Register API scopes on prb CLI OAuth client
Device logins only requested OIDC scopes while the authorizer now gates API calls on v1:* scopes. Register the full scope set on the well-known prb client, request it at login via CLIClientScopes, and cover the device flow in e2e. Collapse API scopes under an accordion on the consent screen and document scope sync for future namespace additions. Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
61
pkg/coredata/migrations/20260618T120002Z.sql
Normal file
61
pkg/coredata/migrations/20260618T120002Z.sql
Normal file
@@ -0,0 +1,61 @@
|
||||
-- Copyright (c) 2026 Probo Inc <hello@probo.com>.
|
||||
--
|
||||
-- Permission to use, copy, modify, and/or distribute this software for any
|
||||
-- purpose with or without fee is hereby granted, provided that the above
|
||||
-- copyright notice and this permission notice appear in all copies.
|
||||
--
|
||||
-- THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
|
||||
-- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
-- AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
-- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
-- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
||||
-- OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
-- PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
-- Register API scopes on the Probo CLI OAuth2 client so the device
|
||||
-- authorization flow can request v1:* scopes under enforcement.
|
||||
UPDATE iam_oauth2_clients
|
||||
SET scopes = '{
|
||||
openid,
|
||||
profile,
|
||||
email,
|
||||
offline_access,
|
||||
v1:access-review,
|
||||
v1:access-review:read,
|
||||
v1:agent,
|
||||
v1:agent:read,
|
||||
v1:asset,
|
||||
v1:asset:read,
|
||||
v1:audit,
|
||||
v1:audit:read,
|
||||
v1:common-third-party,
|
||||
v1:common-third-party:read,
|
||||
v1:compliance-page,
|
||||
v1:compliance-page:read,
|
||||
v1:connector,
|
||||
v1:connector:read,
|
||||
v1:control,
|
||||
v1:control:read,
|
||||
v1:datum,
|
||||
v1:datum:read,
|
||||
v1:document,
|
||||
v1:document:read,
|
||||
v1:iam,
|
||||
v1:iam:read,
|
||||
v1:org,
|
||||
v1:org:read,
|
||||
v1:privacy,
|
||||
v1:privacy:read,
|
||||
v1:risk,
|
||||
v1:risk:read,
|
||||
v1:slack-connection,
|
||||
v1:slack-connection:read,
|
||||
v1:task,
|
||||
v1:task:read,
|
||||
v1:third-party,
|
||||
v1:third-party:read,
|
||||
v1:webhook,
|
||||
v1:webhook:read
|
||||
}'::TEXT[],
|
||||
updated_at = NOW()
|
||||
WHERE id = 'AAAAAAAAAAAASwAAAAAAAAAAcHJiY2xp';
|
||||
56
pkg/coredata/migrations/20260618T120003Z.sql
Normal file
56
pkg/coredata/migrations/20260618T120003Z.sql
Normal file
@@ -0,0 +1,56 @@
|
||||
-- Copyright (c) 2026 Probo Inc <hello@probo.com>.
|
||||
--
|
||||
-- Permission to use, copy, modify, and/or distribute this software for any
|
||||
-- purpose with or without fee is hereby granted, provided that the above
|
||||
-- copyright notice and this permission notice appear in all copies.
|
||||
--
|
||||
-- THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
|
||||
-- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
-- AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
-- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
-- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
||||
-- OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
-- PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
-- Well-known OAuth2 client for Auditor Mode (prbaud).
|
||||
-- Read scopes plus v1:control for measure mutations. Keep in sync with
|
||||
-- Constants.OAuth2.scopes in the Auditor Mode macOS app.
|
||||
INSERT INTO iam_oauth2_clients (
|
||||
id,
|
||||
tenant_id,
|
||||
organization_id,
|
||||
client_name,
|
||||
visibility,
|
||||
redirect_uris,
|
||||
scopes,
|
||||
grant_types,
|
||||
response_types,
|
||||
token_endpoint_auth_method,
|
||||
created_at,
|
||||
updated_at
|
||||
) VALUES (
|
||||
'AAAAAAAAAAAASwAAAAAAAAAAcHJiYXVk',
|
||||
NULL,
|
||||
NULL,
|
||||
'Auditor Mode',
|
||||
'public',
|
||||
'{}',
|
||||
'{
|
||||
openid,
|
||||
profile,
|
||||
email,
|
||||
offline_access,
|
||||
v1:control:read,
|
||||
v1:org:read,
|
||||
v1:control
|
||||
}'::TEXT[],
|
||||
'{urn:ietf:params:oauth:grant-type:device_code,refresh_token}',
|
||||
'{code}',
|
||||
'none',
|
||||
NOW(),
|
||||
NOW()
|
||||
)
|
||||
ON CONFLICT (id) DO UPDATE
|
||||
SET
|
||||
scopes = EXCLUDED.scopes,
|
||||
updated_at = NOW();
|
||||
Reference in New Issue
Block a user