RBAC: Make RBAC action names more consistent (#49730)

* update action names

* correctly retrieve teams for signed in user

* remove test

* undo swagger changes

* undo swagger changes pt2

* add migration from old action names to the new ones

* rename from list to read

* linting

* also update alertign actions

* fix migration
This commit is contained in:
Ieva
2022-06-02 13:14:48 +01:00
committed by GitHub
parent 24c6a73095
commit 5dbea9996b
32 changed files with 279 additions and 222 deletions
@@ -79,7 +79,7 @@ Query Parameters:
| Action | Scope |
| ---------- | -------- |
| roles:list | roles:\* |
| roles:read | roles:\* |
#### Example request
@@ -180,13 +180,13 @@ Content-Type: application/json; charset=UTF-8
"created": "2021-11-19T10:48:00+01:00"
},
{
"action": "reports.admin:create",
"action": "reports:create",
"scope": "",
"updated": "2021-11-19T10:48:00+01:00",
"created": "2021-11-19T10:48:00+01:00"
},
{
"action": "reports.admin:write",
"action": "reports:write",
"scope": "reports:*",
"updated": "2021-11-19T10:48:00+01:00",
"created": "2021-11-19T10:48:00+01:00"
@@ -489,7 +489,7 @@ Query Parameters:
| Action | Scope |
| ---------------- | -------------------- |
| users.roles:list | users:id:`<user ID>` |
| users.roles:read | users:id:`<user ID>` |
#### Example request
@@ -537,7 +537,7 @@ Lists the permissions that a given user has.
| Action | Scope |
| ---------------------- | -------------------- |
| users.permissions:list | users:id:`<user ID>` |
| users.permissions:read | users:id:`<user ID>` |
#### Example request
@@ -763,7 +763,7 @@ Query Parameters:
| Action | Scope |
| ---------------- | -------------------- |
| teams.roles:list | teams:id:`<team ID>` |
| teams.roles:read | teams:id:`<team ID>` |
#### Example request
+10 -10
View File
@@ -380,9 +380,9 @@ Change password for a specific user.
See note in the [introduction]({{< ref "#admin-api" >}}) for an explanation.
| Action | Scope |
| --------------------- | --------------- |
| users.password:update | global.users:\* |
| Action | Scope |
| -------------------- | --------------- |
| users.password:write | global.users:\* |
**Example Request**:
@@ -413,9 +413,9 @@ Only works with Basic Authentication (username and password). See [introduction]
See note in the [introduction]({{< ref "#admin-api" >}}) for an explanation.
| Action | Scope |
| ------------------------ | --------------- |
| users.permissions:update | global.users:\* |
| Action | Scope |
| ----------------------- | --------------- |
| users.permissions:write | global.users:\* |
**Example Request**:
@@ -516,7 +516,7 @@ See note in the [introduction]({{< ref "#admin-api" >}}) for an explanation.
| Action | Scope |
| -------------------- | --------------- |
| users.authtoken:list | global.users:\* |
| users.authtoken:read | global.users:\* |
**Example Request**:
@@ -573,9 +573,9 @@ Only works with Basic Authentication (username and password). See [introduction]
See note in the [introduction]({{< ref "#admin-api" >}}) for an explanation.
| Action | Scope |
| ---------------------- | --------------- |
| users.authtoken:update | global.users:\* |
| Action | Scope |
| --------------------- | --------------- |
| users.authtoken:write | global.users:\* |
**Example Request**:
@@ -71,9 +71,9 @@ Manually ask license issuer for a new token.
See note in the [introduction]({{< ref "#enterprise-license-api" >}}) for an explanation.
| Action | Scope |
| ---------------- | ----- |
| licensing:update | n/a |
| Action | Scope |
| --------------- | ----- |
| licensing:write | n/a |
### Examples
+6 -6
View File
@@ -149,9 +149,9 @@ Content-Type: application/json
See note in the [introduction]({{< ref "#organization-api" >}}) for an explanation.
| Action | Scope |
| --------------------- | -------- |
| org.users.role:update | users:\* |
| Action | Scope |
| --------------- | -------- |
| org.users:write | users:\* |
**Example Request**:
@@ -605,9 +605,9 @@ Only works with Basic Authentication (username and password), see [introduction]
See note in the [introduction]({{< ref "#organization-api" >}}) for an explanation.
| Action | Scope |
| --------------------- | -------- |
| org.users.role:update | users:\* |
| Action | Scope |
| --------------- | -------- |
| org.users:write | users:\* |
**Example Request**:
+13 -12
View File
@@ -140,9 +140,9 @@ Content-Type: application/json
See note in the [introduction]({{< ref "#user-api" >}}) for an explanation.
| Action | Scope |
| ---------- | -------- |
| users:read | users:\* |
| Action | Scope |
| ---------- | --------------- |
| users:read | global.users:\* |
**Example Request**:
@@ -241,9 +241,9 @@ Content-Type: application/json
See note in the [introduction]({{< ref "#user-api" >}}) for an explanation.
| Action | Scope |
| ----------- | -------- |
| users:write | users:\* |
| Action | Scope |
| ----------- | --------------- |
| users:write | global.users:\* |
**Example Request**:
@@ -280,9 +280,9 @@ Content-Type: application/json
See note in the [introduction]({{< ref "#user-api" >}}) for an explanation.
| Action | Scope |
| ---------- | -------- |
| users:read | users:\* |
| Action | Scope |
| ---------- | --------------- |
| users:read | global.users:\* |
**Example Request**:
@@ -318,9 +318,10 @@ Content-Type: application/json
See note in the [introduction]({{< ref "#user-api" >}}) for an explanation.
| Action | Scope |
| ---------------- | -------- |
| users.teams:read | users:\* |
| Action | Scope |
| ---------- | --------------- |
| users:read | global.users:\* |
| teams:read | teams:\* |
**Example Request**: