mirror of
https://github.com/gravitational/teleport.git
synced 2026-10-11 22:49:54 +00:00
* types: Declare all app_resources fields in the proto
Declare the eight reserved AppResource fields (paths, methods, where,
allow_encoded, allow_code, allow_reason, deny_code_hint,
deny_reason_hint) and the AppResourcesExpressions role condition, and
regenerate the proto stubs, the role CRDs, the Terraform schema and
docs, and the derived equality functions. Declaring the fields before
the fine-grained matcher merges lets every client of this version name
them, so a client that round-trips a role written by a newer auth
preserves the fields instead of silently dropping them on write-back,
which would widen the rule.
Tighten IsAllowAllOnly to require every declared field besides
allow_all to be unset. Without this, a rule such as {allow_all: true,
methods: [GET]} written by a newer auth would pass the check once the
fields are named, and this version would treat a method-restricted
rule as unrestricted.
Add GetAppResourcesExpressions to the Role interface, and read it in
decideMinimalV9 so the app agent denies a request governed by a
predicate it cannot evaluate. A predicate restricts the rules it
accompanies, so a role that pairs allow_all with one is not
unrestricted, and a deny-side predicate blocks another role's
allow_all the same way a deny-side rule does. Auth already treats both
as restricting when it downgrades a role for a pre-v9 client, so
without this the agent and auth disagree about the same role.
Strip AppResourcesExpressions in the v9-to-v8 downgrade alongside
AppResources, and reject it at write, so a role can neither reach a
pre-v9 client with the restriction silently removed nor be stored
while this version cannot enforce it.
* docs: List the declared app_resources fields
Honour the docs review on the app-resources reference page. A run of
inline code-style field names inside a sentence is hard to scan, so the
eight rejected `app_resources` fields become a list, and
`app_resources_expressions` gets its own sentence rather than trailing
the same run.
* buf: Trim the reserved-deletion except comment
Drop the two sentences explaining why buf's ignore lists cannot scope the
except. The rule name and the removal condition are what a reader needs
here, and the scoping attempts are recorded on the pull request.
* types: Reword the app_resources_expressions and Methods docs
Honour the review on the proto field comments. Drop "desugared" from
`AppResourcesExpressions`, which needs the RFD to gloss, and state the
relation between the two forms directly instead. Open `Methods` with the
plural, matching `Paths` on the row above.
Regenerate the proto stubs, the role CRDs, the Terraform schema and docs.
114 lines
4.4 KiB
YAML
114 lines
4.4 KiB
YAML
version: v2
|
|
|
|
modules:
|
|
- path: api/proto
|
|
- path: proto
|
|
|
|
deps:
|
|
# gogo/protobuf v1.3.2, keep in sync with build.assets/versions.mk.
|
|
- buf.build/gogo/protobuf:b03c65ea87cdc3521ede29f62fe3ce239267c1bc
|
|
- buf.build/googleapis/googleapis:beb34b4050abfcfff72ff5cc6a28f0afa4043ce0
|
|
|
|
lint:
|
|
use:
|
|
- STANDARD
|
|
- COMMENT_ENUM
|
|
- COMMENT_MESSAGE
|
|
- COMMENT_RPC
|
|
- COMMENT_SERVICE
|
|
- PACKAGE_NO_IMPORT_CYCLE
|
|
- PAGINATION_REQUIRED
|
|
- UNARY_RPC
|
|
except:
|
|
- FIELD_NOT_REQUIRED
|
|
- RPC_REQUEST_RESPONSE_UNIQUE
|
|
- RPC_RESPONSE_STANDARD_NAME
|
|
ignore:
|
|
- api/proto/teleport/legacy/client/proto/authservice.proto
|
|
- api/proto/teleport/legacy/client/proto/certs.proto
|
|
- api/proto/teleport/legacy/client/proto/event.proto
|
|
- api/proto/teleport/legacy/client/proto/proxyservice.proto
