Access control: FGAC for team sync endpoints (#44673)

* add actions for team group sync

* extend the hook to allow specifying whether the user is external

* move user struct to type package

* interface for permission service to allow mocking it

* reuse existing permissions

* test fix

* refactor

* linting
This commit is contained in:
Ieva
2022-02-03 15:27:05 +00:00
committed by GitHub
parent bc7e55d99b
commit 602d62ebcc
14 changed files with 76 additions and 28 deletions
@@ -46,13 +46,13 @@ func TestService_SetUserPermission(t *testing.T) {
var hookCalled bool
if tt.callHook {
service.options.OnSetUser = func(session *sqlstore.DBSession, orgID, userID int64, resourceID, permission string) error {
service.options.OnSetUser = func(session *sqlstore.DBSession, orgID int64, user accesscontrol.User, resourceID, permission string) error {
hookCalled = true
return nil
}
}
_, err = service.SetUserPermission(context.Background(), user.OrgId, user.Id, "1", "")
_, err = service.SetUserPermission(context.Background(), user.OrgId, accesscontrol.User{ID: user.Id}, "1", "")
require.NoError(t, err)
assert.Equal(t, tt.callHook, hookCalled)
})