RBAC: Add required component to perform access control checks for user api when running single tenant (#93104)
* Unexport store and create new constructor function * Add ResourceAuthorizer and LegacyAccessClient * Configure checks for user store * List with checks if AccessClient is configured * Allow system user service account to read all users --------- Co-authored-by: Gabriel MABILLE <gamab@users.noreply.github.com>
This commit is contained in:
co-authored by
Gabriel MABILLE
parent
bca8bd3c8b
commit
2e38329026
@@ -14,6 +14,7 @@ import (
|
||||
type LegacyIdentityStore interface {
|
||||
ListDisplay(ctx context.Context, ns claims.NamespaceInfo, query ListDisplayQuery) (*ListUserResult, error)
|
||||
|
||||
GetUserInternalID(ctx context.Context, ns claims.NamespaceInfo, query GetUserInternalIDQuery) (*GetUserInternalIDResult, error)
|
||||
ListUsers(ctx context.Context, ns claims.NamespaceInfo, query ListUserQuery) (*ListUserResult, error)
|
||||
ListUserTeams(ctx context.Context, ns claims.NamespaceInfo, query ListUserTeamsQuery) (*ListUserTeamsResult, error)
|
||||
|
||||
@@ -37,6 +38,11 @@ func NewLegacySQLStores(sql legacysql.LegacyDatabaseProvider) LegacyIdentityStor
|
||||
|
||||
type legacySQLStore struct {
|
||||
sql legacysql.LegacyDatabaseProvider
|
||||
ac claims.AccessClient
|
||||
}
|
||||
|
||||
func (s *legacySQLStore) WithAccessClient(ac claims.AccessClient) {
|
||||
s.ac = ac
|
||||
}
|
||||
|
||||
// Templates setup.
|
||||
|
||||
Reference in New Issue
Block a user