diff --git a/db/seed/Member.csv b/db/seed/Member.csv index 04791596..2930febc 100644 --- a/db/seed/Member.csv +++ b/db/seed/Member.csv @@ -6,3 +6,6 @@ wicar@dfds.com;Willi hehe;wicar@dfds.com;"{""signedUpForDemos"":true}";User emwee@dfds.com;Emil Weee;emwee@dfds.com;"{""signedUpForDemos"":false}";User ewica@dfds.com;Emil Carlsen;ewica@dfds.com;"{""signedUpForDemos"":true}";User emcla@dfds.com;Emil Clausen;emcla@dfds.com;"{""signedUpForDemos"":true}";User +owner@bar.com;Owner Bar;owner@bar.com;"{""signedUpForDemos"":false}";User +contributor@bar.com;Contributor Bar;contributor@bar.com;"{""signedUpForDemos"":false}";User +reader@bar.com;Reader Bar;reader@bar.com;"{""signedUpForDemos"":false}";User diff --git a/db/seed/RbacGroup.csv b/db/seed/RbacGroup.csv index 1756b1c0..ae3d2cff 100644 --- a/db/seed/RbacGroup.csv +++ b/db/seed/RbacGroup.csv @@ -1,4 +1,7 @@ Id;CreatedAt;UpdatedAt;Name;Description -BA0AA734-206D-454E-AC95-14855B6901E4;2026-07-23T09:15:35.803168;2026-07-23T09:15:35.803174;CloudEngineers;Group: CloudEngineers -899F8F9E-3F7E-4EF3-A2CD-2E1DDA78E40A;2026-07-23T09:15:35.803179;2026-07-23T09:15:35.803180;BatchCapabilityCreators;Group: BatchCapabilityCreators -7D3D7498-9075-4D1B-B6C1-AF6E95788C3B;2026-07-23T09:15:35.803184;2026-07-23T09:15:35.803185;ServiceCatalogueReaders;Group: ServiceCatalogueReaders +BA0AA734-206D-454E-AC95-14855B6901E4;2026-07-28T08:00:09.521076+00:00;2026-07-28T08:00:09.521078+00:00;CloudEngineers;Group: CloudEngineers +890CC44E-2D09-5ACE-A1C3-F62560AE45F8;2026-07-28T08:00:09.521081+00:00;2026-07-28T08:00:09.521082+00:00;CapabilityOwnersBar;Group: CapabilityOwnersBar +12F13079-AD3A-5F64-9AD6-1A94D5F8C7C5;2026-07-28T08:00:09.521085+00:00;2026-07-28T08:00:09.521097+00:00;CapabilityContributorsBar;Group: CapabilityContributorsBar +7C72E0F1-6FBA-5165-94EA-7EE4A75C35A2;2026-07-28T08:00:09.521100+00:00;2026-07-28T08:00:09.521101+00:00;CapabilityReadersBar;Group: CapabilityReadersBar +899F8F9E-3F7E-4EF3-A2CD-2E1DDA78E40A;2026-07-28T08:00:09.521103+00:00;2026-07-28T08:00:09.521104+00:00;BatchCapabilityCreators;Group: BatchCapabilityCreators +7D3D7498-9075-4D1B-B6C1-AF6E95788C3B;2026-07-28T08:00:09.521106+00:00;2026-07-28T08:00:09.521107+00:00;ServiceCatalogueReaders;Group: ServiceCatalogueReaders diff --git a/db/seed/RbacGroupMember.csv b/db/seed/RbacGroupMember.csv index 6c09ecab..62c7a17d 100644 --- a/db/seed/RbacGroupMember.csv +++ b/db/seed/RbacGroupMember.csv @@ -1,3 +1,6 @@ Id;GroupId;UserId;CreatedAt -7BADF960-B926-4BDC-A4BF-8B0CB444E292;BA0AA734-206D-454E-AC95-14855B6901E4;andfris@dfds.com;2026-07-23T09:15:35.803265 -DEF609DD-40B7-4DEC-A430-0208C49555DB;BA0AA734-206D-454E-AC95-14855B6901E4;emcla@dfds.com;2026-07-23T09:15:35.803272 +C4048DBD-0C0F-4E1D-9EDD-FBDECB5782D8;BA0AA734-206D-454E-AC95-14855B6901E4;andfris@dfds.com;2026-07-28T08:00:09.521137+00:00 +18DEDFB3-BAE7-4E3F-8B4C-0A6A54978E98;BA0AA734-206D-454E-AC95-14855B6901E4;emcla@dfds.com;2026-07-28T08:00:09.521143+00:00 +80594E92-85BC-42EC-9DC9-92D57896DCF3;890CC44E-2D09-5ACE-A1C3-F62560AE45F8;owner@bar.com;2026-07-28T08:00:09.521148+00:00 +BDC31F2E-CAE0-4C29-B0F8-CC6FF32A92B4;12F13079-AD3A-5F64-9AD6-1A94D5F8C7C5;contributor@bar.com;2026-07-28T08:00:09.521152+00:00 +B267C1CE-201C-47E5-AC1E-39EFB7977E79;7C72E0F1-6FBA-5165-94EA-7EE4A75C35A2;reader@bar.com;2026-07-28T08:00:09.521156+00:00 diff --git a/db/seed/RbacPermissionGrants.csv b/db/seed/RbacPermissionGrants.csv index 336416a2..29351dec 100644 --- a/db/seed/RbacPermissionGrants.csv +++ b/db/seed/RbacPermissionGrants.csv @@ -1,143 +1,147 @@ Id;CreatedAt;AssignedEntityType;AssignedEntityId;Namespace;Permission;Type;Resource -6636B444-0962-409F-BB43-A8C56B20D5C3;2026-07-23T09:15:35.802046;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;topics;create;Global; -C0C94271-CCE6-427D-A2F7-94B4035AEF10;2026-07-23T09:15:35.802057;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;topics;read-public;Global; -E1E30581-2CC9-4E24-82E9-1800CAD6DC55;2026-07-23T09:15:35.802063;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;topics;read-private;Global; -FBA28174-5714-41FB-AF1E-563C438582CB;2026-07-23T09:15:35.802068;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;topics;update;Global; -03ADA3FC-F4B8-46F8-B28E-884410A0BA14;2026-07-23T09:15:35.802073;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;topics;delete;Global; -CA991F8A-894C-4725-B3D5-BE0B7A3005B7;2026-07-23T09:15:35.802077;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability-management;receive-alerts;Global; -6BDF3560-E5FD-476C-92BE-E702021124FC;2026-07-23T09:15:35.802082;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability-management;receive-cost;Global; -C5E477C0-8FD2-4DA0-908B-113AEFD0CC07;2026-07-23T09:15:35.802086;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability-management;request-deletion;Global; -D4E3F9F6-88E0-4711-A298-018151678B22;2026-07-23T09:15:35.802090;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability-management;manage-permissions;Global; -D0941F2B-2D39-472F-9897-D56E5FB0ABCD;2026-07-23T09:15:35.802094;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability-management;read-self-assess;Global; -2B855B00-9C78-4F9B-8586-33E621D4A06B;2026-07-23T09:15:35.802099;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability-management;create-self-assess;Global; -4F9FBCA3-D38D-42E8-B21A-70561958BB9D;2026-07-23T09:15:35.802103;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability-membership-management;create;Global; -A8DA872A-6A59-4A4A-91C3-CCAC99E8D11D;2026-07-23T09:15:35.802107;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability-membership-management;delete;Global; -E3A0135F-8668-4EA7-BA5D-4514DB422BAF;2026-07-23T09:15:35.802111;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability-membership-management;read;Global; -0EFD309D-0979-4B19-AE71-298C23FE0AE1;2026-07-23T09:15:35.802115;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability-membership-management;read-requests;Global; -977EECE6-8221-40FA-AC2B-2098C1F026C8;2026-07-23T09:15:35.802119;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability-membership-management;manage-requests;Global; -AB7EE446-3F53-4072-8FD7-D7C0E453FE37;2026-07-23T09:15:35.802126;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;tags-and-metadata;create;Global; -27B0A834-8C28-481A-9A7F-FCFD05F062BB;2026-07-23T09:15:35.802129;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;tags-and-metadata;read;Global; -D67C2375-01B3-4538-B687-AF9C9B713CD1;2026-07-23T09:15:35.802133;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;tags-and-metadata;update;Global; -75F6DD9D-03CB-42D7-B29D-480927A61B34;2026-07-23T09:15:35.802137;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;tags-and-metadata;delete;Global; -D4FFA361-0B62-419C-98AF-843A05ADE320;2026-07-23T09:15:35.802142;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;aws;create;Global; -07DD388C-4FA2-4CD9-BB78-5A33E77A77C4;2026-07-23T09:15:35.802146;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;aws;read;Global; -921A5405-E4DD-4012-B86D-33155A8A26FD;2026-07-23T09:15:35.802150;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;aws;manage-provider;Global; -87C539E6-6BD1-422C-A606-D7B40A8680BA;2026-07-23T09:15:35.802154;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;aws;read-provider;Global; -5E80E7A7-E4E2-4A22-8359-DFDBEC1838CD;2026-07-23T09:15:35.802158;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;finout;read-dashboards;Global; -6D85C79E-BAF1-4FA4-9BF7-97C3E7637227;2026-07-23T09:15:35.802162;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;finout;manage-dashboards;Global; -DEC2C696-4409-4ABB-9D7D-892FF45DD15E;2026-07-23T09:15:35.802166;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;finout;manage-alerts;Global; -5DDDB2B3-DB61-4634-B326-C9EDA660163F;2026-07-23T09:15:35.802170;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;finout;read-alerts;Global; -7215EF9D-6F79-40F3-9B5C-0F588B93527D;2026-07-23T09:15:35.802174;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;azure;create;Global; -FAD7F3CE-1E5A-4590-B8ED-25302A090669;2026-07-23T09:15:35.802178;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;azure;read;Global; -B624A296-195C-496F-A978-F73636496C36;2026-07-23T09:15:35.802181;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;azure;read-provider;Global; -AFA290E9-810B-47E0-A4E4-15E41DEBF3EB;2026-07-23T09:15:35.802185;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;azure;manage-provider;Global; -868B7621-7599-4708-952D-16C48E5014CD;2026-07-23T09:15:35.802189;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;rbac;create;Global; -A4A7D300-90AA-4814-B45C-52319C3D0F09;2026-07-23T09:15:35.802193;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;rbac;read;Global; -EBCF6A80-E00F-48A9-8AD9-7CE0DA48B595;2026-07-23T09:15:35.802197;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;rbac;update;Global; -0CF131F2-DE58-443A-9EDF-B9F39C192080;2026-07-23T09:15:35.802201;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;rbac;delete;Global; -EAF901BE-4122-4C37-94C8-8434F3F8C7E9;2026-07-23T09:15:35.802206;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;topics;create;Global; -52E51E0B-1F55-444D-9734-1E8A510A52B1;2026-07-23T09:15:35.802210;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;topics;read-public;Global; -40AA2A38-57D4-4189-B7E5-F4F7BA70BC80;2026-07-23T09:15:35.802215;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;topics;read-private;Global; -1997B0AC-68A0-426B-8711-771B72370EE0;2026-07-23T09:15:35.802219;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;topics;update;Global; -A75E4E4E-D1AC-4286-A7A1-8487F5C0D4E2;2026-07-23T09:15:35.802223;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;topics;delete;Global; -3D4EF3DA-02CD-45F6-9740-F3B2A145A6C6;2026-07-23T09:15:35.802227;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;capability-management;receive-alerts;Global; -5AF25ADF-E8FD-4151-B17C-D5F83D139F68;2026-07-23T09:15:35.802232;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;capability-membership-management;create;Global; -D188347A-CFCF-458B-9AC4-A66F487808B6;2026-07-23T09:15:35.802236;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;capability-membership-management;read;Global; -A8E6793B-54C2-4B3F-B9DC-81FCD65F1159;2026-07-23T09:15:35.802240;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;capability-membership-management;read-requests;Global; -162509FD-7C76-4968-8747-9ADB02202CE7;2026-07-23T09:15:35.802244;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;capability-membership-management;manage-requests;Global; -64E68687-0C94-4F99-A36F-312A2E04543E;2026-07-23T09:15:35.802250;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;tags-and-metadata;create;Global; -A6B67719-B660-412A-8D5E-0F9787E64A33;2026-07-23T09:15:35.802254;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;tags-and-metadata;read;Global; -13CBE1F8-8768-4F54-A93C-A0431ACDC2D1;2026-07-23T09:15:35.802258;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;tags-and-metadata;update;Global; -BEE2F603-834F-49A2-A9EF-9BD59485DBE0;2026-07-23T09:15:35.802262;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;tags-and-metadata;delete;Global; -2AAF2B8F-71BD-4FFD-9CD0-47197B934353;2026-07-23T09:15:35.802294;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;aws;create;Global; -12B68CB9-248E-42EB-A231-337DE83D2378;2026-07-23T09:15:35.802301;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;aws;read;Global; -573A8398-4755-4031-923C-63AAABA5041D;2026-07-23T09:15:35.802307;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;aws;manage-provider;Global; -20B53E15-8C5A-4289-8A53-9D3BFE0230A0;2026-07-23T09:15:35.802312;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;aws;read-provider;Global; -12D8B2CD-CD56-4C6A-A21B-5782179505A7;2026-07-23T09:15:35.802316;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;finout;read-dashboards;Global; -C41C1488-9C86-4B41-8CE9-35DE2120B8B4;2026-07-23T09:15:35.802320;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;finout;manage-dashboards;Global; -5D4BC161-BDED-4078-872F-494F3A515381;2026-07-23T09:15:35.802324;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;finout;manage-alerts;Global; -756D3132-687F-4A5C-AEC3-37B3001589AE;2026-07-23T09:15:35.802328;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;finout;read-alerts;Global; -6779F916-3E6D-490D-BE5C-B94F5A907672;2026-07-23T09:15:35.802332;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;azure;create;Global; -4F7BA42E-40E8-45BE-830E-45C3888470