RBAC: Add required component to perform access control checks for user api when running single tenant (#93104)

* Unexport store and create new constructor function

* Add ResourceAuthorizer and LegacyAccessClient

* Configure checks for user store

* List with checks if AccessClient is configured

* Allow system user service account to read all users

---------

Co-authored-by: Gabriel MABILLE <gamab@users.noreply.github.com>
This commit is contained in:
Karl Persson
2024-09-23 11:26:44 +02:00
committed by GitHub
co-authored by Gabriel MABILLE
parent bca8bd3c8b
commit 2e38329026
18 changed files with 606 additions and 61 deletions
@@ -32,8 +32,8 @@ func (a *recordingAccessControlFake) RegisterScopeAttributeResolver(prefix strin
panic("implement me")
}
func (a *recordingAccessControlFake) IsDisabled() bool {
return a.Disabled
func (a *recordingAccessControlFake) WithoutResolvers() accesscontrol.AccessControl {
panic("unimplemented")
}
var _ accesscontrol.AccessControl = &recordingAccessControlFake{}