From 83899c00cc4b1490be0b3799ca90de1ad7defc69 Mon Sep 17 00:00:00 2001 From: Priec Date: Sat, 8 Aug 2026 23:55:44 +0200 Subject: [PATCH] auth roles are in db now, admin and superadmin can add more --- common/proto/auth.proto | 22 +++ common/src/proto/descriptor.bin | Bin 150790 -> 151786 bytes common/src/proto/komp_ac.auth.rs | 240 +++++++++++++++++++++++++++++++ server | 2 +- 4 files changed, 263 insertions(+), 1 deletion(-) diff --git a/common/proto/auth.proto b/common/proto/auth.proto index a8080867..1d8bc78d 100644 --- a/common/proto/auth.proto +++ b/common/proto/auth.proto @@ -9,6 +9,9 @@ service AuthService { rpc Login(LoginRequest) returns (LoginResponse); rpc GetAuthorization(GetAuthorizationRequest) returns (AuthorizationSnapshot); rpc SetTimezone(SetTimezoneRequest) returns (UserPreferences); + rpc ListRoles(ListRolesRequest) returns (ListRolesResponse); + rpc AddRole(AddRoleRequest) returns (Role); + rpc RemoveRole(RemoveRoleRequest) returns (Role); } message RegisterRequest { @@ -64,3 +67,22 @@ message AuthorizationSnapshot { string role = 1; repeated Permission permissions = 2; } + +message Role { + string name = 1; + bool built_in = 2; +} + +message ListRolesRequest {} + +message ListRolesResponse { + repeated Role roles = 1; +} + +message AddRoleRequest { + string name = 1; +} + +message RemoveRoleRequest { + string name = 1; +} diff --git a/common/src/proto/descriptor.bin b/common/src/proto/descriptor.bin index 0077d896fbd8330e9a0a9a2e06d863dc4111f26e..0bd23bba29dca10e78078d23cc229295ba1dc9b0 100644 GIT binary patch delta 2775 zcmah~OK%%h7@fIuZO>fWseS#7N-%M!*V&^mWob#RUyAOZyjraIl?}y(W ziC^X(JbZLY4*XL}cK7f0v{rKO*1cZYp0ev+*ZkI_%KhNz&fUYCclOEx-`#G);PZRF zR+&q8`iCU#cYB{6_4fA9XyTOW3A9UXq$ zxj_cqfZ@-ok=5I`&6mLO-$MB{mF@QK?SIz$AL7E-@`3aFhCR@ilo#dF6R!q{7PyJZ zD)lnGey!Ncl`zd~<06X-UzSx|OWV3O+N=yasBY0(=A*Pzo`%{nB^Mdbu!xkx4; z%SGh`WVxsuKwiwSqXStUvKv8Y2fDmB5iSyS+UIiEn}X21B%v!rv#fVNjRE*NaKrbTQbwkIVl!oO$-`^-jblRAb7tS>fdTF#`w!+r3 zVoe5HL6fSuc{K|go3>(1Wcc}dd>5Ddpgjw#;=u~Z$#p3XL_ z5uKc?9M={$=vBmR8#?x2e7N&;zBwMzY4+p1WwxN%k7LUkh7K?>{O)OMZ6c!6$R~Jq zws44n+0j80T25QDL3d<2jqYl&5!9VO9DUXp_-unuAoyNzh=5?@7lU&tNISy^1puR% ziDcB<4EKgL$Y#(RRd=+UvrY!pDdU`5P-RqisCrFQ{N&Vy;jho~%^I6w0koP|FmnZh zS*<*(CXEP7_2FO7rknMMPPOYC*)g^2i2SypW3G+ih399R4Uu3!YNO!>2hcHdZ4`>C zW#}l?9De`2J!nSml)34d>x|4a*JduSDu#}u+!ESPPhIWz4r=|W1H4L#%h1VgMJ{x* zTf94tIoU1j4qbPLZrlkTD}X_R;JyPwcY@~%gz6_S*Fc9O-WE+R7dNOBBFNh1;~|2q zU2m`~p`A`tE`f5LC}je&4psXIPmd!K&~>76u6E|d7+bo~%||*Hx_Q1?j&LEH=bI(9 zT(I5@cAsXj;8x6imbCkexX()i{Dj#en*o8g$SniGY>|&rOv}^OTY(u3<}|;UF)~}? zo&aFC#CAX+F0maD?3Q5X;bdZBXDokU9$`RlxLU4S?