RBAC: Add required component to perform access control checks for user api when running single tenant (#93104)

* Unexport store and create new constructor function

* Add ResourceAuthorizer and LegacyAccessClient

* Configure checks for user store

* List with checks if AccessClient is configured

* Allow system user service account to read all users

---------

Co-authored-by: Gabriel MABILLE <gamab@users.noreply.github.com>
This commit is contained in:
Karl Persson
2024-09-23 11:26:44 +02:00
committed by GitHub
co-authored by Gabriel MABILLE
parent bca8bd3c8b
commit 2e38329026
18 changed files with 606 additions and 61 deletions
@@ -75,6 +75,10 @@ func (f FakeAccessControl) Evaluate(ctx context.Context, user identity.Requester
func (f FakeAccessControl) RegisterScopeAttributeResolver(prefix string, resolver accesscontrol.ScopeAttributeResolver) {
}
func (f FakeAccessControl) WithoutResolvers() accesscontrol.AccessControl {
return f
}
type FakeStore struct {
ExpectedUserPermissions []accesscontrol.Permission
ExpectedBasicRolesPermissions []accesscontrol.Permission