Files
teleport/lib/session
Alan ParraandAndrej Tokarčík 64679d2db8 Implement where conditions for active sessions (#9040)
Implements RFD 45 / "where" conditions for active sessions[1].

In few words, the purpose of the RFD is to allow the creation of roles that
permits users to only join a subset of active sessions (for example, only their
own sessions).

Implementation goes a bit further than the RFD, allowing the conditions to be
applied to  `update` and `delete` verbs as well.

Originally implemented by @andrejtokarcik (#8568), tweaks by @codingllama.

[1] https://github.com/gravitational/teleport/blob/master/rfd/0045-ssh_session-where-condition.md


* Implement where conditions for active sessions list/read
* actionWithConditionForList => actionForListWithCondition
* Make Context-exposed sessions follow the RFD API
* Add tests for "where" conditions on active sessions
* Fix typos
* Fix typos and spacing
* Rename "parties" to "participants" in the context session
* Update RFD to reflect PR changes

Update RFD to reflect PR changes

Specifically, mark as implemented and rename `parties` to `participants`.

* Push list authz logic to ServerWithRoles, obsolete cond
* Remove cond from GetSessions signature
* Simplify cast in lib.utils.Fields.GetString
* Add TODO to refactor SearchSessionEvents / stored sessions

Co-authored-by: Andrej Tokarčík <andrej@goteleport.com>
2021-11-18 15:05:13 -08:00
..