Add read actions to all unprefixed scopes

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
Ludovic Vielle
2026-06-23 10:36:32 +02:00
parent 002c91ba11
commit 20b9321de3
11 changed files with 276 additions and 1 deletions

View File

@@ -60,6 +60,20 @@ func (r *Registry) RegisteredScopes() []coredata.OAuth2Scope {
return sortedScopes(slices.Collect(maps.Keys(r.scopeActions)))
}
func (r *Registry) AllWriteScopes() []coredata.OAuth2Scope {
r.mu.RLock()
defer r.mu.RUnlock()
writeScopes := make([]coredata.OAuth2Scope, 0, len(r.scopeActions))
for scope := range r.scopeActions {
if !scope.IsRead() {
writeScopes = append(writeScopes, scope)
}
}
return sortedScopes(writeScopes)
}
func (r *Registry) Allows(tokenScopes coredata.OAuth2Scopes, action string) bool {
r.mu.RLock()
defer r.mu.RUnlock()

View File

@@ -105,6 +105,25 @@ func TestRegistry_ScopesForAction(t *testing.T) {
assert.Nil(t, reg.ScopesForAction("core:organization:delete"))
}
func TestRegistry_AllWriteScopes(t *testing.T) {
t.Parallel()
const (
scopeV1OrgRead = coredata.OAuth2Scope("v1:org:read")
scopeV1OrgWrite = coredata.OAuth2Scope("v1:org")
)
reg := oauth2scope.NewRegistry().
Register(
map[coredata.OAuth2Scope][]string{
scopeV1OrgWrite: {"core:organization:update"},
scopeV1OrgRead: {"core:organization:get"},
},
)
assert.Equal(t, []coredata.OAuth2Scope{scopeV1OrgWrite}, reg.AllWriteScopes())
}
func TestRegistry_RegisteredScopes(t *testing.T) {
t.Parallel()