IAM: Implement update method in team API (#111660)
* implement team update in legacy store * add unit tests * add integration test * set permissions for user in integration tests * add more integration tests for update * update validations * add unit tests for ValidateOnUpdate() func * fix integration test
This commit is contained in:
@@ -30,3 +30,28 @@ func ValidateOnCreate(ctx context.Context, obj *iamv0alpha1.Team) error {
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func ValidateOnUpdate(ctx context.Context, obj, old *iamv0alpha1.Team) error {
|
||||
requester, err := identity.GetRequester(ctx)
|
||||
if err != nil {
|
||||
return apierrors.NewUnauthorized("no identity found")
|
||||
}
|
||||
|
||||
if obj.Spec.Title == "" {
|
||||
return apierrors.NewBadRequest("the team must have a title")
|
||||
}
|
||||
|
||||
if !requester.IsIdentityType(types.TypeServiceAccount) && obj.Spec.Provisioned && !old.Spec.Provisioned {
|
||||
return apierrors.NewBadRequest("provisioned teams are only allowed for service accounts")
|
||||
}
|
||||
|
||||
if old.Spec.Provisioned && !obj.Spec.Provisioned {
|
||||
return apierrors.NewBadRequest("provisioned teams cannot be updated to non-provisioned teams")
|
||||
}
|
||||
|
||||
if !obj.Spec.Provisioned && obj.Spec.ExternalUID != "" {
|
||||
return apierrors.NewBadRequest("externalUID is only allowed for provisioned teams")
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user