From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: <pdm-devel-bounces@lists.proxmox.com> Received: from firstgate.proxmox.com (firstgate.proxmox.com [IPv6:2a01:7e0:0:424::9]) by lore.proxmox.com (Postfix) with ESMTPS id A04DE1FF16B for <inbox@lore.proxmox.com>; Thu, 3 Apr 2025 16:18:29 +0200 (CEST) Received: from firstgate.proxmox.com (localhost [127.0.0.1]) by firstgate.proxmox.com (Proxmox) with ESMTP id 542CD3D3A; Thu, 3 Apr 2025 16:18:16 +0200 (CEST) From: Shannon Sterz <s.sterz@proxmox.com> To: pdm-devel@lists.proxmox.com Date: Thu, 3 Apr 2025 16:18:01 +0200 Message-Id: <20250403141806.402974-5-s.sterz@proxmox.com> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20250403141806.402974-1-s.sterz@proxmox.com> References: <20250403141806.402974-1-s.sterz@proxmox.com> MIME-Version: 1.0 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.018 Adjusted score from AWL reputation of From: address BAYES_00 -1.9 Bayes spam probability is 0 to 1% DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Subject: [pdm-devel] [PATCH proxmox 4/4] access-control: add generic roles endpoint to `api` feature X-BeenThere: pdm-devel@lists.proxmox.com X-Mailman-Version: 2.1.29 Precedence: list List-Id: Proxmox Datacenter Manager development discussion <pdm-devel.lists.proxmox.com> List-Unsubscribe: <https://lists.proxmox.com/cgi-bin/mailman/options/pdm-devel>, <mailto:pdm-devel-request@lists.proxmox.com?subject=unsubscribe> List-Archive: <http://lists.proxmox.com/pipermail/pdm-devel/> List-Post: <mailto:pdm-devel@lists.proxmox.com> List-Help: <mailto:pdm-devel-request@lists.proxmox.com?subject=help> List-Subscribe: <https://lists.proxmox.com/cgi-bin/mailman/listinfo/pdm-devel>, <mailto:pdm-devel-request@lists.proxmox.com?subject=subscribe> Reply-To: Proxmox Datacenter Manager development discussion <pdm-devel@lists.proxmox.com> Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: pdm-devel-bounces@lists.proxmox.com Sender: "pdm-devel" <pdm-devel-bounces@lists.proxmox.com> since this is always the same between most products and we already have access to all the relevant information Signed-off-by: Shannon Sterz <s.sterz@proxmox.com> --- proxmox-access-control/src/api.rs | 45 ++++++++++++++++++++++++++++- proxmox-access-control/src/types.rs | 28 ++++++++++++++++++ 2 files changed, 72 insertions(+), 1 deletion(-) diff --git a/proxmox-access-control/src/api.rs b/proxmox-access-control/src/api.rs index 4a6aabf5..3c62fbcf 100644 --- a/proxmox-access-control/src/api.rs +++ b/proxmox-access-control/src/api.rs @@ -7,7 +7,9 @@ use proxmox_schema::api; use crate::acl::AclTreeNode; use crate::init::access_conf; -use crate::types::{AclListItem, AclUgidType, ACL_PATH_SCHEMA, ACL_PROPAGATE_SCHEMA}; +use crate::types::{ + AclListItem, AclUgidType, RoleInfo, ACL_PATH_SCHEMA, ACL_PROPAGATE_SCHEMA, +}; use crate::CachedUserInfo; #[api( @@ -276,3 +278,44 @@ fn extract_acl_node_data( pub const ACL_ROUTER: Router = Router::new() .get(&API_METHOD_READ_ACL) .put(&API_METHOD_UPDATE_ACL); + +#[api( + returns: { + description: "List of roles.", + type: Array, + items: { + type: RoleInfo, + } + }, + access: { + permission: &Permission::Anybody, + } +)] +/// A list of available roles +fn list_roles() -> Result<Vec<RoleInfo>, Error> { + let list = access_conf() + .roles() + .iter() + .map(|(role, (privs, comment))| { + let priv_list = access_conf() + .privileges() + .iter() + .filter_map(|(name, privilege)| { + if privs & privilege > 0 { + Some(name.to_string()) + } else { + None + } + }); + + RoleInfo { + roleid: role.to_string(), + privs: priv_list.collect(), + comment: Some(comment.to_string()), + } + }); + + Ok(list.collect()) +} + +pub const ROLE_ROUTER: Router = Router::new().get(&API_METHOD_LIST_ROLES); diff --git a/proxmox-access-control/src/types.rs b/proxmox-access-control/src/types.rs index 01d078de..ea64d333 100644 --- a/proxmox-access-control/src/types.rs +++ b/proxmox-access-control/src/types.rs @@ -247,3 +247,31 @@ pub struct AclListItem { /// A role represented as a string. pub roleid: String, } + +#[api( + properties: { + privs: { + type: Array, + description: "List of Privileges", + items: { + type: String, + description: "A Privilege", + }, + }, + comment: { + schema: COMMENT_SCHEMA, + optional: true, + } + } +)] +/// A struct that the describes a role and shows the associated privileges. +#[derive(Serialize, Deserialize, PartialEq, Clone)] +pub struct RoleInfo { + /// The id of the role + pub roleid: String, + /// The privileges the role holds + pub privs: Vec<String>, + /// A comment describing the role + #[serde(skip_serializing_if = "Option::is_none")] + pub comment: Option<String>, +} -- 2.39.5 _______________________________________________ pdm-devel mailing list pdm-devel@lists.proxmox.com https://lists.proxmox.com/cgi-bin/mailman/listinfo/pdm-devel