Files
Julia Ogris 677b0d6e1c types: Declare all app_resources fields (#69500)
* types: Declare all app_resources fields in the proto

Declare the eight reserved AppResource fields (paths, methods, where,
allow_encoded, allow_code, allow_reason, deny_code_hint,
deny_reason_hint) and the AppResourcesExpressions role condition, and
regenerate the proto stubs, the role CRDs, the Terraform schema and
docs, and the derived equality functions. Declaring the fields before
the fine-grained matcher merges lets every client of this version name
them, so a client that round-trips a role written by a newer auth
preserves the fields instead of silently dropping them on write-back,
which would widen the rule.

Tighten IsAllowAllOnly to require every declared field besides
allow_all to be unset. Without this, a rule such as {allow_all: true,
methods: [GET]} written by a newer auth would pass the check once the
fields are named, and this version would treat a method-restricted
rule as unrestricted.

Add GetAppResourcesExpressions to the Role interface, and read it in
decideMinimalV9 so the app agent denies a request governed by a
predicate it cannot evaluate. A predicate restricts the rules it
accompanies, so a role that pairs allow_all with one is not
unrestricted, and a deny-side predicate blocks another role's
allow_all the same way a deny-side rule does. Auth already treats both
as restricting when it downgrades a role for a pre-v9 client, so
without this the agent and auth disagree about the same role.

Strip AppResourcesExpressions in the v9-to-v8 downgrade alongside
AppResources, and reject it at write, so a role can neither reach a
pre-v9 client with the restriction silently removed nor be stored
while this version cannot enforce it.

* docs: List the declared app_resources fields

Honour the docs review on the app-resources reference page. A run of
inline code-style field names inside a sentence is hard to scan, so the
eight rejected `app_resources` fields become a list, and
`app_resources_expressions` gets its own sentence rather than trailing
the same run.

* buf: Trim the reserved-deletion except comment

Drop the two sentences explaining why buf's ignore lists cannot scope the
except. The rule name and the removal condition are what a reader needs
here, and the scoping attempts are recorded on the pull request.

* types: Reword the app_resources_expressions and Methods docs

Honour the review on the proto field comments. Drop "desugared" from
`AppResourcesExpressions`, which needs the RFD to gloss, and state the
relation between the two forms directly instead. Open `Methods` with the
plural, matching `Paths` on the row above.

Regenerate the proto stubs, the role CRDs, the Terraform schema and docs.
2026-08-12 05:19:01 +00:00

114 lines
4.4 KiB
YAML

version: v2
modules:
- path: api/proto
- path: proto
deps:
# gogo/protobuf v1.3.2, keep in sync with build.assets/versions.mk.
- buf.build/gogo/protobuf:b03c65ea87cdc3521ede29f62fe3ce239267c1bc
- buf.build/googleapis/googleapis:beb34b4050abfcfff72ff5cc6a28f0afa4043ce0
lint:
use:
- STANDARD
- COMMENT_ENUM
- COMMENT_MESSAGE
- COMMENT_RPC
- COMMENT_SERVICE
- PACKAGE_NO_IMPORT_CYCLE
- PAGINATION_REQUIRED
- UNARY_RPC
except:
- FIELD_NOT_REQUIRED
- RPC_REQUEST_RESPONSE_UNIQUE
- RPC_RESPONSE_STANDARD_NAME
ignore:
- api/proto/teleport/legacy/client/proto/authservice.proto
- api/proto/teleport/legacy/client/proto/certs.proto
- api/proto/teleport/legacy/client/proto/event.proto
- api/proto/teleport/legacy/client/proto/proxyservice.proto
- api/proto/teleport/legacy/types/events/athena.proto
- api/proto/teleport/legacy/types/events/events.proto
- api/proto/teleport/legacy/types/types.proto
- api/proto/teleport/legacy/types/metadata.proto
- api/proto/teleport/legacy/types/mfa_device.proto
- api/proto/teleport/legacy/types/wrappers/wrappers.proto
- proto/teleport/lib/multiplexer/test/ping.proto
- proto/teleport/lib/web/terminal/envelope.proto
ignore_only:
COMMENT_MESSAGE:
- proto/prehog
- proto/teleport/lib/teleterm/v1/access_request.proto
- proto/teleport/lib/teleterm/v1/app.proto
- proto/teleport/lib/teleterm/v1/auth_settings.proto
- proto/teleport/lib/teleterm/v1/cluster.proto
- proto/teleport/lib/teleterm/v1/database.proto
- proto/teleport/lib/teleterm/v1/gateway.proto
- proto/teleport/lib/teleterm/v1/kube.proto
- proto/teleport/lib/teleterm/v1/label.proto
- proto/teleport/lib/teleterm/v1/server.proto
- proto/teleport/lib/teleterm/v1/service.proto
- proto/teleport/lib/teleterm/v1/usage_events.proto
COMMENT_RPC:
- proto/prehog
COMMENT_SERVICE:
- proto/prehog
FIELD_LOWER_SNAKE_CASE:
- api/proto/teleport/legacy/client/proto/inventory.proto
- api/proto/teleport/legacy/types/device.proto
- api/proto/teleport/legacy/types/resources.proto
PACKAGE_DIRECTORY_MATCH:
- api/proto/teleport/legacy/client/proto/joinservice.proto
- api/proto/teleport/legacy/types/device.proto
- api/proto/teleport/legacy/types/trusted_device_requirement.proto
- api/proto/teleport/legacy/types/resources.proto
- api/proto/teleport/legacy/types/webauthn/webauthn.proto
PACKAGE_VERSION_SUFFIX:
- api/proto/teleport/legacy/client/proto/joinservice.proto
- api/proto/teleport/legacy/types/device.proto
- api/proto/teleport/legacy/types/trusted_device_requirement.proto
- api/proto/teleport/legacy/types/resources.proto
- api/proto/teleport/legacy/types/webauthn/webauthn.proto
RPC_REQUEST_STANDARD_NAME:
- proto/teleport/lib/teleterm/v1/service.proto
UNARY_RPC:
- api/proto/teleport/auditlog/v1/auditlog.proto
- api/proto/teleport/devicetrust/v1/devicetrust_service.proto
- api/proto/teleport/legacy/client/proto/joinservice.proto
- api/proto/teleport/transport/v1/transport_service.proto
- api/proto/teleport/access_graph/v1/secrets_service.proto
- api/proto/teleport/workloadidentity/v1/revocation_service.proto
- proto/accessgraph/v1alpha/access_graph_service.proto
- proto/teleport/lib/teleterm/v1/service.proto
- api/proto/teleport/recordingmetadata/v1/recordingmetadata_service.proto
- api/proto/teleport/join/v1/joinservice.proto
- api/proto/teleport/sessionsearch/v1/session_search.proto
- proto/teleport/web/teleterm/ptyhost/v1/pty_host_service.proto
- proto/accessgraph/v1/session_search.proto
breaking:
use:
- ENUM_VALUE_NO_DELETE
- WIRE_JSON
# TODO(juliaogris): Remove the except once the buf breaking baseline no
# longer holds the app_resources reservations. They were never in a
# release, so deleting them breaks no released wire or JSON format.
except:
- RESERVED_MESSAGE_NO_DELETE
ignore:
# TODO(codingllama): Remove ignore once the PDP API is stable.
- api/proto/teleport/decision/v1alpha1
# TODO(eriktate): Remove ignore once the new scopes API is stable.
- api/proto/teleport/scopes
plugins:
- plugin:
- env
- GOWORK=off
- go
- -C
- ./build.assets/tooling
- run
- ./cmd/buf-plugin-linters