUsersRequest{PageSize: 10})
@@ -502,6 +512,15 @@ func TestListUsers(t *testing.T) {
assert.Empty(t, cmp.Diff(created.User, resp.Users[0], cmpopts.IgnoreFields(types.Metadata{}, "Revision")))
assert.Empty(t, cmp.Diff(llama.GetLocalAuth(), resp.Users[0].GetLocalAuth()), "user secrets do not match")
// Validate that searching by role returns matching users.
resp, err = env.ListUsers(ctx, &userspb.ListUsersRequest{
PageSize: 10,
Filter: &types.UserFilter{SearchKeywords: []string{"test-role"}},
})
require.NoError(t, err, "listing users with role filter")
require.Len(t, resp.Users, 1, "expected one user with test-role")
assert.Equal(t, "llama", resp.Users[0].GetName(), "expected llama to match role search")
// Create addition users to test pagination
createdUsers := []*types.UserV2{llama.(*types.UserV2)}
for i := range 22 {