From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 74A871FF0AB for ; Wed, 23 Sep 2026 23:00:24 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 9FCDF21648; Wed, 23 Sep 2026 23:00:13 +0200 (CEST) From: Thomas Lamprecht To: pve-devel@lists.proxmox.com Subject: [PATCH manager 5/9] api: cluster options: return token-policy without Sys.Audit Date: Wed, 23 Sep 2026 22:59:54 +0200 Message-ID: <20260923210000.4031318-6-t.lamprecht@proxmox.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260923210000.4031318-1-t.lamprecht@proxmox.com> References: <20260923210000.4031318-1-t.lamprecht@proxmox.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1790197207502 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.700 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: C5G53HM3LFOP3HECKVWGYJKPOZPYI7FW X-Message-ID-Hash: C5G53HM3LFOP3HECKVWGYJKPOZPYI7FW X-MailFrom: t.lamprecht@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Any user can create API tokens for themselves, so the token dialogs need the new datacenter token policy to adapt up front, but reading the full datacenter config requires Sys.Audit. Return the policy like the console and tag-style options; it only contains restrictions that are enforced on the token create and update calls anyway. Signed-off-by: Thomas Lamprecht --- PVE/API2/Cluster.pm | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/PVE/API2/Cluster.pm b/PVE/API2/Cluster.pm index 4e5efbfd9..fe7cb7766 100644 --- a/PVE/API2/Cluster.pm +++ b/PVE/API2/Cluster.pm @@ -813,7 +813,7 @@ __PACKAGE__->register_method({ if ($rpcenv->check($authuser, '/', ['Sys.Audit'], 1)) { $res = $datacenter_config; } else { - for my $k (qw(console tag-style)) { + for my $k (qw(console tag-style token-policy)) { $res->{$k} = $datacenter_config->{$k} if exists $datacenter_config->{$k}; } } -- 2.47.3