*=hw zz^m@KiQ!U=HGV+>;J3zpKp?L1IRk>-8lN+lVyuff69WKecU|DH4zSgL7{+=sxN<;5 zEl!72xUA0}H=#T&H>~qPC=aX+H)TS36l#-00U*>ShXMj|lS2W)Zj(cKg8JX$;Q&Fm zCE}(q5OiCKU^YO|ZDBUFbxJ!ItueE63Z#o}*`!NqdD(g|NSDO-%kHR2m!x#tqGEgj z(EB#^j@FX{VWIc!WKaf+&~0aeNdTefHXa{($x>Qgv33IY6j)c>qH#}=dzX6$Ko4E+ z9SFoO_YMTRE~+&c8nmmNHcfuJ><0k9UG@V4ahLso;J2H}eqMd?Q}u=Y Gc;|04TPGR- delta 1710 zcmX|BO>Y}j6rJ~Bd*+$M_M35HPuj$B9LF9fO4_E164NB@qKmRZd{kAp&8lBg%iaS|w6INtMVo$Gt9{cVppvUO$fumQgO7cg4J-m~6dKL5}Ds!!Zo^(^hFHu%6 z23Lxwpr{tZ#0+2~=qWn6I3H#mw!vQ@bfUUz5(qY(`G)B`I*z*e$LE8r>*?gz~=J4-#C5>NT1grvk%Jk;3H0haQA&L?-4Je`tW;>3hh#6V(nCu#L^ zuv*-SOqX$|4cJJ!(@K8w_xPLtW6_)y1A~8|U0EnbP?Dg>GXa3?dt4HT&iFz=ko9mO zDyghq3$}`q)Yw|sHXW2yRB|BGe!X|^{-?b!ox6|gV$pQ*# zBTh`}C>Y0)wEel>XD?4)Y`pBfc>d(1?2U$V#P?P-C2GV`1Hom4sA*#rEzOwY0&u9< zSRly8h-*gc3<%wrcSuQ0X(lsntm@EWiJ;3m>m`CL8;!YK&8mqnS3|jp@3IEjgkML= z8f25A+UF=9TD2*c*fNA})9XU$HhDQfgl?0ULtDKaTq|CcGT07Nx00G(bq6cCH^Wbu z?XVdTXgk~l5X^RXL@HL_2yPZ;l*|qO=vByUm+u4syIr;e0&$n^fMB-^y9g79#P)(d zKBxGG(t7WOD{c~NR__NN7G)@reGCY_RE^3Ua2WuUIp8utARcfTAe1@ahpN$#O=aSe z1AuJmWkSpVqegiM-PFdejnL}D;C9gl1$-D@b!~*y#u0x60pNGUen21|@tgs{?uh3s sq&AM_&{YD!>>f)D>j;wth%k=p#VP?2bz!xn!sU3d{^jM5m*VV`_Z04il>h($ diff --git a/common/src/proto/komp_ac.auth.rs b/common/src/proto/komp_ac.auth.rs index 856e77a3..2fa7cf86 100644 --- a/common/src/proto/komp_ac.auth.rs +++ b/common/src/proto/komp_ac.auth.rs @@ -94,6 +94,30 @@ pub struct AuthorizationSnapshot { #[prost(message, repeated, tag = "2")] pub permissions: ::prost::alloc::vec::Vec, } +#[derive(Clone, PartialEq, Eq, Hash, ::prost::Message)] +pub struct Role { + #[prost(string, tag = "1")] + pub name: ::prost::alloc::string::String, + #[prost(bool, tag = "2")] + pub built_in: bool, +} +#[derive(Clone, Copy, PartialEq, Eq, Hash, ::prost::Message)] +pub struct ListRolesRequest {} +#[derive(Clone, PartialEq, ::prost::Message)] +pub struct ListRolesResponse { + #[prost(message, repeated, tag = "1")] + pub roles: ::prost::alloc::vec::Vec, +} +#[derive(Clone, PartialEq, Eq, Hash, ::prost::Message)] +pub struct AddRoleRequest { + #[prost(string, tag = "1")] + pub name: ::prost::alloc::string::String, +} +#[derive(Clone, PartialEq, Eq, Hash, ::prost::Message)] +pub struct RemoveRoleRequest { + #[prost(string, tag = "1")] + pub name: ::prost::alloc::string::String, +} /// Generated client implementations. pub mod auth_service_client { #![allow( @@ -275,6 +299,72 @@ pub mod auth_service_client { .insert(GrpcMethod::new("komp_ac.auth.AuthService", "SetTimezone")); self.inner.unary(req, path, codec).await } + pub async fn list_roles( + &mut self, + request: impl tonic::IntoRequest, + ) -> std::result::Result< + tonic::Response, + tonic::Status, + > { + self.inner + .ready() + .await + .map_err(|e| { + tonic::Status::unknown( + format!("Service was not ready: {}", e.into()), + ) + })?; + let codec = tonic_prost::ProstCodec::default(); + let path = http::uri::PathAndQuery::from_static( + "/komp_ac.auth.AuthService/ListRoles", + ); + let mut req = request.into_request(); + req.extensions_mut() + .insert(GrpcMethod::new("komp_ac.auth.AuthService", "ListRoles")); + self.inner.unary(req, path, codec).await + } + pub async fn add_role( + &mut self, + request: impl tonic::IntoRequest, + ) -> std::result::Result, tonic::Status> { + self.inner + .ready() + .await + .map_err(|e| { + tonic::Status::unknown( + format!