RBAC: Add and resolve action sets when searching user's permissions (#88694)
* include and resolve action sets when fetching user's permissions * expand both action and action prefix (returns an empty set for the one that isn't specified) Co-authored-by: Gabriel MABILLE <gamab@users.noreply.github.com> * if action is specified, check for exact match; also extend tests
This commit is contained in:
@@ -16,7 +16,15 @@ type ScopeAttributeResolver interface {
|
||||
}
|
||||
|
||||
type ActionResolver interface {
|
||||
// ExpandActionSets takes a set of permissions that might include some action set permissions, and returns a set of permissions with action sets expanded into underlying permissions
|
||||
ExpandActionSets(permissions []Permission) []Permission
|
||||
// ExpandActionSetsWithFilter works like ExpandActionSets, but it also takes a function for action filtering. When action sets are expanded into the underlying permissions,
|
||||
// only those permissions whose action is matched by actionMatcher are included.
|
||||
ExpandActionSetsWithFilter(permissions []Permission, actionMatcher func(action string) bool) []Permission
|
||||
// ResolveAction returns all action sets that include the given action
|
||||
ResolveAction(action string) []string
|
||||
// ResolveActionPrefix returns all action sets that include at least one action with the specified prefix
|
||||
ResolveActionPrefix(prefix string) []string
|
||||
}
|
||||
|
||||
// ScopeAttributeResolverFunc is an adapter to allow functions to implement ScopeAttributeResolver interface
|
||||
|
||||
Reference in New Issue
Block a user