Add OAuth2 API scope registration and enforcement

Register v1 API scopes in coredata, advertise them in OIDC discovery
and protected-resource metadata, show them on the consent screen, and
enforce scope-to-action mapping in the IAM Authorizer before policy
evaluation.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
Ludovic Vielle
2026-06-15 17:33:15 +02:00
parent 25151fa089
commit 3ebb221a9b
56 changed files with 1918 additions and 290 deletions

View File

@@ -48,6 +48,17 @@ var ReadAccessPolicy = policy.NewPolicy(
).WithSID("access-review-read-access").When(organizationCondition),
).WithDescription("Read-only access-review access")
// DriverCatalogPolicy grants every authenticated identity read access to the
// global access-review driver catalog. The catalog is deployment-scoped and has
// no organization scoping, so the allow has no condition.
var DriverCatalogPolicy = policy.NewPolicy(
"access-review:driver-catalog",
"Access Review Driver Catalog",
policy.Allow(
ActionDriverCatalogList,
).WithSID("read-access-review-driver-catalog"),
).WithDescription("Allows every authenticated user to read the global access-review driver catalog")
// PolicySet returns the PolicySet for the access-review service. It is owned by
// this package and registered into the authorizer at composition time so the
// access-review authorization rules live alongside the access-review domain
@@ -56,5 +67,6 @@ func PolicySet() *iam.PolicySet {
return iam.NewPolicySet().
AddRolePolicy("OWNER", FullAccessPolicy).
AddRolePolicy("ADMIN", FullAccessPolicy).
AddRolePolicy("VIEWER", ReadAccessPolicy)
AddRolePolicy("VIEWER", ReadAccessPolicy).
AddIdentityScopedPolicy(DriverCatalogPolicy)
}