Access Control: Refactor scope resolvers with support to resolve into several scopes (#48202)

* Refactor Scope resolver to support resolving into several scopes

* Change permission evaluator to match at least one of passed scopes
This commit is contained in:
Karl Persson
2022-05-02 09:29:30 +02:00
committed by GitHub
parent 9622e7457e
commit de50f39c12
18 changed files with 453 additions and 434 deletions
+4 -4
View File
@@ -25,11 +25,11 @@ func TestPermission_Evaluate(t *testing.T) {
},
},
{
desc: "should evaluate to true when allEvaluator required scopes matches",
desc: "should evaluate to true when at least one scope matches",
expected: true,
evaluator: EvalPermission("reports:read", "reports:1", "reports:2"),
permissions: map[string][]string{
"reports:read": {"reports:1", "reports:2"},
"reports:read": {"reports:2"},
},
},
{
@@ -41,11 +41,11 @@ func TestPermission_Evaluate(t *testing.T) {
},
},
{
desc: "should evaluate to false when only one of required scopes exists",
desc: "should evaluate to false when no scopes matches",
expected: false,
evaluator: EvalPermission("reports:read", "reports:1", "reports:2"),
permissions: map[string][]string{
"reports:read": {"reports:1"},
"reports:read": {"reports:9", "reports:10"},
},
},
}