|
|
- api/proto/teleport/legacy/types/events/athena.proto
|
|
- api/proto/teleport/legacy/types/events/events.proto
|
|
- api/proto/teleport/legacy/types/types.proto
|
|
- api/proto/teleport/legacy/types/metadata.proto
|
|
- api/proto/teleport/legacy/types/mfa_device.proto
|
|
- api/proto/teleport/legacy/types/wrappers/wrappers.proto
|
|
- proto/teleport/lib/multiplexer/test/ping.proto
|
|
- proto/teleport/lib/web/terminal/envelope.proto
|
|
ignore_only:
|
|
COMMENT_MESSAGE:
|
|
- proto/prehog
|
|
- proto/teleport/lib/teleterm/v1/access_request.proto
|
|
- proto/teleport/lib/teleterm/v1/app.proto
|
|
- proto/teleport/lib/teleterm/v1/auth_settings.proto
|
|
- proto/teleport/lib/teleterm/v1/cluster.proto
|
|
- proto/teleport/lib/teleterm/v1/database.proto
|
|
- proto/teleport/lib/teleterm/v1/gateway.proto
|
|
- proto/teleport/lib/teleterm/v1/kube.proto
|
|
- proto/teleport/lib/teleterm/v1/label.proto
|
|
- proto/teleport/lib/teleterm/v1/server.proto
|
|
- proto/teleport/lib/teleterm/v1/service.proto
|
|
- proto/teleport/lib/teleterm/v1/usage_events.proto
|
|
COMMENT_RPC:
|
|
- proto/prehog
|
|
COMMENT_SERVICE:
|
|
- proto/prehog
|
|
FIELD_LOWER_SNAKE_CASE:
|
|
- api/proto/teleport/legacy/client/proto/inventory.proto
|
|
- api/proto/teleport/legacy/types/device.proto
|
|
- api/proto/teleport/legacy/types/resources.proto
|
|
PACKAGE_DIRECTORY_MATCH:
|
|
- api/proto/teleport/legacy/client/proto/joinservice.proto
|
|
- api/proto/teleport/legacy/types/device.proto
|
|
- api/proto/teleport/legacy/types/trusted_device_requirement.proto
|
|
- api/proto/teleport/legacy/types/resources.proto
|
|
- api/proto/teleport/legacy/types/webauthn/webauthn.proto
|
|
PACKAGE_VERSION_SUFFIX:
|
|
- api/proto/teleport/legacy/client/proto/joinservice.proto
|
|
- api/proto/teleport/legacy/types/device.proto
|
|
- api/proto/teleport/legacy/types/trusted_device_requirement.proto
|
|
- api/proto/teleport/legacy/types/resources.proto
|
|
- api/proto/teleport/legacy/types/webauthn/webauthn.proto
|
|
RPC_REQUEST_STANDARD_NAME:
|
|
- proto/teleport/lib/teleterm/v1/service.proto
|
|
UNARY_RPC:
|
|
- api/proto/teleport/auditlog/v1/auditlog.proto
|
|
- api/proto/teleport/devicetrust/v1/devicetrust_service.proto
|
|
- api/proto/teleport/legacy/client/proto/joinservice.proto
|
|
- api/proto/teleport/transport/v1/transport_service.proto
|
|
- api/proto/teleport/access_graph/v1/secrets_service.proto
|
|
- api/proto/teleport/workloadidentity/v1/revocation_service.proto
|
|
- proto/accessgraph/v1alpha/access_graph_service.proto
|
|
- proto/teleport/lib/teleterm/v1/service.proto
|
|
- api/proto/teleport/recordingmetadata/v1/recordingmetadata_service.proto
|
|
- api/proto/teleport/join/v1/joinservice.proto
|
|
- api/proto/teleport/sessionsearch/v1/session_search.proto
|
|
- proto/teleport/web/teleterm/ptyhost/v1/pty_host_service.proto
|
|
- proto/accessgraph/v1/session_search.proto
|
|
|
|
breaking:
|
|
use:
|
|
- ENUM_VALUE_NO_DELETE
|
|
- WIRE_JSON
|
|
# TODO(juliaogris): Remove the except once the buf breaking baseline no
|
|
# longer holds the app_resources reservations. They were never in a
|
|
# release, so deleting them breaks no released wire or JSON format.
|
|
except:
|
|
- RESERVED_MESSAGE_NO_DELETE
|
|
ignore:
|
|
# TODO(codingllama): Remove ignore once the PDP API is stable.
|
|
- api/proto/teleport/decision/v1alpha1
|
|
# TODO(eriktate): Remove ignore once the new scopes API is stable.
|
|
- api/proto/teleport/scopes
|
|
|
|
plugins:
|
|
- plugin:
|
|
- env
|
|
- GOWORK=off
|
|
- go
|
|
- -C
|
|
- ./build.assets/tooling
|
|
- run
|
|
- ./cmd/buf-plugin-linters
|