Remove ActionFileDownloadUrl, replace with ActionFileGet
The two actions expressed the same permission. Consolidate on core:file:get and remove the now-redundant core:file:download-url constant, policy entries, and all three call sites. Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
@@ -295,8 +295,7 @@ const (
|
||||
ActionCustomDomainDelete = "core:custom-domain:delete"
|
||||
|
||||
// File actions
|
||||
ActionFileGet = "core:file:get"
|
||||
ActionFileDownloadUrl = "core:file:download-url"
|
||||
ActionFileGet = "core:file:get"
|
||||
|
||||
// Connector actions
|
||||
ActionConnectorInitiate = "core:connector:initiate"
|
||||
|
||||
@@ -76,7 +76,7 @@ var ViewerPolicy = policy.NewPolicy(
|
||||
ActionProcessingActivityGet, ActionProcessingActivityList,
|
||||
ActionDataProtectionImpactAssessmentGet, ActionDataProtectionImpactAssessmentList,
|
||||
ActionTransferImpactAssessmentGet, ActionTransferImpactAssessmentList,
|
||||
ActionFileGet, ActionFileDownloadUrl,
|
||||
ActionFileGet,
|
||||
ActionSlackConnectionList, ActionConnectorList,
|
||||
ActionRightsRequestGet, ActionRightsRequestList,
|
||||
ActionStatementOfApplicabilityGet, ActionStatementOfApplicabilityList,
|
||||
@@ -164,7 +164,7 @@ var AuditorPolicy = policy.NewPolicy(
|
||||
ActionProcessingActivityGet, ActionProcessingActivityList,
|
||||
ActionDataProtectionImpactAssessmentGet, ActionDataProtectionImpactAssessmentList,
|
||||
ActionTransferImpactAssessmentGet, ActionTransferImpactAssessmentList,
|
||||
ActionFileGet, ActionFileDownloadUrl,
|
||||
ActionFileGet,
|
||||
ActionStatementOfApplicabilityGet, ActionStatementOfApplicabilityList,
|
||||
ActionApplicabilityStatementGet, ActionApplicabilityStatementList,
|
||||
ActionRiskAssessmentGet, ActionRiskAssessmentList,
|
||||
|
||||
@@ -984,7 +984,7 @@ func (r *thirdPartyBusinessAssociateAgreementResolver) ThirdParty(ctx context.Co
|
||||
|
||||
// FileURL is the resolver for the fileUrl field.
|
||||
func (r *thirdPartyBusinessAssociateAgreementResolver) FileURL(ctx context.Context, obj *types.ThirdPartyBusinessAssociateAgreement) (string, error) {
|
||||
scope, err := r.authorize(ctx, obj.ID, probo.ActionFileDownloadUrl)
|
||||
scope, err := r.authorize(ctx, obj.ID, probo.ActionFileGet)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
@@ -1175,7 +1175,7 @@ func (r *thirdPartyDataPrivacyAgreementResolver) ThirdParty(ctx context.Context,
|
||||
|
||||
// FileURL is the resolver for the fileUrl field.
|
||||
func (r *thirdPartyDataPrivacyAgreementResolver) FileURL(ctx context.Context, obj *types.ThirdPartyDataPrivacyAgreement) (string, error) {
|
||||
scope, err := r.authorize(ctx, obj.ID, probo.ActionFileDownloadUrl)
|
||||
scope, err := r.authorize(ctx, obj.ID, probo.ActionFileGet)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user