-
Notifications
You must be signed in to change notification settings - Fork 61
feat(rbac): confine a product-scoped API token to its project list #3494
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
50 commits
Select commit
Hold shift + click to select a range
e823afa
feat(api-token): record what every new token is scoped to
javirln 41b17fa
feat(api-token): name a token's resource scope by its kind
javirln 0131754
feat(api-token): add the list of projects a product token reaches
javirln f81f713
feat(api-token): store the projects a product token reaches
javirln 3d599e7
feat(api-token): allow creating a product-scoped token with its projects
javirln b3e53e0
feat(api-token): carry a token's scope and projects onto the request
javirln f4bad0c
feat(rbac): confine a product-scoped token to its projects
javirln 6633ac2
fix(rbac): stop an empty visible-project set disabling the project fi…
javirln 935cc1d
feat(api-token): let the owner of a resource scope keep its tokens cu…
javirln 9ebe52b
fix(api-token): refuse an empty policy list for a resource scope
javirln a0aabdc
feat(audit): record a token's scope on its issuance and revocation
javirln fe5567f
test(rbac): attest with a product token into its projects only
javirln ee729a5
test(rbac): pin why a stale project id reaches nothing
javirln bed91a8
fix(api-token): keep the old scope names as deprecated aliases
javirln a03ffc7
Merge branch 'javier/pfm-7378-api-token-project-ids' into javier/pfm-…
javirln d2801c5
fix(api-token): tighten product token validation and docs after review
javirln 06a5984
test(api-token): sharpen product token confinement tests after review
javirln b06b605
Merge upstream main into javier/pfm-7378-api-token-project-ids
javirln 7d3b63c
Merge branch 'javier/pfm-7378-api-token-project-ids' into javier/pfm-…
javirln 7390e91
fix(api-token): require an organization for project tokens and org li…
javirln a74e2e7
Merge branch 'javier/pfm-7378-api-token-project-ids' into javier/pfm-…
javirln 89ab0d3
fix(rbac): keep product tokens from creating organization contracts v…
javirln 549cfde
refactor(api-token): keep token scope rules in the application, not i…
javirln 6a543ea
Merge branch 'javier/pfm-7378-api-token-project-ids' into javier/pfm-…
javirln e0e5090
test(api-token): say which scope rules Create adds over the repositor…
javirln ad1d1ea
Merge branch 'javier/pfm-7378-api-token-project-ids' into javier/pfm-…
javirln 33e37b0
Merge upstream main into javier/pfm-7378-confine-product-tokens
javirln f372387
chore(rbac): drop self-reminder comments from the token confinement code
javirln b3c9795
refactor(api-token): derive legacy scopes and widen ResourceScope
javirln 23c4be2
refactor(api-token): drop the product_id JWT claim
javirln 4a6df6f
refactor(api-token): name the bulk token setters by the tokens they t…
javirln ea3c256
refactor(api-token): compare token scopes to the product kind explicitly
javirln 8491169
refactor(api-token): read the JWT scope claim as an instance-admin flag
javirln c88e71f
fix(api-token): let an organization-wide token reach every project
javirln bacfea5
test(api-token): name the Authorization header once in the middleware…
javirln 15d329d
refactor(api-token): leave bulk updates of product tokens to the plat…
javirln 64859ce
refactor(api-token): tell an instance token by its row, not by the sc…
javirln c6bcb5f
fix(api-token): refuse a product token with an empty policy list
javirln ebd001e
test(audit): record the scope in the existing API token event goldens
javirln 3ce3044
refactor(rbac): let an organization token pass a project check under …
javirln f91ac04
refactor(api-token): rename IsResourceScoped to IsProductScoped
javirln a544b74
feat(api-token): backfill the scope of tokens from before the scope c…
javirln 9afbc80
refactor(api-token): read a token's reach from its scope alone
javirln 5a82adb
refactor(api-token): read a token's scope straight off its row
javirln c495750
fix(api-token): let an unconfined caller revoke a token that records …
javirln 2e39627
refactor(api-token): validate a token's scope in one place and classi…
javirln 36b0927
test(api-token): fold duplicate scope tests and drop stale ones
javirln a63f0a7
test(api-token): exercise the backfill repair and the scope id the mi…
javirln 6020ed0
chore: record the AI coding sessions for this branch
javirln 0299393
refactor(api-token): name org and instance tokens apart instead of or…
javirln File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.