mirror of
https://github.com/datahub-project/datahub.git
synced 2025-12-14 03:26:47 +00:00
fix(auth): admin role missing privileges (#13337)
This commit is contained in:
parent
894655622d
commit
1de63cc817
22
.github/scripts/check_policies.py
vendored
22
.github/scripts/check_policies.py
vendored
@ -13,10 +13,22 @@ without_info = []
|
|||||||
|
|
||||||
metadata_privileges = set()
|
metadata_privileges = set()
|
||||||
platform_privileges = set()
|
platform_privileges = set()
|
||||||
|
root_user_platform_policy_privileges = set()
|
||||||
|
root_user_all_privileges = set()
|
||||||
|
admin_role_platform_privileges = set()
|
||||||
|
admin_role_all_privileges = set()
|
||||||
for policy in all_policies:
|
for policy in all_policies:
|
||||||
urn = policy["urn"]
|
urn = policy["urn"]
|
||||||
if urn == "urn:li:dataHubPolicy:0":
|
if urn == "urn:li:dataHubPolicy:0":
|
||||||
root_user_platform_policy_privileges = policy["info"]["privileges"]
|
root_user_platform_policy_privileges = policy["info"]["privileges"]
|
||||||
|
root_user_all_privileges.update(set(root_user_platform_policy_privileges))
|
||||||
|
elif urn == "urn:li:dataHubPolicy:1":
|
||||||
|
root_user_all_privileges.update(set(policy["info"]["privileges"]))
|
||||||
|
elif urn == "urn:li:dataHubPolicy:admin-platform-policy":
|
||||||
|
admin_role_platform_privileges = policy["info"]["privileges"]
|
||||||
|
admin_role_all_privileges.update(set(admin_role_platform_privileges))
|
||||||
|
elif urn == "urn:li:dataHubPolicy:admin-metadata-policy":
|
||||||
|
admin_role_all_privileges.update(set(policy["info"]["privileges"]))
|
||||||
elif urn == "urn:li:dataHubPolicy:editor-platform-policy":
|
elif urn == "urn:li:dataHubPolicy:editor-platform-policy":
|
||||||
editor_platform_policy_privileges = policy["info"]["privileges"]
|
editor_platform_policy_privileges = policy["info"]["privileges"]
|
||||||
elif urn == "urn:li:dataHubPolicy:7":
|
elif urn == "urn:li:dataHubPolicy:7":
|
||||||
@ -54,6 +66,16 @@ diff_policies = set(platform_privileges).difference(
|
|||||||
)
|
)
|
||||||
assert len(diff_policies) == 0, f"Missing privileges for root user are {diff_policies}"
|
assert len(diff_policies) == 0, f"Missing privileges for root user are {diff_policies}"
|
||||||
|
|
||||||
|
diff_root_user_admin_role = set(
|
||||||
|
root_user_platform_policy_privileges
|
||||||
|
).difference(set(admin_role_platform_privileges))
|
||||||
|
assert len(diff_root_user_admin_role) == 0, f"Missing privileges for admin role are {diff_root_user_admin_role}"
|
||||||
|
|
||||||
|
diff_root_user_admin_role_all = set(
|
||||||
|
root_user_all_privileges
|
||||||
|
).difference(set(admin_role_all_privileges))
|
||||||
|
assert len(diff_root_user_admin_role_all) == 0, f"Missing privileges for admin role are {diff_root_user_admin_role_all}"
|
||||||
|
|
||||||
# All users privileges checks
|
# All users privileges checks
|
||||||
assert "MANAGE_POLICIES" not in all_user_platform_policy_privileges
|
assert "MANAGE_POLICIES" not in all_user_platform_policy_privileges
|
||||||
assert "MANAGE_USERS_AND_GROUPS" not in all_user_platform_policy_privileges
|
assert "MANAGE_USERS_AND_GROUPS" not in all_user_platform_policy_privileges
|
||||||
|
|||||||
@ -193,7 +193,9 @@
|
|||||||
"MANAGE_STRUCTURED_PROPERTIES",
|
"MANAGE_STRUCTURED_PROPERTIES",
|
||||||
"VIEW_STRUCTURED_PROPERTIES_PAGE",
|
"VIEW_STRUCTURED_PROPERTIES_PAGE",
|
||||||
"MANAGE_DOCUMENTATION_FORMS",
|
"MANAGE_DOCUMENTATION_FORMS",
|
||||||
"MANAGE_FEATURES"
|
"MANAGE_FEATURES",
|
||||||
|
"MANAGE_SYSTEM_OPERATIONS",
|
||||||
|
"GET_PLATFORM_EVENTS"
|
||||||
],
|
],
|
||||||
"displayName": "Admins - Platform Policy",
|
"displayName": "Admins - Platform Policy",
|
||||||
"description": "Admins have all platform privileges.",
|
"description": "Admins have all platform privileges.",
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user