A5;2026-07-23T09:15:35.802364;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;azure;read;Global; -8BE5B8C9-2ADB-4A48-8A4D-B0ACC5D609E8;2026-07-23T09:15:35.802369;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;azure;read-provider;Global; -79693C7B-B9DF-4228-B467-68892D24860F;2026-07-23T09:15:35.802373;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;azure;manage-provider;Global; -1B015EC2-FCC4-4EE8-9FB6-1364C10B4D48;2026-07-23T09:15:35.802378;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;topics;read-public;Global; -8DAB5132-2D1C-4889-96C0-87F0932FD174;2026-07-23T09:15:35.802382;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;topics;read-private;Global; -4A6F9403-5E5B-4D4E-B9BF-80ABAC201E01;2026-07-23T09:15:35.802387;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;capability-membership-management;read;Global; -D0A528F6-E359-4BC5-A6B4-88C58EDC62A4;2026-07-23T09:15:35.802391;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;capability-membership-management;read-requests;Global; -D94C9D17-E297-4F65-ACF0-FD11A4FA2E7D;2026-07-23T09:15:35.802395;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;tags-and-metadata;read;Global; -17426823-83AE-4A75-AA77-68968445A66F;2026-07-23T09:15:35.802399;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;aws;read;Global; -94D0EF39-EA11-4C34-A972-6A56EBA39E05;2026-07-23T09:15:35.802403;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;aws;read-provider;Global; -35268B4C-B82F-43C0-9C3E-FE1693BBB4E2;2026-07-23T09:15:35.802407;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;finout;read-dashboards;Global; -B316CE3E-CA4B-4201-8DD2-0C66EA6E8893;2026-07-23T09:15:35.802411;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;finout;read-alerts;Global; -4BF97729-9C04-458A-9AE1-1C2B8C4E2448;2026-07-23T09:15:35.802415;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;azure;read;Global; -24A70679-816D-4542-A291-17C9E3750E9E;2026-07-23T09:15:35.802418;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;azure;read-provider;Global; -E0582B2F-CDE8-423D-8C46-B5E6C893B389;2026-07-23T09:15:35.802423;Role;F67CACC9-8DD4-4481-AC15-00B5DD83B046;topics;read-public;Global; -62828754-CA11-40EA-8E12-1CD66C423A04;2026-07-23T09:15:35.802427;Role;F67CACC9-8DD4-4481-AC15-00B5DD83B046;capability-membership-management;read;Global; -FE0F02C6-BB2C-4EA5-A2E7-57ED49E007DF;2026-07-23T09:15:35.802431;Role;F67CACC9-8DD4-4481-AC15-00B5DD83B046;tags-and-metadata;read;Global; -5B945857-7EA8-4540-92A6-9D53C649A8DD;2026-07-23T09:15:35.802435;Role;F67CACC9-8DD4-4481-AC15-00B5DD83B046;finout;read-dashboards;Global; -260E3A07-50BD-48A7-A7AF-FBD3CE681E3C;2026-07-23T09:15:35.802439;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;topics;create;Global; -5668DE32-F17B-4466-85BF-EF918BC10791;2026-07-23T09:15:35.802443;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;topics;read-public;Global; -471B5C65-5E85-4FCF-8A4F-58D023055DBB;2026-07-23T09:15:35.802447;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;topics;read-private;Global; -59EB2F5A-85DB-45DA-A099-5B996F042F72;2026-07-23T09:15:35.802451;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;topics;update;Global; -7C04DE78-FC43-4281-BCD7-0A5909ED45E6;2026-07-23T09:15:35.802455;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;topics;delete;Global; -6F001F31-306A-4D44-8760-E77742E97BF5;2026-07-23T09:15:35.802459;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability-management;receive-alerts;Global; -5B1ABCEF-5E34-461E-B933-5FC8925E175D;2026-07-23T09:15:35.802463;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability-management;receive-cost;Global; -CDE9EC1D-C3BC-42CF-8FF4-4676DE2DF5E0;2026-07-23T09:15:35.802467;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability-management;request-deletion;Global; -8F6C9030-5561-43B3-ABAB-AAC4D5FDAAFD;2026-07-23T09:15:35.802471;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability-management;manage-permissions;Global; -3BAF39FA-E1F7-405E-BDDE-E54C7A6414EC;2026-07-23T09:15:35.802475;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability-management;read-self-assess;Global; -BEA0704D-6B88-40B6-93C9-72C567016502;2026-07-23T09:15:35.802479;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability-management;create-self-assess;Global; -AA3ED47C-5372-49CC-BDA9-94EB7405286B;2026-07-23T09:15:35.802483;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability-management;batch-create-capabilities;Global; -A7E0615B-6BB6-4C46-B52C-1F532B882A20;2026-07-23T09:15:35.802487;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability-membership-management;create;Global; -553B57ED-0B11-4796-8DFF-C87374E13698;2026-07-23T09:15:35.802492;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability-membership-management;delete;Global; -2E6F2BA9-F2AC-42B1-A881-2AAD75DD1C67;2026-07-23T09:15:35.802496;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability-membership-management;read;Global; -3D95E997-6B97-4971-8225-19291F44D5E5;2026-07-23T09:15:35.802500;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability-membership-management;read-requests;Global; -7D322740-BABD-4743-A1F9-85A06F14BEF8;2026-07-23T09:15:35.802504;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability-membership-management;manage-requests;Global; -45A0C9C9-B115-476D-9418-A7852F1FAFB0;2026-07-23T09:15:35.802508;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;tags-and-metadata;create;Global; -429EF882-8EED-4C8F-B3F2-633CD0D89FD5;2026-07-23T09:15:35.802512;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;tags-and-metadata;read;Global; -809B28B6-13A2-4996-A28B-5F0C6832F572;2026-07-23T09:15:35.802516;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;tags-and-metadata;update;Global; -E4A77F04-C2EB-4E33-AF19-C1B9F7E249C5;2026-07-23T09:15:35.802520;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;tags-and-metadata;delete;Global; -59F5B9B1-0B16-4907-9892-CAC8D46806DD;2026-07-23T09:15:35.802524;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;aws;create;Global; -1D1C7EB7-2EB4-4A26-A7E3-537BA1F08D80;2026-07-23T09:15:35.802528;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;aws;read;Global; -486D49C3-A72F-4665-9112-10264EF479DC;2026-07-23T09:15:35.802532;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