Authorize scoped public registration applicants
This commit is contained in:
parent
693136edbc
commit
b74756791a
3 changed files with 21 additions and 0 deletions
|
|
@ -43,6 +43,16 @@ roles := object.get(object.get(input.subject, "attributes", {}), "roles", [])
|
|||
subject_tenant := object.get(input.subject, "tenant", "")
|
||||
resource_tenant := object.get(input.resource, "tenant", input.tenant)
|
||||
self_request := object.get(input.context, "self", false)
|
||||
resource_type := object.get(input.resource, "type", "")
|
||||
subject_issuer := object.get(object.get(input.subject, "attributes", {}), "issuer", "")
|
||||
|
||||
registration_applicant if {
|
||||
"registration-applicant" in roles
|
||||
subject_issuer == "urn:netkingdom:public-registration"
|
||||
same_tenant
|
||||
startswith(input.action, "registration.")
|
||||
resource_type in {"user-engine:registration", "user-engine:registration-factor"}
|
||||
}
|
||||
|
||||
decision := {"effect": "allow", "reason": "platform_operator"} if {
|
||||
valid_system
|
||||
|
|
@ -55,6 +65,9 @@ decision := {"effect": "allow", "reason": "platform_operator"} if {
|
|||
valid_system
|
||||
same_tenant
|
||||
self_request == true
|
||||
} else := {"effect": "allow", "reason": "registration_applicant"} if {
|
||||
valid_system
|
||||
registration_applicant
|
||||
} else := {"effect": "deny", "reason": first_denial} if { true }
|
||||
|
||||
valid_system if { input.resource.system == "user-engine" }
|
||||
|
|
@ -80,4 +93,7 @@ test_platform_operator_cross_tenant_allowed if { portal.decision.effect == "allo
|
|||
test_cross_tenant_denied if { portal.decision.reason == "cross_tenant" with input as object.union(base, {"subject": object.union(base.subject, {"tenant": "tenant:family:other"})}) }
|
||||
test_missing_role_denied if { portal.decision.effect == "deny" with input as {"tenant": "tenant:friendly:binky", "subject": {"id": "u1", "type": "human", "tenant": "tenant:friendly:binky", "attributes": {"roles": []}}, "action": "membership.write", "resource": {"id": "m1", "type": "user-engine:membership", "system": "user-engine", "tenant": "tenant:friendly:binky"}, "context": {}} }
|
||||
test_wrong_system_denied if { portal.decision.reason == "wrong_system" with input as object.union(base, {"resource": object.union(base.resource, {"system": "other"})}) }
|
||||
test_registration_applicant_allowed if { portal.decision.reason == "registration_applicant" with input as {"tenant": "tenant:friendly:binky", "subject": {"id": "applicant", "type": "human", "tenant": "tenant:friendly:binky", "attributes": {"roles": ["registration-applicant"], "issuer": "urn:netkingdom:public-registration"}}, "action": "registration.start", "resource": {"id": "new", "type": "user-engine:registration", "system": "user-engine", "tenant": "tenant:friendly:binky"}, "context": {}} }
|
||||
test_registration_applicant_other_action_denied if { portal.decision.effect == "deny" with input as {"tenant": "tenant:friendly:binky", "subject": {"id": "applicant", "type": "human", "tenant": "tenant:friendly:binky", "attributes": {"roles": ["registration-applicant"], "issuer": "urn:netkingdom:public-registration"}}, "action": "membership.write", "resource": {"id": "m1", "type": "user-engine:membership", "system": "user-engine", "tenant": "tenant:friendly:binky"}, "context": {}} }
|
||||
test_registration_applicant_wrong_issuer_denied if { portal.decision.effect == "deny" with input as {"tenant": "tenant:friendly:binky", "subject": {"id": "applicant", "type": "human", "tenant": "tenant:friendly:binky", "attributes": {"roles": ["registration-applicant"], "issuer": "untrusted"}}, "action": "registration.start", "resource": {"id": "new", "type": "user-engine:registration", "system": "user-engine", "tenant": "tenant:friendly:binky"}, "context": {}} }
|
||||
```
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue