Add OAuth2 API scope registration and enforcement
Register v1 API scopes in coredata, advertise them in OIDC discovery and protected-resource metadata, show them on the consent screen, and enforce scope-to-action mapping in the IAM Authorizer before policy evaluation. Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
@@ -48,6 +48,17 @@ var ReadAccessPolicy = policy.NewPolicy(
|
||||
).WithSID("access-review-read-access").When(organizationCondition),
|
||||
).WithDescription("Read-only access-review access")
|
||||
|
||||
// DriverCatalogPolicy grants every authenticated identity read access to the
|
||||
// global access-review driver catalog. The catalog is deployment-scoped and has
|
||||
// no organization scoping, so the allow has no condition.
|
||||
var DriverCatalogPolicy = policy.NewPolicy(
|
||||
"access-review:driver-catalog",
|
||||
"Access Review Driver Catalog",
|
||||
policy.Allow(
|
||||
ActionDriverCatalogList,
|
||||
).WithSID("read-access-review-driver-catalog"),
|
||||
).WithDescription("Allows every authenticated user to read the global access-review driver catalog")
|
||||
|
||||
// PolicySet returns the PolicySet for the access-review service. It is owned by
|
||||
// this package and registered into the authorizer at composition time so the
|
||||
// access-review authorization rules live alongside the access-review domain
|
||||
@@ -56,5 +67,6 @@ func PolicySet() *iam.PolicySet {
|
||||
return iam.NewPolicySet().
|
||||
AddRolePolicy("OWNER", FullAccessPolicy).
|
||||
AddRolePolicy("ADMIN", FullAccessPolicy).
|
||||
AddRolePolicy("VIEWER", ReadAccessPolicy)
|
||||
AddRolePolicy("VIEWER", ReadAccessPolicy).
|
||||
AddIdentityScopedPolicy(DriverCatalogPolicy)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user