IAM: Implement update method in team API (#111660)

* implement team update in legacy store

* add unit tests

* add integration test

* set permissions for user in integration tests

* add more integration tests for update

* update validations

* add unit tests for ValidateOnUpdate() func

* fix integration test
This commit is contained in:
Mihai Doarna
2025-10-03 12:48:38 +03:00
committed by GitHub
parent 76d467f285
commit 0f60e2208e
13 changed files with 484 additions and 7 deletions
+25
View File
@@ -30,3 +30,28 @@ func ValidateOnCreate(ctx context.Context, obj *iamv0alpha1.Team) error {
return nil
}
func ValidateOnUpdate(ctx context.Context, obj, old *iamv0alpha1.Team) error {
requester, err := identity.GetRequester(ctx)
if err != nil {
return apierrors.NewUnauthorized("no identity found")
}
if obj.Spec.Title == "" {
return apierrors.NewBadRequest("the team must have a title")
}
if !requester.IsIdentityType(types.TypeServiceAccount) && obj.Spec.Provisioned && !old.Spec.Provisioned {
return apierrors.NewBadRequest("provisioned teams are only allowed for service accounts")
}
if old.Spec.Provisioned && !obj.Spec.Provisioned {
return apierrors.NewBadRequest("provisioned teams cannot be updated to non-provisioned teams")
}
if !obj.Spec.Provisioned && obj.Spec.ExternalUID != "" {
return apierrors.NewBadRequest("externalUID is only allowed for provisioned teams")
}
return nil
}