RBAC: Add required component to perform access control checks for user api when running single tenant (#93104)
* Unexport store and create new constructor function * Add ResourceAuthorizer and LegacyAccessClient * Configure checks for user store * List with checks if AccessClient is configured * Allow system user service account to read all users --------- Co-authored-by: Gabriel MABILLE <gamab@users.noreply.github.com>
This commit is contained in:
co-authored by
Gabriel MABILLE
parent
bca8bd3c8b
commit
2e38329026
@@ -28,6 +28,10 @@ type AccessControl interface {
|
||||
// RegisterScopeAttributeResolver allows the caller to register a scope resolver for a
|
||||
// specific scope prefix (ex: datasources:name:)
|
||||
RegisterScopeAttributeResolver(prefix string, resolver ScopeAttributeResolver)
|
||||
// WithoutResolvers copies AccessControl without any configured resolvers.
|
||||
// This is useful when we don't want to reuse any pre-configured resolvers
|
||||
// for a authorization call.
|
||||
WithoutResolvers() AccessControl
|
||||
}
|
||||
|
||||
type Service interface {
|
||||
|
||||
Reference in New Issue
Block a user