Map platform-root group to platform operator
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 26s
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 26s
This commit is contained in:
parent
41d2e1d1f6
commit
90a20783e5
2 changed files with 34 additions and 0 deletions
|
|
@ -316,8 +316,11 @@ func mapEntryToUser(entry *ldap.Entry) domain.User {
|
|||
func identityEnvelopeFromGroups(groups []string) (string, []string) {
|
||||
tenants := make(map[string]bool)
|
||||
admins := make(map[string]bool)
|
||||
platformOperator := false
|
||||
for _, group := range groups {
|
||||
switch {
|
||||
case group == "net-kingdom-admins":
|
||||
platformOperator = true
|
||||
case strings.HasPrefix(group, "tenant:") && strings.HasSuffix(group, ":users"):
|
||||
tenants[strings.TrimSuffix(group, ":users")] = true
|
||||
case strings.HasPrefix(group, "tenant:") && strings.HasSuffix(group, ":admins"):
|
||||
|
|
@ -326,6 +329,12 @@ func identityEnvelopeFromGroups(groups []string) (string, []string) {
|
|||
admins[tenant] = true
|
||||
}
|
||||
}
|
||||
// Preserve the established bootstrap/platform-root group as an explicit
|
||||
// platform control-plane identity. Tenant envelopes must never narrow or
|
||||
// ambiguously reinterpret platform authority.
|
||||
if platformOperator {
|
||||
return "tenant:platform", []string{"user", "platform-operator"}
|
||||
}
|
||||
if len(tenants) != 1 {
|
||||
return "", []string{}
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue