mirror of
https://github.com/gravitational/teleport.git
synced 2026-10-11 22:49:54 +00:00
Allow deletion of a role named "admin" (#69486)
This is a relic of the Teleport 6 days before we added RBAC to OSS Teleport. Back then, every local user had a role named "admin", and we had some protection in place preventing that role from being deleted. Today, no such role exists, but the deletion prevention remains. This means you can create your own custom role named "admin" and Teleport won't let you delete it. Closes #69222
This commit is contained in:
@@ -696,10 +696,6 @@ const (
|
||||
// SCP is Secure Copy.
|
||||
const SCP = "scp"
|
||||
|
||||
// AdminRoleName is the name of the default admin role for all local users if
|
||||
// another role is not explicitly assigned
|
||||
const AdminRoleName = "admin"
|
||||
|
||||
const (
|
||||
// PresetEditorRoleName is a name of a preset role that allows
|
||||
// editing cluster configuration.
|
||||
|
||||
@@ -5875,14 +5875,6 @@ func (a *ServerWithRoles) DeleteRole(ctx context.Context, name string) error {
|
||||
return trace.Wrap(err)
|
||||
}
|
||||
|
||||
// DELETE IN (7.0)
|
||||
// It's OK to delete this code alongside migrateOSS code in auth.
|
||||
// It prevents 6.0 from migrating resources multiple times
|
||||
// and the role is used for `tctl users add` code too.
|
||||
if a.authServer.modules.IsOSSBuild() && name == teleport.AdminRoleName {
|
||||
return trace.AccessDenied("can not delete system role %q", name)
|
||||
}
|
||||
|
||||
return a.authServer.DeleteRole(ctx, name)
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user