An organization ADMIN could hard-remove members, including OWNERs, because removeUser (connect and MCP) only checked the weaker iam:membership-profile:delete gate. Authorize the owner-only iam:membership:delete instead, and expose the source attribute on MembershipProfile so the owner grant's non-SCIM condition can match. Consolidate ownership-grant authorization into policy for both createUser and updateMembership: each resolver passes the requested role as a target_role attribute and ADMIN is denied granting ownership via deny-create-owner / deny-promote-owner. target_role is distinct from resource.role, which is the target's current role and guards editing existing owners. With no callers left, the iam:membership-role:set-owner action (grant and OAuth2 scope) is removed. Also pass the authorized scope through to the RemoveUser/CreateUser services, gate the console Remove action on iam:membership:delete, and add regression tests plus a changelog entry. Signed-off-by: Sacha Al Himdani <sacha@probo.com>
108 lines
3.1 KiB
Go
108 lines
3.1 KiB
Go
// Copyright (c) 2026 Probo Inc <hello@probo.com>.
|
|
//
|
|
// Permission to use, copy, modify, and/or distribute this software for any
|
|
// purpose with or without fee is hereby granted, provided that the above
|
|
// copyright notice and this permission notice appear in all copies.
|
|
//
|
|
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
|
|
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
|
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
|
|
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
|
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
|
|
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
|
// PERFORMANCE OF THIS SOFTWARE.
|
|
|
|
package iam
|
|
|
|
import "go.probo.inc/probo/pkg/coredata"
|
|
|
|
const (
|
|
ScopeV1IAMRead coredata.OAuth2Scope = "v1:iam:read"
|
|
ScopeV1IAM coredata.OAuth2Scope = "v1:iam"
|
|
)
|
|
|
|
var IAMOAuth2ScopeMappings = map[coredata.OAuth2Scope][]string{
|
|
ScopeV1IAMRead: {
|
|
ActionOrganizationGet,
|
|
ActionOrganizationList,
|
|
ActionIdentityGet,
|
|
ActionSessionList,
|
|
ActionSessionGet,
|
|
ActionInvitationList,
|
|
ActionInvitationGet,
|
|
ActionMembershipGet,
|
|
ActionMembershipList,
|
|
ActionMembershipProfileGet,
|
|
ActionMembershipProfileList,
|
|
ActionPersonalAPIKeyGet,
|
|
ActionPersonalAPIKeyList,
|
|
ActionSAMLConfigurationGet,
|
|
ActionSAMLConfigurationList,
|
|
ActionSCIMConfigurationGet,
|
|
ActionSCIMEventList,
|
|
ActionSCIMEventGet,
|
|
ActionSCIMBridgeGet,
|
|
ActionOAuth2ConsentGet,
|
|
ActionAuditLogEntryGet,
|
|
ActionAuditLogEntryList,
|
|
ActionOAuth2AccessTokenGet,
|
|
ActionOAuth2AccessTokenList,
|
|
},
|
|
ScopeV1IAM: {
|
|
ActionOrganizationGet,
|
|
ActionOrganizationList,
|
|
ActionIdentityGet,
|
|
ActionSessionList,
|
|
ActionSessionGet,
|
|
ActionInvitationList,
|
|
ActionInvitationGet,
|
|
ActionMembershipGet,
|
|
ActionMembershipList,
|
|
ActionMembershipProfileGet,
|
|
ActionMembershipProfileList,
|
|
ActionPersonalAPIKeyGet,
|
|
ActionPersonalAPIKeyList,
|
|
ActionSAMLConfigurationGet,
|
|
ActionSAMLConfigurationList,
|
|
ActionSCIMConfigurationGet,
|
|
ActionSCIMEventList,
|
|
ActionSCIMEventGet,
|
|
ActionSCIMBridgeGet,
|
|
ActionOAuth2ConsentGet,
|
|
ActionAuditLogEntryGet,
|
|
ActionAuditLogEntryList,
|
|
ActionOAuth2AccessTokenGet,
|
|
ActionOAuth2AccessTokenList,
|
|
ActionOrganizationCreate,
|
|
ActionOrganizationUpdate,
|
|
ActionOrganizationDelete,
|
|
ActionIdentityUpdate,
|
|
ActionIdentityDelete,
|
|
ActionSessionRevoke,
|
|
ActionSessionRevokeAll,
|
|
ActionInvitationCreate,
|
|
ActionInvitationAccept,
|
|
ActionInvitationDelete,
|
|
ActionMembershipUpdate,
|
|
ActionMembershipDelete,
|
|
ActionMembershipProfileCreate,
|
|
ActionMembershipProfileUpdate,
|
|
ActionMembershipProfileDelete,
|
|
ActionMembershipProfileActivate,
|
|
ActionMembershipProfileDeactivate,
|
|
ActionPersonalAPIKeyCreate,
|
|
ActionPersonalAPIKeyUpdate,
|
|
ActionPersonalAPIKeyDelete,
|
|
ActionSAMLConfigurationCreate,
|
|
ActionSAMLConfigurationUpdate,
|
|
ActionSAMLConfigurationDelete,
|
|
ActionSCIMConfigurationCreate,
|
|
ActionSCIMConfigurationUpdate,
|
|
ActionSCIMConfigurationDelete,
|
|
ActionSCIMBridgeCreate,
|
|
ActionSCIMBridgeUpdate,
|
|
ActionSCIMBridgeDelete,
|
|
ActionOAuth2ConsentApprove,
|
|
},
|
|
}
|