Skip to content

Commit

Permalink
VAULT-15840: Allow updates of only entity-alias custom-metadata (hash…
Browse files Browse the repository at this point in the history
…icorp#20368)

* allow updates of only custom metadata

* add changelog
  • Loading branch information
miagilepner authored May 1, 2023
1 parent 90bc695 commit 884840a
Show file tree
Hide file tree
Showing 3 changed files with 46 additions and 2 deletions.
3 changes: 3 additions & 0 deletions changelog/20368.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
```release-note:bug
core/identity: Allow updates of only the custom-metadata for entity alias.
```
5 changes: 3 additions & 2 deletions vault/identity_store_aliases.go
Original file line number Diff line number Diff line change
Expand Up @@ -211,8 +211,9 @@ func (i *IdentityStore) handleAliasCreateUpdate() framework.OperationFunc {
}
switch {
case mountAccessor == "" && name == "":
// Just a canonical ID update, maybe
if canonicalID == "" {
// Check if the canonicalID or the customMetadata are being
// updated
if canonicalID == "" && !customMetadataExists {
// Nothing to do, so be idempotent
return nil, nil
}
Expand Down
40 changes: 40 additions & 0 deletions vault/identity_store_aliases_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -461,6 +461,46 @@ func TestIdentityStore_AliasUpdate(t *testing.T) {
"custom_metadata": map[string]string{},
},
},
{
name: "only-metadata",
createData: map[string]interface{}{
"name": "only",
"mount_accessor": githubAccessor,
"custom_metadata": map[string]string{
"foo": "bar",
},
},
updateData: map[string]interface{}{
"custom_metadata": map[string]string{
"bar": "baz",
},
},
},
{
name: "only-metadata-clear",
createData: map[string]interface{}{
"name": "only-clear",
"mount_accessor": githubAccessor,
"custom_metadata": map[string]string{
"foo": "bar",
},
},
updateData: map[string]interface{}{
"custom_metadata": map[string]string{},
},
},
{
name: "only-metadata-none-before",
createData: map[string]interface{}{
"name": "no-metadata",
"mount_accessor": githubAccessor,
},
updateData: map[string]interface{}{
"custom_metadata": map[string]string{
"foo": "bar",
},
},
},
}

handleRequest := func(t *testing.T, req *logical.Request) *logical.Response {
Expand Down

0 comments on commit 884840a

Please sign in to comment.