("Service was not ready: {}", e.into()), + ) + })?; + let codec = tonic_prost::ProstCodec::default(); + let path = http::uri::PathAndQuery::from_static( + "/komp_ac.auth.AuthService/AddRole", + ); + let mut req = request.into_request(); + req.extensions_mut() + .insert(GrpcMethod::new("komp_ac.auth.AuthService", "AddRole")); + self.inner.unary(req, path, codec).await + } + pub async fn remove_role( + &mut self, + request: impl tonic::IntoRequest, + ) -> std::result::Result, tonic::Status> { + self.inner + .ready() + .await + .map_err(|e| { + tonic::Status::unknown( + format!("Service was not ready: {}", e.into()), + ) + })?; + let codec = tonic_prost::ProstCodec::default(); + let path = http::uri::PathAndQuery::from_static( + "/komp_ac.auth.AuthService/RemoveRole", + ); + let mut req = request.into_request(); + req.extensions_mut() + .insert(GrpcMethod::new("komp_ac.auth.AuthService", "RemoveRole")); + self.inner.unary(req, path, codec).await + } } } /// Generated server implementations. @@ -309,6 +399,21 @@ pub mod auth_service_server { &self, request: tonic::Request, ) -> std::result::Result, tonic::Status>; + async fn list_roles( + &self, + request: tonic::Request, + ) -> std::result::Result< + tonic::Response, + tonic::Status, + >; + async fn add_role( + &self, + request: tonic::Request, + ) -> std::result::Result, tonic::Status>; + async fn remove_role( + &self, + request: tonic::Request, + ) -> std::result::Result, tonic::Status>; } #[derive(Debug)] pub struct AuthServiceServer { @@ -564,6 +669,141 @@ pub mod auth_service_server { }; Box::pin(fut) } + "/komp_ac.auth.AuthService/ListRoles" => { + #[allow(non_camel_case_types)] + struct ListRolesSvc(pub Arc); + impl< + T: AuthService, + > tonic::server::UnaryService + for ListRolesSvc { + type Response = super::ListRolesResponse; + type Future = BoxFuture< + tonic::Response, + tonic::Status, + >; + fn call( + &mut self, + request: tonic::Request, + ) -> Self::Future { + let inner = Arc::clone(&self.0); + let fut = async move { + ::list_roles(&inner, request).await + }; + Box::pin(fut) + } + } + let accept_compression_encodings = self.accept_compression_encodings; + let send_compression_encodings = self.send_compression_encodings; + let max_decoding_message_size = self.max_decoding_message_size; + let max_encoding_message_size = self.max_encoding_message_size; + let inner = self.inner.clone(); + let fut = async move { + let method = ListRolesSvc(inner); + let codec = tonic_prost::ProstCodec::default(); + let mut grpc = tonic::server::Grpc::new(codec) + .apply_compression_config( + accept_compression_encodings, + send_compression_encodings, + ) + .apply_max_message_size_config( + max_decoding_message_size, + max_encoding_message_size, + ); + let