Files
proxui/backend/internal/rbac/policy.go
T
2026-06-10 20:01:22 +02:00

84 lines
1.6 KiB
Go

package rbac
type Role string
const (
RoleOwner Role = "owner"
RoleAdmin Role = "admin"
RoleMember Role = "member"
RoleViewer Role = "viewer"
)
type Action string
const (
ActionVMRead Action = "vm.read"
ActionVMPower Action = "vm.power"
ActionVMCreate Action = "vm.create"
ActionVMDelete Action = "vm.delete"
ActionVMConsole Action = "vm.console"
ActionProjectRead Action = "project.read"
ActionProjectManage Action = "project.manage"
ActionSSHKeyRead Action = "ssh_key.read"
ActionSSHKeyManage Action = "ssh_key.manage"
ActionAuditRead Action = "audit.read"
ActionClusterManage Action = "cluster.manage"
)
func Can(role Role, action Action) bool {
allowed, ok := permissions[role]
if !ok {
return false
}
return allowed[action]
}
var permissions = map[Role]map[Action]bool{
RoleOwner: allow(
ActionVMRead,
ActionVMPower,
ActionVMCreate,
ActionVMDelete,
ActionVMConsole,
ActionProjectRead,
ActionProjectManage,
ActionSSHKeyRead,
ActionSSHKeyManage,
ActionAuditRead,
),
RoleAdmin: allow(
ActionVMRead,
ActionVMPower,
ActionVMCreate,
ActionVMDelete,
ActionVMConsole,
ActionProjectRead,
ActionProjectManage,
ActionSSHKeyRead,
ActionSSHKeyManage,
ActionAuditRead,
),
RoleMember: allow(
ActionVMRead,
ActionVMPower,
ActionVMCreate,
ActionVMConsole,
ActionProjectRead,
ActionSSHKeyRead,
),
RoleViewer: allow(
ActionVMRead,
ActionVMConsole,
ActionProjectRead,
ActionSSHKeyRead,
),
}
func allow(actions ...Action) map[Action]bool {
allowed := make(map[Action]bool, len(actions))
for _, action := range actions {
allowed[action] = true
}
return allowed
}