;aws;manage-provider;Global; -986F8E0E-320B-44F2-A95E-56D67774D2B8;2026-07-23T09:15:35.802535;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;aws;read-provider;Global; -533DE13A-9310-45E4-A845-12743F792074;2026-07-23T09:15:35.802539;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;finout;read-dashboards;Global; -160521A7-CE80-41E3-8F44-AAAB5772BA39;2026-07-23T09:15:35.802543;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;finout;manage-dashboards;Global; -AF53572A-ACD9-4A6B-B17B-FAC7293B3527;2026-07-23T09:15:35.802547;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;finout;manage-alerts;Global; -222F6368-DF53-4675-93BE-B5F3F89079F7;2026-07-23T09:15:35.802551;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;finout;read-alerts;Global; -D341E34E-BE0C-48F0-B651-9CFB84EC32FF;2026-07-23T09:15:35.802555;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;azure;create;Global; -0824258B-63A2-4CFE-9218-ED3A594DE109;2026-07-23T09:15:35.802559;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;azure;read;Global; -CD94038F-B325-4625-A50D-EA9E758E55C6;2026-07-23T09:15:35.802563;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;azure;read-provider;Global; -DBA916DD-F2EB-4A59-B780-00B88D4FADB3;2026-07-23T09:15:35.802567;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;azure;manage-provider;Global; -F033D884-EA98-4230-AB31-BE9D50579B16;2026-07-23T09:15:35.802570;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;rbac;create;Global; -F573E433-D2A6-4D99-A3D2-85952DE94EB9;2026-07-23T09:15:35.802574;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;rbac;read;Global; -9B56595A-22AD-4E96-A318-AC8E5C442B4D;2026-07-23T09:15:35.802578;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;rbac;update;Global; -9F28ACD9-082C-48B7-A0F6-737D17388CD7;2026-07-23T09:15:35.802582;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;rbac;delete;Global; -3766C7F2-675F-4DE6-8367-50E0968459CF;2026-07-23T09:15:35.802585;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;service-catalogue;read;Global; -51442D3E-CE6C-4407-9D69-ACE32C4FC7CD;2026-07-23T09:15:35.802590;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-legacy;read;Global; -66EEDB4E-48F2-4450-AFD6-8150DA8C91DE;2026-07-23T09:15:35.802594;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;view-deleted-capabilities;Global; -3B7336CF-F6F1-41FD-AE4F-3E3469223740;2026-07-23T09:15:35.802598;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;unset-capability-tags;Global; -9DE53FD2-FCF2-49AF-82E3-059B9CE6EE01;2026-07-23T09:15:35.802607;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;create-demo-recording;Global; -094C2E55-2C74-4136-91F6-C61EFD524913;2026-07-23T09:15:35.802611;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;update-demo-recording;Global; -70A6217D-947B-4E79-829A-8332955CD1BE;2026-07-23T09:15:35.802615;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;delete-demo-recording;Global; -37648039-F90E-47DE-83DA-71431870ACCA;2026-07-23T09:15:35.802620;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;manage-permission-matrix;Global; -F93F8A4A-FDED-43D4-98EA-AB74F67A1893;2026-07-23T09:15:35.802624;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;synchronize-aws-ecr-and-database-ecr;Global; -59B5CC02-9D5C-4762-9EB6-D884BB959F90;2026-07-23T09:15:35.802628;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;bypass-membership-approvals;Global; -5F685936-A455-4A03-BE71-B4BD02ACE8A7;2026-07-23T09:15:35.802632;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;manage-self-assessment-options;Global; -2117F27C-CDEB-46D5-8E4B-EB618E9DA6ED;2026-07-23T09:15:35.802636;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;create-release-notes;Global; -DB339914-DF95-4AC3-9236-33262A0F5381;2026-07-23T09:15:35.802640;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;update-release-note;Global; -99C2892C-B283-4CC5-9BF9-89FC51A6F52A;2026-07-23T09:15:35.802644;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;toggle-release-note-is-active;Global; -F272A151-CE15-49EB-8126-24FF128A8DE7;2026-07-23T09:15:35.802648;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;list-draft-release-notes;Global; -D435D795-24A7-4B4D-9DB0-BB0EC6179115;2026-07-23T09:15:35.802652;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;remove-release-note;Global; -D6E3BDE2-607F-4B64-998F-2C550728B694;2026-07-23T09:15:35.802656;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;create-event;Global; -F7BA0993-5E2E-41D4-BA41-757CD0B3B485;2026-07-23T09:15:35.802660;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;update-event;Global; -D82DC6F8-4E45-4AE9-9FE2-29EC1B115C9E;2026-07-23T09:15:35.802664;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;delete-event;Global; -12B2C367-EBA8-4369-9780-A3F50A0412DF;2026-07-23T09:15:35.802668;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;create-news-item;Global; -8F5947C1-977C-4F95-8C09-DE2F2B8741DC;2026-07-23T09:15:35.802672;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;update-news-item;Global; -BE05A459-AA3A-4A74-B300-62BA19B50618;2026-07-23T09:15:35.802676;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;delete-news-item;Global; -B908B85B-8489-4E5F-8130-BFA4FAA7A631;2026-07-23T09:15:35.802680;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;get-user-emails;Global; -FAABC901-C540-4FDD-9408-16812B3683E3;2026-07-23T09:15:35.802684;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;delete-membership-application-as-admin;Global; -708B2C75-2CDD-4545-A717-D5BBDE8C9884;2026-07-23T09:15:35.802688;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;retry-creating-message-contract;Global; -77763D1C-2D3A-426F-BB4B-CDBFC48BDC3D;2026-07-23T09:15:35.802690;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;manage-json-schemas;Global; -7E6A90BB-9E8C-4F11-AFE8-F53D97B4B803;2026-07-23T09:15:35.802693;Role;6A2EE52C-6A9B-4A2A-B9C8-5851DD2D9A6F;capability-management;batch-create-capabilities;Global; -213F793E-3048-427E-863C-D359BBA7D9CA;2026-07-23T09:15:35.802697;Role;A983CF2E-772E-437D-B9D8-5DDF769339D3;service-catalogue;read;Global; +B277A53F-336E-4D29-9971-861573BEC4A3;2026-07-28T08:00:09.520470+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;topics;create;Global; +BF89BA53-8C91-4CFC-A85B-