Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add forgotten label for system-reserved roles #2865

Merged
merged 1 commit into from
Dec 7, 2022
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions src/main/java/run/halo/app/core/extension/Role.java
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,9 @@ public class Role extends AbstractExtension {
"rbac.authorization.halo.run/dependency-rules";
public static final String ROLE_DEPENDENCIES_ANNO = "rbac.authorization.halo.run/dependencies";
public static final String UI_PERMISSIONS_ANNO = "rbac.authorization.halo.run/ui-permissions";

public static final String SYSTEM_RESERVED_LABELS =
"rbac.authorization.halo.run/system-reserved";
public static final String UI_PERMISSIONS_AGGREGATED_ANNO =
"rbac.authorization.halo.run/ui-permissions-aggregated";

Expand Down
46 changes: 8 additions & 38 deletions src/main/java/run/halo/app/security/SuperAdminInitializer.java
Original file line number Diff line number Diff line change
@@ -1,9 +1,7 @@
package run.halo.app.security;

import java.time.Instant;
import java.util.HashMap;
import java.util.List;
import java.util.Map;
import lombok.extern.slf4j.Slf4j;
import org.apache.commons.lang3.RandomStringUtils;
import org.springframework.boot.context.event.ApplicationReadyEvent;
Expand All @@ -12,7 +10,6 @@
import org.springframework.util.StringUtils;
import reactor.core.publisher.Mono;
import run.halo.app.core.extension.Role;
import run.halo.app.core.extension.Role.PolicyRule;
import run.halo.app.core.extension.RoleBinding;
import run.halo.app.core.extension.RoleBinding.RoleRef;
import run.halo.app.core.extension.RoleBinding.Subject;
Expand Down Expand Up @@ -42,28 +39,21 @@ public SuperAdminInitializer(ReactiveExtensionClient client, PasswordEncoder pas
@EventListener
public Mono<Void> initialize(ApplicationReadyEvent readyEvent) {
return client.fetch(User.class, initializer.getSuperAdminUsername())
.switchIfEmpty(Mono.defer(() -> client.create(createAdmin()))
.flatMap(admin -> {
var superRole = createSuperRole();
return client.create(superRole)
.flatMap(role -> {
var binding = bindAdminAndSuperRole(admin, superRole);
return client.create(binding).thenReturn(role);
})
.thenReturn(admin);
}))
.then();
.switchIfEmpty(Mono.defer(() -> client.create(createAdmin())).flatMap(admin -> {
var binding = bindAdminAndSuperRole(admin);
return client.create(binding).thenReturn(admin);
})).then();
}

RoleBinding bindAdminAndSuperRole(User admin, Role superRole) {
RoleBinding bindAdminAndSuperRole(User admin) {
var metadata = new Metadata();
String name =
String.join("-", initializer.getSuperAdminUsername(), SUPER_ROLE_NAME, "binding");
metadata.setName(name);
var roleRef = new RoleRef();
roleRef.setName(superRole.getMetadata().getName());
roleRef.setApiGroup(superRole.groupVersionKind().group());
roleRef.setKind(superRole.getKind());
roleRef.setName(SUPER_ROLE_NAME);
roleRef.setApiGroup(Role.GROUP);
roleRef.setKind(Role.KIND);

var subject = new Subject();
subject.setName(admin.getMetadata().getName());
Expand All @@ -78,26 +68,6 @@ RoleBinding bindAdminAndSuperRole(User admin, Role superRole) {
return roleBinding;
}

Role createSuperRole() {
var metadata = new Metadata();
metadata.setName(SUPER_ROLE_NAME);
Map<String, String> annotations = new HashMap<>();
annotations.put(Role.UI_PERMISSIONS_ANNO, "[\"*\"]");
metadata.setAnnotations(annotations);

var superRule = new PolicyRule.Builder()
.apiGroups("*")
.resources("*")
.nonResourceURLs("*")
.verbs("*")
.build();

var role = new Role();
role.setMetadata(metadata);
role.setRules(List.of(superRule));
return role;
}

User createAdmin() {
var metadata = new Metadata();
metadata.setName(initializer.getSuperAdminUsername());
Expand Down
20 changes: 19 additions & 1 deletion src/main/resources/extensions/system-default-role.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,23 @@
apiVersion: v1alpha1
kind: "Role"
kind: Role
metadata:
name: guest
labels:
rbac.authorization.halo.run/system-reserved: "true"
rules: [ ]

---
apiVersion: v1alpha1
kind: Role
metadata:
name: super-role
labels:
rbac.authorization.halo.run/system-reserved: "true"
annotations:
rbac.authorization.halo.run/ui-permissions: |
["*"]
rules:
- apiGroups: ["*"]
resources: ["*"]
nonResourceURLs: ["*"]
verbs: ["*"]