RBAC: Add required component to perform access control checks for user api when running single tenant (#93104)

* Unexport store and create new constructor function

* Add ResourceAuthorizer and LegacyAccessClient

* Configure checks for user store

* List with checks if AccessClient is configured

* Allow system user service account to read all users

---------

Co-authored-by: Gabriel MABILLE <gamab@users.noreply.github.com>
This commit is contained in:
Karl Persson
2024-09-23 11:26:44 +02:00
committed by GitHub
co-authored by Gabriel MABILLE
parent bca8bd3c8b
commit 2e38329026
18 changed files with 606 additions and 61 deletions
+6
View File
@@ -14,6 +14,7 @@ import (
type LegacyIdentityStore interface {
ListDisplay(ctx context.Context, ns claims.NamespaceInfo, query ListDisplayQuery) (*ListUserResult, error)
GetUserInternalID(ctx context.Context, ns claims.NamespaceInfo, query GetUserInternalIDQuery) (*GetUserInternalIDResult, error)
ListUsers(ctx context.Context, ns claims.NamespaceInfo, query ListUserQuery) (*ListUserResult, error)
ListUserTeams(ctx context.Context, ns claims.NamespaceInfo, query ListUserTeamsQuery) (*ListUserTeamsResult, error)
@@ -37,6 +38,11 @@ func NewLegacySQLStores(sql legacysql.LegacyDatabaseProvider) LegacyIdentityStor
type legacySQLStore struct {
sql legacysql.LegacyDatabaseProvider
ac claims.AccessClient
}
func (s *legacySQLStore) WithAccessClient(ac claims.AccessClient) {
s.ac = ac
}
// Templates setup.