80652702D24D;2026-07-28T08:00:09.520480+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;topics;read-public;Global; +88BE493D-248F-4B71-810A-B1A83D729246;2026-07-28T08:00:09.520485+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;topics;read-private;Global; +A7D1763B-D62E-412D-A7A1-B9888D140816;2026-07-28T08:00:09.520489+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;topics;update;Global; +7E45FC18-5EF8-4DAF-A452-3E3A33A66F1A;2026-07-28T08:00:09.520493+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;topics;delete;Global; +A27D4ECD-4BD3-4BF4-BEE6-EEB5F04D21F0;2026-07-28T08:00:09.520497+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;topics;delete-public;Global; +D0658624-7D87-4B84-B97B-51E3FD077C3E;2026-07-28T08:00:09.520500+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;topics;retry-creating-message-contract;Global; +FC0E162C-1538-4791-83E6-32EA15E4B2C0;2026-07-28T08:00:09.520504+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;demos;read-signups;Global; +2D471B03-B3B1-4AAD-9646-B7C77F8ED9D9;2026-07-28T08:00:09.520508+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability;receive-alerts;Global; +D9187254-72AA-482B-8994-11ED91790579;2026-07-28T08:00:09.520512+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability;receive-cost;Global; +5C5041BD-34DD-4175-8856-5279A2ACDC09;2026-07-28T08:00:09.520517+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability;request-deletion;Global; +4FA05C5C-CDBB-4690-9E2F-CB05B1C8A411;2026-07-28T08:00:09.520521+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability;manage-permissions;Global; +73196C5E-0C65-40F9-976E-93C0F4941139;2026-07-28T08:00:09.520524+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability;read-self-assess;Global; +A816C63B-4FF3-4EA3-8B2B-F8DCB7D42296;2026-07-28T08:00:09.520528+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability;create-self-assess;Global; +86A8A620-AFCE-41F4-80F5-7D80D812831D;2026-07-28T08:00:09.520532+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability;invite-member;Global; +38EA82AB-D5BD-4A11-899B-2DB86E237DED;2026-07-28T08:00:09.520535+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability;remove-member;Global; +D4EF77E6-B750-4563-AA2D-883BD1A4A3B7;2026-07-28T08:00:09.520539+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability;read-members;Global; +F6F91A2B-A4D9-40FB-9E88-672EBC339C28;2026-07-28T08:00:09.520543+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability;read-requests;Global; +3919E624-95B2-460F-A8DD-B516E287D229;2026-07-28T08:00:09.520546+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;capability;manage-requests;Global; +D58F5AEA-3E88-4DD2-AE2C-7B42FFBFCD94;2026-07-28T08:00:09.520550+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;tags-and-metadata;create;Global; +5B7376C8-FFE8-4673-9AE9-4EA8649574D8;2026-07-28T08:00:09.520554+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;tags-and-metadata;read;Global; +5C9FDA55-81C1-495B-A0D9-C2EA5A76F032;2026-07-28T08:00:09.520557+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;tags-and-metadata;update;Global; +7960A967-439B-42C9-A52C-DABDCF938A39;2026-07-28T08:00:09.520561+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;tags-and-metadata;delete;Global; +0904F6FD-5004-4C4D-A735-8DA15BF6BBE9;2026-07-28T08:00:09.520565+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;aws;create;Global; +47C2ABE2-C754-47CF-97B7-F0807C23117A;2026-07-28T08:00:09.520569+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;aws;read;Global; +EEE8D53F-992A-4627-8533-C3FB27B945FD;2026-07-28T08:00:09.520573+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;aws;manage-provider;Global; +EA8F2945-7A50-4CCB-A865-432F4B978C88;2026-07-28T08:00:09.520576+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;aws;read-provider;Global; +629789C5-AF6D-41A0-9B09-91A07BCA4650;2026-07-28T08:00:09.520580+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;finout;read-dashboards;Global; +74CBB1D7-29B3-4EDB-94D8-8FB5B5DF0C9D;2026-07-28T08:00:09.520584+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;finout;manage-dashboards;Global; +1A4243BA-2E08-4E94-99EE-BC91E0247C1B;2026-07-28T08:00:09.520589+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;finout;manage-alerts;Global; +D7C7F366-AABB-43E0-A966-576CAF85B26F;2026-07-28T08:00:09.520593+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;finout;read-alerts;Global; +BE33D586-9895-4097-A361-E233763B64C7;2026-07-28T08:00:09.520597+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;azure;create;Global; +4DF9C45B-AA8D-4826-BDD5-0DFF189F87EF;2026-07-28T08:00:09.520601+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;azure;read;Global; +A91703F7-089A-471C-88F1-BC35BF7A0892;2026-07-28T08:00:09.520605+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;azure;read-provider;Global; +06EF4054-0229-40EE-A51B-8E9A139BADC1;2026-07-28T08:00:09.520609+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;azure;manage-provider;Global; +D74CECB2-6FAA-4425-B719-280157ACB13D;2026-07-28T08:00:09.520613+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;rbac;create;Global; +EE28D3B6-99D2-4990-B959-7605515D3651;2026-07-28T08:00:09.520617+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;rbac;read;Global; +CA3B04ED-70BA-48B1-8F09-737FF803637C;2026-07-28T08:00:09.520620+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;rbac;update;Global; +F1175DB6-8C6E-406A-B604-1FEE6BF09CBB;2026-07-28T08:00:09.520624+00:00;Role;36202DFB-D106-440D-8B99-F11BC8D77C9C;rbac;delete;Global; +B983A44B-575F-4716-AE87-061BE4F026AA;2026-07-28T08:00:09.520628+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;topics;create;Global; +92C0B891-3CDC-430A-B229-F22443C7C875;2026-07-28T08:00:09.520632+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;topics;read-public;Global; +699E3218-DFC6-4D5B-BB50-5E53262CE7BA;2026-07-28T08:00:09.520636+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;topics;read-private;Global; +3EABC71D-A5AB-482B-ADD2-347B9AA81BC9;2026-07-28T08:00:09.520639+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;topics;update;Global; +E4D482B8-C8C0-428A-B141-F6351085EE23;2026-07-28T08:00:09.520643+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;topics;delete;Global; +355AAB6E-409F-4B89-B425-D3BF352387E1;2026-07-28T08:00:09.520646+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;topics;delete-public;Global; +660B2D41-717D-4FEB-BF0E-9CA02D51F7DB;2026-07-28T08:00:09.520650+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;capability;receive-alerts;Global; +97A4E1C4-AA5B-416A-9553-8735A1CF98D2;2026-07-28T08:00:09.520654+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;capability;invite-member;Global; +D509A39E-4C27-4212-B843-1ACBF1677BAC;2026-07-28T08:00:09.520658+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;capability;read-members;Global; +FF971709-5AA7-4160-B990-40F5DB1F1C30;2026-07-28T08:00:09.520661+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;capability;read-requests;Global; +A3507495-1ED4-4910-9921-94CA38A5B593;2026-07-28T08:00:09.520665+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;capability;manage-requests;Global; +39A63A41-8526-4A95-B768-485965B9B86E;2026-07-28T08:00:09.520669+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;tags-and-metadata;create;Global; +09EB5423-5539-4CF9-B747-929AE86B793F;2026-07-28T08:00:09.520672+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;tags-and-metadata;read;Global; +BEE63160-2FC2-4422-AB2C-9AB0B5ACEB1F;2026-07-28T08:00:09.520676+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;tags-and-metadata;update;Global; +F5A90594-26CF-463B-88F9-3FEA6437AAD2;2026-07-28T08:00:09.520680+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;tags-and-metadata;delete;Global; +AE0CC531-8798-4006-97B1-FC7B1A51B989;2026-07-28T08:00:09.520683+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;aws;create;Global; +87339788-B9D9-44E1-B551-D2579F81D96A;2026-07-28T08:00:09.520687+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;aws;read;Global; +C0EA92DA-EF1D-43B6-A75D-235214C1B385;2026-07-28T08:00:09.520690+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;aws;manage-provider;Global; +31A9E66E-320C-4904-955F-7F49E69209C4;2026-07-28T08:00:09.520694+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;aws;read-provider;Global; +002D8D1E-4680-4ADB-A5FD-D2247A3EE644;2026-07-28T08:00:09.520713+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;finout;read-dashboards;Global; +F1736FC6-90F3-4B39-BA99-073B9B45BF17;2026-07-28T08:00:09.520717+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;finout;manage-dashboards;Global; +FAB33178-2131-474E-8273-587AE6378981;2026-07-28T08:00:09.520720+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;finout;manage-alerts;Global; +872FAD29-1FF9-4AFF-8707-23A7B2C02476;2026-07-28T08:00:09.520724+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;finout;read-alerts;Global; +1F76C5A3-96A5-44C0-8ABA-79AF2244DAD2;2026-07-28T08:00:09.520728+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;azure;create;Global; +AE03FDED-C509-4FB3-8F69-DEBDE0FB06B1;2026-07-28T08:00:09.520731+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;azure;read;Global; +7F0F1562-E032-4056-9EF9-3572E625E07C;2026-07-28T08:00:09.520735+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;azure;read-provider;Global; +24F0B3DA-7AD0-45DA-BA0F-0C2351AE9F85;2026-07-28T08:00:09.520738+00:00;Role;2C561A6D-90F4-4649-80B3-76A854A64EA2;azure;manage-provider;Global; +E57BCD89-456F-432A-83C9-5990C423429E;2026-07-28T08:00:09.520742+00:00;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;topics;read-public;Global; +BF2F8C39-8BE6-4F4A-BB4C-CA001FBFF748;2026-07-28T08:00:09.520746+00:00;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;topics;read-private;Global; +5CEEB602-59B0-45BA-BE59-29B3A643C31D;2026-07-28T08:00:09.520750+00:00;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;capability;read-members;Global; +D402B19E-6D14-467B-BA9A-C0C139CEB1F7;2026-07-28T08:00:09.520753+00:00;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;capability;read-requests;Global; +F516A795-1AD7-4F82-90D6-2D35F36A0115;2026-07-28T08:00:09.520757+00:00;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;tags-and-metadata;read;Global; +D3D9FEC8-8EDE-4F4A-984F-73917F92DBDF;2026-07-28T08:00:09.520760+00:00;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;aws;read;Global; +C61FE52F-9F9B-414D-ACDE-8B4EF57953A5;2026-07-28T08:00:09.520764+00:00;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;aws;read-provider;Global; +7EF8E282-11AA-4928-B5D6-084E3D1AF3AC;2026-07-28T08:00:09.520767+00:00;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;finout;read-dashboards;Global; +B4CE5F8D-9C39-4A7A-873B-1EEA694282F6;2026-07-28T08:00:09.520771+00:00;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;finout;read-alerts;Global; +BA7FFCD9-3A89-4C1F-91A6-D5E39A6E3C43;2026-07-28T08:00:09.520775+00:00;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;azure;read;Global; +37E7A0B5-C656-4AA0-9EDD-D8257869EFE1;2026-07-28T08:00:09.520778+00:00;Role;22DAB91B-C2D8-4840-A173-1416EF1B882D;azure;read-provider;Global; +B1DB5828-D736-44DB-B35E-621E5314D044;2026-07-28T08:00:09.520782+00:00;Role;F67CACC9-8DD4-4481-AC15-00B5DD83B046;topics;read-public;Global; +12ACD66B-A378-4DC8-A1CF-D3E0F1D8CE0E;2026-07-28T08:00:09.520785+00:00;Role;F67CACC9-8DD4-4481-AC15-00B5DD83B046;capability;read-members;Global; +BA594BA6-2E72-442B-A6AC-AC83D77936CC;2026-07-28T08:00:09.520789+00:00;Role;F67CACC9-8DD4-4481-AC15-00B5DD83B046;tags-and-metadata;read;Global; +8783E619-5381-417F-9B6E-F2DFEC4B1EB9;2026-07-28T08:00:09.520793+00:00;Role;F67CACC9-8DD4-4481-AC15-00B5DD83B046;finout;read-dashboards;Global; +CD895564-9A00-4F76-A506-D237CF0580D4;2026-07-28T08:00:09.520797+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;topics;create;Global; +ABA64D4C-121F-44B0-B5A2-941DF6570769;2026-07-28T08:00:09.520800+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;topics;read-public;Global; +F60FAFF4-A536-4202-AFAD-62714F240831;2026-07-28T08:00:09.520804+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;topics;read-private;Global; +44981CF1-4D08-4FE6-8403-0125A7150A6A;2026-07-28T08:00:09.520807+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;topics;update;Global; +217B6719-DEDF-447D-B5B6-1C05D3115CA5;2026-07-28T08:00:09.520811+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;topics;delete;Global; +51A0AC48-F31B-4953-9CFE-B837C25CA765;2026-07-28T08:00:09.520814+