res = grpc.unary(method, req).await; + Ok(res) + }; + Box::pin(fut) + } + "/komp_ac.auth.AuthService/AddRole" => { + #[allow(non_camel_case_types)] + struct AddRoleSvc(pub Arc); + impl< + T: AuthService, + > tonic::server::UnaryService + for AddRoleSvc { + type Response = super::Role; + type Future = BoxFuture< + tonic::Response, + tonic::Status, + >; + fn call( + &mut self, + request: tonic::Request, + ) -> Self::Future { + let inner = Arc::clone(&self.0); + let fut = async move { + ::add_role(&inner, request).await + }; + Box::pin(fut) + } + } + let accept_compression_encodings = self.accept_compression_encodings; + let send_compression_encodings = self.send_compression_encodings; + let max_decoding_message_size = self.max_decoding_message_size; + let max_encoding_message_size = self.max_encoding_message_size; + let inner = self.inner.clone(); + let fut = async move { + let method = AddRoleSvc(inner); + let codec = tonic_prost::ProstCodec::default(); + let mut grpc = tonic::server::Grpc::new(codec) + .apply_compression_config( + accept_compression_encodings, + send_compression_encodings, + ) + .apply_max_message_size_config( + max_decoding_message_size, + max_encoding_message_size, + ); + let res = grpc.unary(method, req).await; + Ok(res) + }; + Box::pin(fut) + } + "/komp_ac.auth.AuthService/RemoveRole" => { + #[allow(non_camel_case_types)] + struct RemoveRoleSvc(pub Arc); + impl< + T: AuthService, + > tonic::server::UnaryService + for RemoveRoleSvc { + type Response = super::Role; + type Future = BoxFuture< + tonic::Response, + tonic::Status, + >; + fn call( + &mut self, + request: tonic::Request, + ) -> Self::Future { + let inner = Arc::clone(&self.0); + let fut = async move { + ::remove_role(&inner, request).await + }; + Box::pin(fut) + } + } + let accept_compression_encodings = self.accept_compression_encodings; + let send_compression_encodings = self.send_compression_encodings; + let max_decoding_message_size = self.max_decoding_message_size; + let max_encoding_message_size = self.max_encoding_message_size; + let inner = self.inner.clone(); + let fut = async move { + let method = RemoveRoleSvc(inner); + let codec = tonic_prost::ProstCodec::default(); + let mut grpc = tonic::server::Grpc::new(codec) + .apply_compression_config( + accept_compression_encodings, + send_compression_encodings, + ) + .apply_max_message_size_config( + max_decoding_message_size, + max_encoding_message_size, + ); + let res = grpc.unary(method, req).await; + Ok(res) + }; + Box::pin(fut) + } _ => { Box::pin(async move { let mut response = http::Response::new( diff --git a/server b/server index 65e67fe7..5fa954d3 160000 --- a/server +++ b/server @@ -1 +1 @@ -Subproject commit 65e67fe785b76a647759ca7d7e3517d251dab235 +Subproject commit 5fa954d3f45230069c2ca3fa169f014a689cac84