Skip to content
体验新版
项目
组织
正在加载...
登录
切换导航
打开侧边栏
水淹萌龙
kubesphere
提交
24cbc083
K
kubesphere
项目概览
水淹萌龙
/
kubesphere
与 Fork 源项目一致
Fork自
KubeSphere / kubesphere
通知
1
Star
0
Fork
0
代码
文件
提交
分支
Tags
贡献者
分支图
Diff
Issue
0
列表
看板
标记
里程碑
合并请求
0
DevOps
流水线
流水线任务
计划
Wiki
0
Wiki
分析
仓库
DevOps
项目成员
Pages
K
kubesphere
项目概览
项目概览
详情
发布
仓库
仓库
文件
提交
分支
标签
贡献者
分支图
比较
Issue
0
Issue
0
列表
看板
标记
里程碑
合并请求
0
合并请求
0
Pages
DevOps
DevOps
流水线
流水线任务
计划
分析
分析
仓库分析
DevOps
Wiki
0
Wiki
成员
成员
收起侧边栏
关闭侧边栏
动态
分支图
创建新Issue
流水线任务
提交
Issue看板
体验新版 GitCode,发现更多精彩内容 >>
未验证
提交
24cbc083
编写于
11月 04, 2019
作者:
K
KubeSphere CI Bot
提交者:
GitHub
11月 04, 2019
浏览文件
操作
浏览文件
下载
差异文件
Merge pull request #1341 from wansir/policy-rules
refine iam policy rules
上级
04f6eba7
636ace1b
变更
2
隐藏空白更改
内联
并排
Showing
2 changed file
with
19 addition
and
4 deletion
+19
-4
pkg/controller/workspace/workspace_controller.go
pkg/controller/workspace/workspace_controller.go
+8
-3
pkg/models/iam/am.go
pkg/models/iam/am.go
+11
-1
未找到文件。
pkg/controller/workspace/workspace_controller.go
浏览文件 @
24cbc083
...
@@ -574,10 +574,15 @@ func getWorkspaceAdmin(workspaceName string) *rbac.ClusterRole {
...
@@ -574,10 +574,15 @@ func getWorkspaceAdmin(workspaceName string) *rbac.ClusterRole {
APIGroups
:
[]
string
{
"iam.kubesphere.io"
},
APIGroups
:
[]
string
{
"iam.kubesphere.io"
},
Resources
:
[]
string
{
"users"
},
Resources
:
[]
string
{
"users"
},
},
},
{
Verbs
:
[]
string
{
"get"
,
"list"
},
APIGroups
:
[]
string
{
"openpitrix.io"
},
Resources
:
[]
string
{
"categories"
},
},
{
{
Verbs
:
[]
string
{
"*"
},
Verbs
:
[]
string
{
"*"
},
APIGroups
:
[]
string
{
"openpitrix.io"
},
APIGroups
:
[]
string
{
"openpitrix.io"
},
Resources
:
[]
string
{
"applications"
,
"apps"
,
"apps/versions"
,
"apps/events"
,
"apps/action"
,
"apps/audits"
,
"repos"
,
"repos/action"
,
"
categories"
,
"
attachments"
},
Resources
:
[]
string
{
"applications"
,
"apps"
,
"apps/versions"
,
"apps/events"
,
"apps/action"
,
"apps/audits"
,
"repos"
,
"repos/action"
,
"attachments"
},
},
},
}
}
...
@@ -610,13 +615,13 @@ func getWorkspaceRegular(workspaceName string) *rbac.ClusterRole {
...
@@ -610,13 +615,13 @@ func getWorkspaceRegular(workspaceName string) *rbac.ClusterRole {
{
{
Verbs
:
[]
string
{
"get"
,
"list"
},
Verbs
:
[]
string
{
"get"
,
"list"
},
APIGroups
:
[]
string
{
"openpitrix.io"
},
APIGroups
:
[]
string
{
"openpitrix.io"
},
Resources
:
[]
string
{
"apps/events"
,
"apps/action"
,
"apps/audits"
},
Resources
:
[]
string
{
"apps/events"
,
"apps/action"
,
"apps/audits"
,
"categories"
},
},
},
{
{
Verbs
:
[]
string
{
"*"
},
Verbs
:
[]
string
{
"*"
},
APIGroups
:
[]
string
{
"openpitrix.io"
},
APIGroups
:
[]
string
{
"openpitrix.io"
},
Resources
:
[]
string
{
"applications"
,
"apps"
,
"apps/versions"
,
"repos"
,
"repos/action"
,
"
categories"
,
"
attachments"
},
Resources
:
[]
string
{
"applications"
,
"apps"
,
"apps/versions"
,
"repos"
,
"repos/action"
,
"attachments"
},
},
},
}
}
...
...
pkg/models/iam/am.go
浏览文件 @
24cbc083
...
@@ -480,7 +480,16 @@ func GetUserWorkspaceSimpleRules(workspace, username string) ([]models.SimpleRul
...
@@ -480,7 +480,16 @@ func GetUserWorkspaceSimpleRules(workspace, username string) ([]models.SimpleRul
return
nil
,
err
return
nil
,
err
}
}
// workspace manager
// cluster-admin
if
RulesMatchesRequired
(
clusterRules
,
rbacv1
.
PolicyRule
{
Verbs
:
[]
string
{
"*"
},
APIGroups
:
[]
string
{
"*"
},
Resources
:
[]
string
{
"*"
},
})
{
return
GetWorkspaceRoleSimpleRules
(
workspace
,
constants
.
WorkspaceAdmin
),
nil
}
// workspaces-manager
if
RulesMatchesRequired
(
clusterRules
,
rbacv1
.
PolicyRule
{
if
RulesMatchesRequired
(
clusterRules
,
rbacv1
.
PolicyRule
{
Verbs
:
[]
string
{
"*"
},
Verbs
:
[]
string
{
"*"
},
APIGroups
:
[]
string
{
"*"
},
APIGroups
:
[]
string
{
"*"
},
...
@@ -497,6 +506,7 @@ func GetUserWorkspaceSimpleRules(workspace, username string) ([]models.SimpleRul
...
@@ -497,6 +506,7 @@ func GetUserWorkspaceSimpleRules(workspace, username string) ([]models.SimpleRul
}
}
return
nil
,
err
return
nil
,
err
}
}
return
GetWorkspaceRoleSimpleRules
(
workspace
,
workspaceRole
.
Annotations
[
constants
.
DisplayNameAnnotationKey
]),
nil
return
GetWorkspaceRoleSimpleRules
(
workspace
,
workspaceRole
.
Annotations
[
constants
.
DisplayNameAnnotationKey
]),
nil
}
}
...
...
编辑
预览
Markdown
is supported
0%
请重试
或
添加新附件
.
添加附件
取消
You are about to add
0
people
to the discussion. Proceed with caution.
先完成此消息的编辑!
取消
想要评论请
注册
或
登录