mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
Implements RFD 45 / "where" conditions for active sessions[1]. In few words, the purpose of the RFD is to allow the creation of roles that permits users to only join a subset of active sessions (for example, only their own sessions). Implementation goes a bit further than the RFD, allowing the conditions to be applied to `update` and `delete` verbs as well. Originally implemented by @andrejtokarcik (#8568), tweaks by @codingllama. [1] https://github.com/gravitational/teleport/blob/master/rfd/0045-ssh_session-where-condition.md * Implement where conditions for active sessions list/read * actionWithConditionForList => actionForListWithCondition * Make Context-exposed sessions follow the RFD API * Add tests for "where" conditions on active sessions * Fix typos * Fix typos and spacing * Rename "parties" to "participants" in the context session * Update RFD to reflect PR changes Update RFD to reflect PR changes Specifically, mark as implemented and rename `parties` to `participants`. * Push list authz logic to ServerWithRoles, obsolete cond * Remove cond from GetSessions signature * Simplify cast in lib.utils.Fields.GetString * Add TODO to refactor SearchSessionEvents / stored sessions Co-authored-by: Andrej Tokarčík <andrej@goteleport.com>