Whitelist ownership grants via allow policies
Replace the deny-based restriction on granting OWNER with role-scoped allow policies so authorization fails closed: admins may create and update memberships only when the assigned role is not OWNER, and the absence of a target role no longer implies permission. To keep console UI gating accurate without loosening the base grants, the permission field gains an optional typed options argument (PermissionOptionsInput) that forwards target_role into the dry-run authorization. Only the two role-related console calls (create user, update membership) pass it; the OWNER option stays hidden for admins via the existing assignable-roles helper. Add a non-regression test that an admin cannot promote a member to OWNER while still being able to change members between non-owner roles.
This commit is contained in:
@@ -39,7 +39,8 @@
|
||||
"Duration": "string",
|
||||
"BigInt": "number",
|
||||
"EmailAddr": "string",
|
||||
"OAuth2Scope": "string"
|
||||
"OAuth2Scope": "string",
|
||||
"Map": "Record<string, string>"
|
||||
}
|
||||
},
|
||||
"trust": {
|
||||
|
||||
Reference in New Issue
Block a user