Introduce policy.Attributes and policy.AttributesByID aliases

These aliases (`map[string]string` and `map[gid.GID]Attributes`) give
batch authorization call sites readable types when loading and
returning per-resource condition attributes. ConditionContext now uses
the alias instead of the bare map type, with no behavior change.

Also extend policy tests to cover ResourcePattern.MatchesResource,
comma-separated value handling for In/NotIn, unresolved-reference
fallthrough, and resolveKey/resolveValue.

Signed-off-by: Bryan Frimin <bryan@probo.com>
This commit is contained in:
Bryan Frimin
2026-05-23 11:25:08 -07:00
parent 0c5168b5c6
commit 9b6bee4a27
4 changed files with 423 additions and 8 deletions

View File

@@ -166,8 +166,26 @@ func TestActionMatcher_Matches(t *testing.T) {
target: "documents:document:read",
want: false,
},
{
name: "two-part pattern without wildcard is invalid",
pattern: "iam:identity",
target: "iam:identity:get",
want: false,
},
// Invalid targets
{
name: "single-part non-wildcard pattern is invalid",
pattern: "iam",
target: "iam:identity:get",
want: false,
},
{
name: "pattern with too many parts is invalid",
pattern: "iam:identity:get:extra",
target: "iam:identity:get",
want: false,
},
{
name: "invalid target - too few parts",
pattern: "iam:identity:get",