RBAC: Only write action sets (#112429)

* implementation + broken tests

* finish tests and cleanup

* fix a bug in logic where we'd return too early for non dash and folder resources
This commit is contained in:
Ieva
2025-10-20 16:02:56 +01:00
committed by GitHub
parent c95b057cdc
commit 0a0311a2b2
9 changed files with 253 additions and 38 deletions
-3
View File
@@ -20,8 +20,6 @@ type RBACSettings struct {
// run the zanzana reconciliation loop.
ZanzanaReconciliationInterval time.Duration
OnlyStoreAccessActionSets bool
// set of resources that should generate managed permissions when created
resourcesWithPermissionsOnCreation map[string]struct{}
@@ -37,7 +35,6 @@ func (cfg *Cfg) readRBACSettings() {
s.PermissionValidationEnabled = rbac.Key("permission_validation_enabled").MustBool(false)
s.ResetBasicRoles = rbac.Key("reset_basic_roles").MustBool(false)
s.SingleOrganization = rbac.Key("single_organization").MustBool(false)
s.OnlyStoreAccessActionSets = rbac.Key("only_store_access_action_sets").MustBool(false)
// List of resources to generate managed permissions for upon resource creation (dashboard, folder, service-account, datasource)
resources := util.SplitString(rbac.Key("resources_with_managed_permissions_on_creation").MustString("dashboard, folder, service-account, datasource"))