authz

package
v0.19.1161 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 2, 2026 License: AGPL-3.0 Imports: 18 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func CanCreate

func CanCreate(ctx *gin.Context, objectID string) error

func CanDelete

func CanDelete(ctx *gin.Context, objectID string) error

func CanRead

func CanRead(ctx *gin.Context, objectID string) error

func CanUpdate

func CanUpdate(ctx *gin.Context, objectID string) error

func DeleteStackInstallRoles added in v0.19.1149

func DeleteStackInstallRoles(tx *gorm.DB, accountID string) error

DeleteStackInstallRoles hard-deletes the stack roles bound to an account, and their policies. They are per-account garbage once the account is gone, and a soft delete would keep the unique policy-per-role index occupied.

tx is expected to be a transaction.

func ReconcileOrgRoles added in v0.19.1115

func ReconcileOrgRoles(ctx context.Context, db *gorm.DB, org app.Org) error

ReconcileOrgRoles brings an org's managed roles in line with standardOrgRoles: missing roles are created (with their policies), and existing roles have their metadata (title, description, contexts, managed) updated to match the definition. Existing rows' policies are deliberately never modified.

Types

type Client

type Client struct {
	// contains filtered or unexported fields
}

func New

func New(params Params) *Client

func (*Client) AcceptInvite

func (h *Client) AcceptInvite(ctx context.Context, invite *app.OrgInvite, acct *app.Account) error

func (*Client) AddAccountOrgRole

func (h *Client) AddAccountOrgRole(ctx context.Context, roleType app.RoleType, orgID, accountID string) error

func (*Client) AddAccountRoleByID

func (h *Client) AddAccountRoleByID(ctx context.Context, roleID, accountID string) error

func (*Client) AssignableRoles added in v0.19.1115

func (c *Client) AssignableRoles(ctx context.Context, orgID, roleContext string) ([]app.Role, error)

AssignableRoles returns the org's roles offerable on the given assignment surface (see app.RoleContext*), ordered by role type.

func (*Client) CreateOrgRoles

func (c *Client) CreateOrgRoles(ctx context.Context, orgID string) error

func (*Client) EnsureStackInstallRole added in v0.19.1149

func (h *Client) EnsureStackInstallRole(ctx context.Context, orgID, installID, accountID string) error

EnsureStackInstallRole converges a stack account's install-scoped role: one role, one policy, on this install's stack object. Looked up through the account's own binding, since the account is already per-install.

func (*Client) RemoveAccountOrgRoleByType added in v0.19.1149

func (h *Client) RemoveAccountOrgRoleByType(ctx context.Context, roleType app.RoleType, orgID, accountID string) error

RemoveAccountOrgRoleByType drops one role binding, unlike RemoveAccountOrgRoles, which clears every binding in an org.

func (*Client) RemoveAccountOrgRoles

func (h *Client) RemoveAccountOrgRoles(ctx context.Context, orgID, accountID string) error

func (*Client) ResolveAssignableRole added in v0.19.1115

func (c *Client) ResolveAssignableRole(ctx context.Context, orgID string, roleType app.RoleType, roleContext string) (*app.Role, error)

ResolveAssignableRole validates that roleType is offerable on the given surface in the org and returns its role row. The error lists the roles that are assignable there.

func (*Client) SetAccountOrgRole added in v0.19.1075

func (h *Client) SetAccountOrgRole(ctx context.Context, orgID, accountID string, roleType app.RoleType) error

SetAccountOrgRole replaces an account's role(s) in an org with a single role of the given type. Unlike RemoveAccountOrgRoles it does not touch the account's OrgInvite records, so it is safe for in-place role changes.

type Params

type Params struct {
	fx.In

	Cfg             *internal.Config
	DB              *gorm.DB `name:"psql"`
	V               *validator.Validate
	AnalyticsClient analytics.Writer
}

Directories

Path Synopsis
Package require turns a route's declared resource and verb into the gin middleware that authorizes it.
Package require turns a route's declared resource and verb into the gin middleware that authorizes it.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL