Introduce policy.Attributes and policy.AttributesByID aliases
These aliases (`map[string]string` and `map[gid.GID]Attributes`) give batch authorization call sites readable types when loading and returning per-resource condition attributes. ConditionContext now uses the alias instead of the bare map type, with no behavior change. Also extend policy tests to cover ResourcePattern.MatchesResource, comma-separated value handling for In/NotIn, unresolved-reference fallthrough, and resolveKey/resolveValue. Signed-off-by: Bryan Frimin <bryan@probo.com>
This commit is contained in:
@@ -166,8 +166,26 @@ func TestActionMatcher_Matches(t *testing.T) {
|
||||
target: "documents:document:read",
|
||||
want: false,
|
||||
},
|
||||
{
|
||||
name: "two-part pattern without wildcard is invalid",
|
||||
pattern: "iam:identity",
|
||||
target: "iam:identity:get",
|
||||
want: false,
|
||||
},
|
||||
|
||||
// Invalid targets
|
||||
{
|
||||
name: "single-part non-wildcard pattern is invalid",
|
||||
pattern: "iam",
|
||||
target: "iam:identity:get",
|
||||
want: false,
|
||||
},
|
||||
{
|
||||
name: "pattern with too many parts is invalid",
|
||||
pattern: "iam:identity:get:extra",
|
||||
target: "iam:identity:get",
|
||||
want: false,
|
||||
},
|
||||
{
|
||||
name: "invalid target - too few parts",
|
||||
pattern: "iam:identity:get",
|
||||
|
||||
Reference in New Issue
Block a user