Add RBAC functions for workflow for check&grant

This commit is contained in:
Denis Arh
2021-07-15 20:36:57 +02:00
parent 3eafe6c39d
commit 89ae50dbae
7 changed files with 162 additions and 13 deletions
+34
View File
@@ -0,0 +1,34 @@
package workflows
import (
"context"
"testing"
"github.com/cortezaproject/corteza-server/automation/types"
"github.com/cortezaproject/corteza-server/pkg/rbac"
"github.com/stretchr/testify/require"
)
func Test0002_rbac_fn(t *testing.T) {
var (
ctx = bypassRBAC(context.Background())
req = require.New(t)
)
loadScenario(ctx, t)
req.Len(rbac.Global().Rules(), 0)
var (
aux = struct {
CanCurrentRead string
CanOtherRead string
}{}
vars, _ = mustExecWorkflow(ctx, t, "check-and-grant", types.WorkflowExecParams{})
)
req.NoError(vars.Decode(&aux))
req.Equal("y", aux.CanCurrentRead)
req.Equal("n", aux.CanOtherRead)
req.Len(rbac.Global().Rules(), 1)
}
+1
View File
@@ -39,6 +39,7 @@ func TestMain(m *testing.M) {
ctx := context.Background()
defApp = helpers.NewIntegrationTestApp(ctx, func(app *app.CortezaApp) (err error) {
//app.Opt.Workflow.ExecDebug = true
defStore = app.Store
eventbus.Set(eventBus)
return nil
+66
View File
@@ -0,0 +1,66 @@
roles:
testers:
users:
tester:
email: tester@testing-samples.tld
workflows:
check-and-grant:
enabled: true
trace: true
triggers:
- enabled: true
stepID: 1
steps:
- stepID: 1
kind: function
ref: rolesLookup
arguments:
- { target: lookup, type: Handle, value: "testers" }
results:
- { target: res, expr: role }
- stepID: 2
kind: function
ref: rbacCheck
arguments:
- { target: resource, type: RbacResource, expr: "res" }
- { target: operation, type: String, value: "read" }
results:
- { target: canCurrentRead, type: String, expr: 'can ? "y":"n"' }
- stepID: 3
kind: function
ref: usersLookup
arguments:
- { target: lookup, type: Handle, value: "tester" }
results:
- { target: usr, expr: user }
- stepID: 4
kind: function
ref: rbacCheck
arguments:
- { target: resource, type: RbacResource, expr: "res" }
- { target: operation, type: String, value: "read" }
- { target: user, type: User, expr: "usr" }
results:
- { target: canOtherRead, type: String, expr: 'can ? "y":"n"' }
- stepID: 5
kind: function
ref: rbacAllow
arguments:
- { target: resource, type: RbacResource, expr: "res" }
- { target: operation, type: String, value: "read" }
- { target: role, type: Role, expr: "res" }
paths:
- { parentID: 1, childID: 2 }
- { parentID: 2, childID: 3 }
- { parentID: 3, childID: 4 }
- { parentID: 4, childID: 5 }