Remove ActionFileDownloadUrl, replace with ActionFileGet

The two actions expressed the same permission. Consolidate on
core:file:get and remove the now-redundant core:file:download-url
constant, policy entries, and all three call sites.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
Ludovic Vielle
2026-06-08 19:54:18 +02:00
parent 6f83d9be48
commit d94864fe2d
3 changed files with 5 additions and 6 deletions

View File

@@ -295,8 +295,7 @@ const (
ActionCustomDomainDelete = "core:custom-domain:delete"
// File actions
ActionFileGet = "core:file:get"
ActionFileDownloadUrl = "core:file:download-url"
ActionFileGet = "core:file:get"
// Connector actions
ActionConnectorInitiate = "core:connector:initiate"

View File

@@ -76,7 +76,7 @@ var ViewerPolicy = policy.NewPolicy(
ActionProcessingActivityGet, ActionProcessingActivityList,
ActionDataProtectionImpactAssessmentGet, ActionDataProtectionImpactAssessmentList,
ActionTransferImpactAssessmentGet, ActionTransferImpactAssessmentList,
ActionFileGet, ActionFileDownloadUrl,
ActionFileGet,
ActionSlackConnectionList, ActionConnectorList,
ActionRightsRequestGet, ActionRightsRequestList,
ActionStatementOfApplicabilityGet, ActionStatementOfApplicabilityList,
@@ -164,7 +164,7 @@ var AuditorPolicy = policy.NewPolicy(
ActionProcessingActivityGet, ActionProcessingActivityList,
ActionDataProtectionImpactAssessmentGet, ActionDataProtectionImpactAssessmentList,
ActionTransferImpactAssessmentGet, ActionTransferImpactAssessmentList,
ActionFileGet, ActionFileDownloadUrl,
ActionFileGet,
ActionStatementOfApplicabilityGet, ActionStatementOfApplicabilityList,
ActionApplicabilityStatementGet, ActionApplicabilityStatementList,
ActionRiskAssessmentGet, ActionRiskAssessmentList,

View File

@@ -984,7 +984,7 @@ func (r *thirdPartyBusinessAssociateAgreementResolver) ThirdParty(ctx context.Co
// FileURL is the resolver for the fileUrl field.
func (r *thirdPartyBusinessAssociateAgreementResolver) FileURL(ctx context.Context, obj *types.ThirdPartyBusinessAssociateAgreement) (string, error) {
scope, err := r.authorize(ctx, obj.ID, probo.ActionFileDownloadUrl)
scope, err := r.authorize(ctx, obj.ID, probo.ActionFileGet)
if err != nil {
return "", err
}
@@ -1175,7 +1175,7 @@ func (r *thirdPartyDataPrivacyAgreementResolver) ThirdParty(ctx context.Context,
// FileURL is the resolver for the fileUrl field.
func (r *thirdPartyDataPrivacyAgreementResolver) FileURL(ctx context.Context, obj *types.ThirdPartyDataPrivacyAgreement) (string, error) {
scope, err := r.authorize(ctx, obj.ID, probo.ActionFileDownloadUrl)
scope, err := r.authorize(ctx, obj.ID, probo.ActionFileGet)
if err != nil {
return "", err
}