lahirujayathilake opened a new pull request, #484:
URL: https://github.com/apache/airavata-custos/pull/484
Adds an authorization model for Custos admins, fine-grained privileges plus
named role bundles that group privileges together.
## Architecture
Two layers,
- **Privileges** - declared keys (`amie:read`, `hpc:write`,
`privileges:grant`, `roles:manage`, etc.) granted directly to a user.
- **Roles** - named bundles of privileges. Granting a role to a user is
shorthand for granting every privilege the role carries. Update to a role's
bundle propagates to every holder.
A user's `effective set = direct grants UNION privileges` from every role
they hold. The auth middleware caches this set per user.
## Models
- `user_privileges` - direct grants (revoke is DELETE; history in
`audit_events`)
- `roles` - role definitions (`name`, `description`, `is_system`)
- `role_privileges` - many-to-many relationship
- `user_roles` - role assignments (revoke is DELETE; history in
`audit_events`)
`audit_events` (existing core table) is the single source of grant/revoke
history.
## Identification
Caller is identified via the `X-Custos-User-Id` header. A JWT-verification
middleware (the planned implementation) will set this from the verified `sub`
claim after validating against the IdP's JWKS endpoint.
## Bootstrap
If `CUSTOS_BOOTSTRAP_ADMIN_EMAIL` is set, the server idempotently creates a
`super_admin` role carrying `privileges:grant` + `roles:manage` and grants it
to the named user on first start.
## API contract
- `GET /user/privileges` - caller's effective set
- `GET /privileges/catalog` - declared privilege keys
- `GET|POST|DELETE /users/{id}/privileges...` - direct grant management
- `GET|POST|PUT|DELETE /roles...` - role CRUD + bundle management
- `GET|POST|DELETE /users/{id}/roles...` - role assignments
Privilege management endpoints gated on `privileges:grant`; role management
gated on `roles:manage`.
## Dev tooling
- `dev-ops/compose/seeds/dev_users_and_roles.sql` - seeds 4 dev users
(`dev-admin`, `dev-operator`, `dev-auditor`, `dev-researcher`) plus `operator`
and `auditor` roles
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]