Access Control: move features to Enterprise (#32640)
* Move db package WIP * Implement OSS access control * Register OSS access control * Fix linter error in tests * Fix linter error in evaluator * Simplify OSS tests * Optimize builtin roles * Chore: add comments to the exported functions * Remove init from ossaccesscontrol package (moved to ext) * Add access control as a dependency for http server * Modify middleware to receive fallback function * Middleware: refactor fallback function call * Move unused models to enterprise * Simplify AccessControl type * Chore: use bool IsDisabled() method instead of CanBeDisabled interface
This commit is contained in:
@@ -7,38 +7,12 @@ import (
|
||||
)
|
||||
|
||||
type AccessControl interface {
|
||||
Evaluator
|
||||
Store
|
||||
}
|
||||
|
||||
type Evaluator interface {
|
||||
// Evaluate evaluates access to the given resource
|
||||
// Evaluate evaluates access to the given resource.
|
||||
Evaluate(ctx context.Context, user *models.SignedInUser, permission string, scope ...string) (bool, error)
|
||||
}
|
||||
|
||||
type Store interface {
|
||||
// Database access methods
|
||||
GetRoles(ctx context.Context, orgID int64) ([]*Role, error)
|
||||
GetRole(ctx context.Context, orgID, roleID int64) (*RoleDTO, error)
|
||||
GetRoleByUID(ctx context.Context, orgId int64, uid string) (*RoleDTO, error)
|
||||
CreateRole(ctx context.Context, cmd CreateRoleCommand) (*Role, error)
|
||||
CreateRoleWithPermissions(ctx context.Context, cmd CreateRoleWithPermissionsCommand) (*RoleDTO, error)
|
||||
UpdateRole(ctx context.Context, cmd UpdateRoleCommand) (*RoleDTO, error)
|
||||
DeleteRole(cmd *DeleteRoleCommand) error
|
||||
GetRolePermissions(ctx context.Context, roleID int64) ([]Permission, error)
|
||||
CreatePermission(ctx context.Context, cmd CreatePermissionCommand) (*Permission, error)
|
||||
UpdatePermission(cmd *UpdatePermissionCommand) (*Permission, error)
|
||||
DeletePermission(ctx context.Context, cmd *DeletePermissionCommand) error
|
||||
GetTeamRoles(query *GetTeamRolesQuery) ([]*RoleDTO, error)
|
||||
GetUserRoles(ctx context.Context, query GetUserRolesQuery) ([]*RoleDTO, error)
|
||||
GetUserPermissions(ctx context.Context, query GetUserPermissionsQuery) ([]*Permission, error)
|
||||
AddTeamRole(cmd *AddTeamRoleCommand) error
|
||||
RemoveTeamRole(cmd *RemoveTeamRoleCommand) error
|
||||
AddUserRole(cmd *AddUserRoleCommand) error
|
||||
RemoveUserRole(cmd *RemoveUserRoleCommand) error
|
||||
AddBuiltinRole(ctx context.Context, orgID, roleID int64, roleName string) error
|
||||
}
|
||||
// GetUserPermissions returns user permissions.
|
||||
GetUserPermissions(ctx context.Context, user *models.SignedInUser, roles []string) ([]*Permission, error)
|
||||
|
||||
type Seeder interface {
|
||||
Seed(ctx context.Context, orgID int64) error
|
||||
// Middleware checks if service disabled or not to switch to fallback authorization.
|
||||
IsDisabled() bool
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user