Replace pkg/iam/scopeset with pkg/iam/oauth2scope.Registry, a shared OAuth2 scope→action registry used by the authorizer, OAuth2 service, and Connect API. Registration stays open until probod calls Freeze(); read paths (RegisteredScopes, Allows, ValidateScopes) panic before that. Drop the leaky APIScopes surface and AllowedAPIScopes on manual access-token creation in favor of registry.ValidateScopes. Metadata, protected-resource metadata, and CIMD scope lists are built from RegisteredScopes() via helpers in pkg/iam/oauth2/scopes.go. Expose oauth2ScopesSupported as an OAuth2Scope GraphQL scalar. Signed-off-by: Ludovic Vielle <ludovic@probo.com>
55 lines
1.4 KiB
JSON
55 lines
1.4 KiB
JSON
{
|
|
"root": ".",
|
|
"featureFlags": {
|
|
"enforce_fragment_alias_where_ambiguous": { "kind": "disabled" }
|
|
},
|
|
"sources": {
|
|
"apps/console/src/pages/iam": "iam",
|
|
"apps/console/src": "core",
|
|
"apps/trust/src": "trust"
|
|
},
|
|
"projects": {
|
|
"core": {
|
|
"schema": "pkg/server/api/console/v1/schema.graphql",
|
|
"language": "typescript",
|
|
"noFutureProofEnums": true,
|
|
"output": "apps/console/src/__generated__/core",
|
|
"relativizeJsModulePaths": false,
|
|
"customScalarTypes": {
|
|
"Datetime": "string",
|
|
"GID": "string",
|
|
"CursorKey": "string",
|
|
"Duration": "string",
|
|
"BigInt": "number",
|
|
"EmailAddr": "string"
|
|
}
|
|
},
|
|
"iam": {
|
|
"schema": "pkg/server/api/connect/v1/schema.graphql",
|
|
"language": "typescript",
|
|
"noFutureProofEnums": true,
|
|
"output": "apps/console/src/__generated__/iam",
|
|
"relativizeJsModulePaths": false,
|
|
"customScalarTypes": {
|
|
"Datetime": "string",
|
|
"GID": "string",
|
|
"CursorKey": "string",
|
|
"Duration": "string",
|
|
"BigInt": "number",
|
|
"EmailAddr": "string",
|
|
"OAuth2Scope": "string"
|
|
}
|
|
},
|
|
"trust": {
|
|
"schema": "pkg/server/api/trust/v1/schema.graphql",
|
|
"language": "typescript",
|
|
"noFutureProofEnums": true,
|
|
"customScalarTypes": {
|
|
"Datetime": "string",
|
|
"CursorKey": "string",
|
|
"EmailAddr": "string"
|
|
}
|
|
}
|
|
}
|
|
}
|