RBAC: remove redundant role name field from plugin role registrations (#58166)
* RBAC: Remove name from role registration * Inline accesscontrol service * test fix * use fmt Co-Authored-By: marefr <marcus.efraimsson@gmail.com> Co-authored-by: marefr <marcus.efraimsson@gmail.com>
This commit is contained in:
co-authored by
marefr
parent
80e80221b9
commit
d999b5bda0
@@ -220,7 +220,7 @@ func (s *Service) DeclarePluginRoles(_ context.Context, ID, name string, regs []
|
||||
return nil
|
||||
}
|
||||
|
||||
acRegs := pluginutils.ToRegistrations(name, regs)
|
||||
acRegs := pluginutils.ToRegistrations(ID, name, regs)
|
||||
for _, r := range acRegs {
|
||||
if err := pluginutils.ValidatePluginRole(ID, r.Role); err != nil {
|
||||
return err
|
||||
|
||||
@@ -175,31 +175,19 @@ func TestService_DeclarePluginRoles(t *testing.T) {
|
||||
pluginID: "test-app",
|
||||
registrations: []plugins.RoleRegistration{
|
||||
{
|
||||
Role: plugins.Role{Name: "plugins:test-app:test"},
|
||||
Role: plugins.Role{Name: "Tester"},
|
||||
Grants: []string{"Admin"},
|
||||
},
|
||||
},
|
||||
wantErr: false,
|
||||
},
|
||||
{
|
||||
name: "should fail registration invalid role name",
|
||||
pluginID: "test-app",
|
||||
registrations: []plugins.RoleRegistration{
|
||||
{
|
||||
Role: plugins.Role{Name: "invalid.plugins:test-app:test"},
|
||||
Grants: []string{"Admin"},
|
||||
},
|
||||
},
|
||||
wantErr: true,
|
||||
err: &accesscontrol.ErrorInvalidRole{},
|
||||
},
|
||||
{
|
||||
name: "should add registration with valid permissions",
|
||||
pluginID: "test-app",
|
||||
registrations: []plugins.RoleRegistration{
|
||||
{
|
||||
Role: plugins.Role{
|
||||
Name: "plugins:test-app:test",
|
||||
Name: "Tester",
|
||||
Permissions: []plugins.Permission{
|
||||
{Action: "plugins.app:access"},
|
||||
{Action: "test-app:read"},
|
||||
@@ -217,7 +205,7 @@ func TestService_DeclarePluginRoles(t *testing.T) {
|
||||
registrations: []plugins.RoleRegistration{
|
||||
{
|
||||
Role: plugins.Role{
|
||||
Name: "plugins:test-app:test",
|
||||
Name: "Tester",
|
||||
Permissions: []plugins.Permission{
|
||||
{Action: "invalid.test-app.resource:read"},
|
||||
},
|
||||
@@ -233,7 +221,7 @@ func TestService_DeclarePluginRoles(t *testing.T) {
|
||||
pluginID: "test-app",
|
||||
registrations: []plugins.RoleRegistration{
|
||||
{
|
||||
Role: plugins.Role{Name: "plugins:test-app:test"},
|
||||
Role: plugins.Role{Name: "Tester"},
|
||||
Grants: []string{"WrongAdmin"},
|
||||
},
|
||||
},
|
||||
@@ -245,11 +233,11 @@ func TestService_DeclarePluginRoles(t *testing.T) {
|
||||
pluginID: "test-app",
|
||||
registrations: []plugins.RoleRegistration{
|
||||
{
|
||||
Role: plugins.Role{Name: "plugins:test-app:test"},
|
||||
Role: plugins.Role{Name: "Tester"},
|
||||
Grants: []string{"Admin"},
|
||||
},
|
||||
{
|
||||
Role: plugins.Role{Name: "plugins:test-app:test2"},
|
||||
Role: plugins.Role{Name: "Tester2"},
|
||||
Grants: []string{"Admin"},
|
||||
},
|
||||
},
|
||||
@@ -335,7 +323,8 @@ func TestService_RegisterFixedRoles(t *testing.T) {
|
||||
registrations: []accesscontrol.RoleRegistration{
|
||||
{
|
||||
Role: accesscontrol.RoleDTO{
|
||||
Name: "plugins:test-app:test",
|
||||
Name: accesscontrol.PluginRolePrefix + "test-app:tester",
|
||||
DisplayName: "Tester",
|
||||
Permissions: []accesscontrol.Permission{{Action: "test-app:test"}},
|
||||
},
|
||||
Grants: []string{"Editor"},
|
||||
|
||||
Reference in New Issue
Block a user