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;topics;delete-public;Global; +0D866000-76C0-4027-A870-5117B48EC75E;2026-07-28T08:00:09.520817+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;topics;retry-creating-message-contract;Global; +F047369B-4AD6-47A4-8426-CCD0D436993E;2026-07-28T08:00:09.520821+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;demos;create;Global; +FAADA0C8-7F24-4E9D-9979-1D1BC3922578;2026-07-28T08:00:09.520825+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;demos;update;Global; +CE68B23C-8E12-4DB3-9845-BF9EA60747D8;2026-07-28T08:00:09.520828+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;demos;delete;Global; +5831B5FA-D571-4420-AE57-7CFEDECB293B;2026-07-28T08:00:09.520832+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;demos;read-signups;Global; +151B2D97-2A59-4DF5-B823-E8A4A3B6986F;2026-07-28T08:00:09.520836+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability;receive-alerts;Global; +2CB7A479-4B0C-4FEF-A247-0FFD11C3F0D1;2026-07-28T08:00:09.520840+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability;receive-cost;Global; +FC1815F4-D4ED-4343-B70B-F018830EB736;2026-07-28T08:00:09.520844+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability;request-deletion;Global; +D6709690-7839-4817-B923-81192929750B;2026-07-28T08:00:09.520847+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability;manage-permissions;Global; +F16196B7-71D5-403A-99D0-FC394C75D4C9;2026-07-28T08:00:09.520851+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability;read-self-assess;Global; +77CBF6E3-2B46-48BE-A588-A525F3F37127;2026-07-28T08:00:09.520855+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability;create-self-assess;Global; +DEA7EA21-966B-4870-8C27-0E45DDA2B17C;2026-07-28T08:00:09.520859+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability;batch-create-capabilities;Global; +1D2E7B27-0A6C-4BBC-991F-789B19AAA47F;2026-07-28T08:00:09.520862+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability;view-deleted-capabilities;Global; +EDBDE421-56EB-429C-BA1A-0621186F851A;2026-07-28T08:00:09.520866+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability;bypass-membership-approvals;Global; +9767F11A-F574-48B9-BA38-9AD811C4B794;2026-07-28T08:00:09.520870+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability;unset-capability-tags;Global; +E612DCD3-8E0A-4EE0-A833-5C5A0A585BE4;2026-07-28T08:00:09.520874+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability;invite-member;Global; +6ED44BBE-1865-408D-9222-66CD9DD51E87;2026-07-28T08:00:09.520877+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability;remove-member;Global; +904C2B83-37DA-4CF6-9B64-B59AC4DCF596;2026-07-28T08:00:09.520881+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability;read-members;Global; +6F8A2755-7190-40D1-A8C5-358B3123BED6;2026-07-28T08:00:09.520884+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability;read-requests;Global; +2A91AB02-DCE3-4F25-B5D8-379572563278;2026-07-28T08:00:09.520888+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;capability;manage-requests;Global; +C4A5EC6F-3766-4A65-BAD4-EE02CADAE5DD;2026-07-28T08:00:09.520892+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;tags-and-metadata;create;Global; +E4A51B87-6381-4558-91CD-AFE231A9267F;2026-07-28T08:00:09.520895+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;tags-and-metadata;read;Global; +D800E6D4-9A1F-48A6-911D-FB2E719D1F7D;2026-07-28T08:00:09.520899+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;tags-and-metadata;update;Global; +E60BF395-5FE1-4C07-B9B4-B27868F621A9;2026-07-28T08:00:09.520902+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;tags-and-metadata;delete;Global; +AC1DEBB0-9F9D-4A21-8BB9-FC48B78B4313;2026-07-28T08:00:09.520906+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;aws;create;Global; +20829EEF-D2ED-4DF4-8016-4418205DA242;2026-07-28T08:00:09.520910+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;aws;read;Global; +7EA190F0-441A-433D-86E4-13A030E10403;2026-07-28T08:00:09.520913+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;aws;manage-provider;Global; +20625256-1036-4A7D-957F-5F65728CF2CD;2026-07-28T08:00:09.520917+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;aws;read-provider;Global; +0A24F53C-5264-472E-95AE-68E5FB62FFA8;2026-07-28T08:00:09.520920+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;finout;read-dashboards;Global; +B3D2F16F-0410-466E-B324-16F7D6E1720E;2026-07-28T08:00:09.520928+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;finout;manage-dashboards;Global; +7C8BFD99-AE1E-45E8-A36E-10F3D8115F90;2026-07-28T08:00:09.520932+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;finout;manage-alerts;Global; +8D888EB8-92C2-4B1A-8CB4-F03491E19A59;2026-07-28T08:00:09.520936+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;finout;read-alerts;Global; +57B8D78D-D9DD-4B9B-84EF-044D880BBC3F;2026-07-28T08:00:09.520939+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;azure;create;Global; +389D43F1-5137-4852-9FD6-29E0427B26BE;2026-07-28T08:00:09.520943+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;azure;read;Global; +1E39EABB-9FCF-4025-9B57-715B9C92B221;2026-07-28T08:00:09.520946+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;azure;read-provider;Global; +8695A114-4EFD-4925-A71B-C827D45E0775;2026-07-28T08:00:09.520950+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;azure;manage-provider;Global; +F755860C-BA30-4E5A-ABDF-A99636BB7B3D;2026-07-28T08:00:09.520953+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;rbac;create;Global; +FCEE5C78-C8B2-446B-96C7-B8E74644D310;2026-07-28T08:00:09.520957+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;rbac;read;Global; +E02B18ED-F562-4AD0-AD43-0160E67F4600;2026-07-28T08:00:09.520972+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;rbac;update;Global; +B43F4B4D-8B19-4864-BFE9-459D56099F4D;2026-07-28T08:00:09.520977+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;rbac;delete;Global; +335E4EEA-59A2-4F71-834A-4218C4E25225;2026-07-28T08:00:09.520982+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;service-catalogue;read;Global; +8CF75C0D-FE43-4FED-A13C-9DA3A312B655;2026-07-28T08:00:09.520985+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-legacy;read;Global