Commit Graph

46 Commits

Author SHA1 Message Date
屈轩
f5303d35c9 fix(keystone): policy result (#18284) 2023-10-13 07:30:19 +08:00
Jian Qiu
23a907319a fix: policy tag filters not effect for shared resources (#17004)
Co-authored-by: Qiu Jian <qiujian@yunionyun.com>
2023-05-11 11:00:07 +08:00
Qiu Jian
ccb79efd23 fix: usage filter by policy tags revisit2 2023-02-14 09:19:22 +08:00
Qiu Jian
ca04fcd0de fix: usage filter by policy tags 2023-01-30 21:52:17 +08:00
Jian Qiu
21716cefb5 fix: remove mutual dependency of cloudmux on onecloud (#15621)
Co-authored-by: Qiu Jian <qiujian@yunionyun.com>
2022-12-27 01:21:26 +08:00
Zexi Li
0e2c520ecd feat(misc): use cloudmux package (#15254) 2022-10-28 19:53:03 +08:00
Qiu Jian
1d354d8919 1. Remove is_rbac_enable option
2. code changes due to interface change
2021-12-02 10:24:23 +08:00
Qiu Jian
84a9ae95f6 feature: policy support tags 2021-12-02 07:43:10 +08:00
Qiu Jian
2d39cb4cb0 feature: policy group support 2020-10-24 22:46:46 +08:00
Qiu Jian
be4a76b253 fix: oidc response user's info 2020-09-30 11:54:57 +08:00
Qiu Jian
818d40c08b fix: disable policy rule compaction 2020-06-16 22:36:00 +08:00
Qiu Jian
5ebb18b691 fix: policy-explain not working properly 2020-06-09 22:17:35 +08:00
Qiu Jian
0157028465 fix: ignore match weights when searching matched policysets 2020-05-29 10:01:20 +08:00
Qiu Jian
03477cbe72 fix: default policy not effective 2020-05-22 22:31:14 +08:00
Qiu Jian
728524fefc fix: empty matched policies list for roles 2020-05-22 18:47:57 +08:00
Qiu Jian
f4a676575a fix: anonymous user may list resources 2020-05-19 01:13:00 +08:00
Qiu Jian
54689d862b fix: fail to explain permission for disabled policy 2020-05-16 00:18:28 +08:00
Qiu Jian
ecb483b9be fix: prevent policy violation 2020-04-28 23:28:29 +08:00
郑雨
ba4b9be249 fix: cancel the merge in service level and resource level of Keystone Policy. 2019-11-04 10:44:33 +08:00
Yousong Zhou
8ba5986d83 goimports: first run 2019-10-28 06:22:17 +00:00
Qiu Jian
2c7c817ddc fix: string2scope ignore user scope 2019-10-11 22:06:05 +08:00
Qiu Jian
a177f8c2af fix: use policy match weight to override less specific policy 2019-08-23 21:14:47 +08:00
Qiu Jian
c18359def4 fix: role assignments list should include matched policies 2019-07-25 02:26:39 +08:00
Qiu Jian
2dd12cc14f fix: misc 2019-06-18 10:32:43 +08:00
Qiu Jian
f414d4090a fix: 1. project add user/group rpc paramter error 2. secgrouprule 403 3. 2019-06-13 14:08:59 +08:00
Qiu Jian
74c6a131a4 fix: numerous incorrect privilege issues 2019-06-06 03:23:03 +08:00
Qiu Jian
292c2a141c fix: bugs in scope support 2019-06-04 23:27:55 +08:00
Jian Qiu
72c13b8e39 3level priviliges bufixes 20190603 (#1036) 2019-06-03 12:30:58 +08:00
Qiu Jian
d8e492ee5a misc fixes 2019-05-31 13:56:02 +08:00
Qiu Jian
802b3b0d21 bugfixes 2019-05-31 13:56:02 +08:00
Qiu Jian
b7027934db feature: 3-level policies, system/domain/project 2019-05-31 13:56:02 +08:00
Qiu Jian
fefdb706f3 fix: the default policy for actions not matching any rule defaults to allow 2019-03-29 20:45:38 +08:00
Qiu Jian
004d9b6f95 update copyright headers of all source 2019-03-29 14:47:48 +08:00
Qiu Jian
cc30b585e0 fix: refine policy match conditions 2019-03-21 10:16:55 +08:00
Qiu Jian
06ae94ebe3 fix: simplify rbac policy condition to match projects and roles 2019-03-21 01:03:51 +08:00
Qiu Jian
d008d47f52 Avoid empty policy rules 2018-12-25 16:31:07 +08:00
Qiu Jian
cdec7fa2b7 改进: 1. policy explain增加name参数,允许针对一个policy进行策略测试。2.
将owner,admin统一为allow
2018-12-21 22:02:04 +08:00
Qiu Jian
46aaba2474 make fmt 2018-12-12 23:24:34 +08:00
Qiu Jian
965e84ea36 update 2018-12-07 02:57:58 +08:00
Qiu Jian
4034ee517e make fmt 2018-11-16 01:43:01 +08:00
Qiu Jian
2734d2f5db 增加user/guest两个权利等级 2018-11-16 01:32:01 +08:00
Qiu Jian
ca0e3977c7 minor fixes 2018-11-15 23:41:04 +08:00
Qiu Jian
1d0ad17e36 fix format 2018-11-08 11:39:48 +08:00
Qiu Jian
388b793490 修正:增加owner级别权限,放置普通用户可以访问系统资源 2018-11-08 01:36:19 +08:00
Qiu Jian
11dddd8ad3 remove slice nil check 2018-10-27 19:12:38 +08:00
Qiu Jian
d0fef591f1 改进:model资源支持rbac认证,需要打开enable_rbac选项,默认关闭。非model资源还不支持 2018-10-27 14:34:09 +08:00