Add OAuth2 API scope registration and enforcement
Register v1 API scopes in coredata, advertise them in OIDC discovery and protected-resource metadata, show them on the consent screen, and enforce scope-to-action mapping in the IAM Authorizer before policy evaluation. Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
@@ -42,4 +42,7 @@ const (
|
||||
ActionSourceUpdate = "access-review:source:update"
|
||||
ActionSourceDelete = "access-review:source:delete"
|
||||
ActionSourceSync = "access-review:source:sync"
|
||||
|
||||
// Driver catalog actions (global deployment-scoped catalog).
|
||||
ActionDriverCatalogList = "access-review:driver-catalog:list"
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user