; +B20F7B4B-9EE1-49AE-9CB1-DE2AE05A8527;2026-07-28T08:00:09.520989+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;self-assessment;manage-self-assessment-options;Global; +8A6069A7-4DF9-4B85-BAAF-506C7C54B5C0;2026-07-28T08:00:09.520993+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;release-notes;create;Global; +66BAD326-BC6A-48A2-A241-F771A5DC9F16;2026-07-28T08:00:09.520997+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;release-notes;update;Global; +BE4A4E03-FAD2-4D94-A931-35702F84A8A1;2026-07-28T08:00:09.521000+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;release-notes;toggle-release-note-is-active;Global; +BE0F9DE0-E6E9-4D15-964F-CB80EE93E9AB;2026-07-28T08:00:09.521004+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;release-notes;list-draft-release-notes;Global; +6D79BC0E-AE7D-4FD1-8071-C2B8A0404CB2;2026-07-28T08:00:09.521008+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;release-notes;delete;Global; +528E7CA0-A33A-4004-8CC5-D7A20A3FFADD;2026-07-28T08:00:09.521011+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;events;create;Global; +7493B5D6-1A79-4609-9B6E-C47BD910932F;2026-07-28T08:00:09.521015+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;events;update;Global; +3AE0D259-932B-4190-A55E-39DE7BB770DA;2026-07-28T08:00:09.521019+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;events;delete;Global; +821AFDEC-C582-4006-91F9-B194AA5F98E6;2026-07-28T08:00:09.521022+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;news;create;Global; +9E74B5E4-D021-45B9-A71A-4CB33FD7D897;2026-07-28T08:00:09.521026+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;news;update;Global; +AA1009FA-F26A-4CE5-885B-E61A2EE796A8;2026-07-28T08:00:09.521029+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;news;delete;Global; +C48F5140-972F-4CBE-89D9-5155D0D97490;2026-07-28T08:00:09.521032+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;users;read;Global; +076FC070-E09A-4182-9D3E-F08830F4585F;2026-07-28T08:00:09.521036+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;synchronize-aws-ecr-and-database-ecr;Global; +57B37773-5BB5-4BA4-AF9D-C40AB3EBC734;2026-07-28T08:00:09.521040+00:00;Role;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;system-admin;manage-json-schemas;Global; +15233D13-99DA-4FDD-9F57-5A7D08EF2669;2026-07-28T08:00:09.521044+00:00;Role;6A2EE52C-6A9B-4A2A-B9C8-5851DD2D9A6F;capability;batch-create-capabilities;Global; +5EB34D2A-D0B8-4415-BC86-7A51BB8442C8;2026-07-28T08:00:09.521048+00:00;Role;A983CF2E-772E-437D-B9D8-5DDF769339D3;service-catalogue;read;Global; diff --git a/db/seed/RbacRole.csv b/db/seed/RbacRole.csv index 3fa8de18..bfdf31ee 100644 --- a/db/seed/RbacRole.csv +++ b/db/seed/RbacRole.csv @@ -1,8 +1,8 @@ Id;OwnerId;CreatedAt;UpdatedAt;Name;Description;Type -36202DFB-D106-440D-8B99-F11BC8D77C9C;0000DFD5-0000-0000-0000-00000000000A;2026-07-23T09:15:35.801873;2026-07-23T09:15:35.801901;Owner;Role: Owner;Global -2C561A6D-90F4-4649-80B3-76A854A64EA2;0000DFD5-0000-0000-0000-00000000000A;2026-07-23T09:15:35.801908;2026-07-23T09:15:35.801909;Contributor;Role: Contributor;Global -22DAB91B-C2D8-4840-A173-1416EF1B882D;0000DFD5-0000-0000-0000-00000000000A;2026-07-23T09:15:35.801913;2026-07-23T09:15:35.801914;Reader;Role: Reader;Global -F67CACC9-8DD4-4481-AC15-00B5DD83B046;0000DFD5-0000-0000-0000-00000000000A;2026-07-23T09:15:35.801917;2026-07-23T09:15:35.801918;Guest;Role: Guest;Global -5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;0000DFD5-0000-0000-0000-00000000000A;2026-07-23T09:15:35.801921;2026-07-23T09:15:35.801922;CloudEngineer;Role: CloudEngineer;Global -6A2EE52C-6A9B-4A2A-B9C8-5851DD2D9A6F;0000DFD5-0000-0000-0000-00000000000A;2026-07-23T09:15:35.801925;2026-07-23T09:15:35.801926;BatchCapabilityCreator;Role: BatchCapabilityCreator;Global -A983CF2E-772E-437D-B9D8-5DDF769339D3;0000DFD5-0000-0000-0000-00000000000A;2026-07-23T09:15:35.801929;2026-07-23T09:15:35.801930;ServiceCatalogueReader;Role: ServiceCatalogueReader;Global +36202DFB-D106-440D-8B99-F11BC8D77C9C;0000DFD5-0000-0000-0000-00000000000A;2026-07-28T08:00:09.520313+00:00;2026-07-28T08:00:09.520339+00:00;Owner;Role: Owner;Global +2C561A6D-90F4-4649-80B3-76A854A64EA2;0000DFD5-0000-0000-0000-00000000000A;2026-07-28T08:00:09.520344+00:00;2026-07-28T08:00:09.520345+00:00;Contributor;Role: Contributor;Global +22DAB91B-C2D8-4840-A173-1416EF1B882D;0000DFD5-0000-0000-0000-00000000000A;2026-07-28T08:00:09.520349+00:00;2026-07-28T08:00:09.520350+00:00;Reader;Role: Reader;Global +F67CACC9-8DD4-4481-AC15-00B5DD83B046;0000DFD5-0000-0000-0000-00000000000A;2026-07-28T08:00:09.520353+00:00;2026-07-28T08:00:09.520354+00:00;Guest;Role: Guest;Global +5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;0000DFD5-0000-0000-0000-00000000000A;2026-07-28T08:00:09.520356+00:00;2026-07-28T08:00:09.520357+00:00;CloudEngineer;Role: CloudEngineer;Global +6A2EE52C-6A9B-4A2A-B9C8-5851DD2D9A6F;0000DFD5-0000-0000-0000-00000000000A;2026-07-28T08:00:09.520360+00:00;2026-07-28T08:00:09.520361+00:00;BatchCapabilityCreator;Role: BatchCapabilityCreator;Global +A983CF2E-772E-437D-B9D8-5DDF769339D3;0000DFD5-0000-0000-0000-00000000000A;2026-07-28T08:00:09.520364+00:00;2026-07-28T08:00:09.520364+00:00;ServiceCatalogueReader;Role: ServiceCatalogueReader;Global diff --git a/db/seed/RbacRoleGrants.csv b/db/seed/RbacRoleGrants.csv index 2cf67820..b77264b2 100644 --- a/db/seed/RbacRoleGrants.csv +++ b/db/seed/RbacRoleGrants.csv @@ -1,7 +1,7 @@ Id;RoleId;CreatedAt;AssignedEntityType;AssignedEntityId;Type;Resource -E02D91E6-DE3C-4C55-BC0A-EDABD1492197;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;2026-07-23T09:15:35.803819;Group;BA0AA734-206D-454E-AC95-14855B6901E4;Global; -4CE54588-72CB-4B27-93D3-7F842B9C91AF;6A2EE52C-6A9B-4A2A-B9C8-5851DD2D9A6F;2026-07-23T09:15:35.803831;Group;899F8F9E-3F7E-4EF3-A2CD-2E1DDA78E40A;Global; -059F294D-4FD4-4836-9B11-9A7E8FA125C7;A983CF2E-772E-437D-B9D8-5DDF769339D3;2026-07-23T09:15:35.803837;Group;7D3D7498-9075-4D1B-B6C1-AF6E95788C3B;Global; -F1F3A53C-3D8E-4D54-BF66-7FB67209B701;36202DFB-D106-440D-8B99-F11BC8D77C9C;2026-07-23T09:15:35.803840;User;owner@bar.com;Capability;bar -706A6EB8-4378-4F66-9D37-BC84601D57F0;2C561A6D-90F4-4649-80B3-76A854A64EA2;2026-07-23T09:15:35.803843;User;contributor@bar.com;Capability;bar -8D0D4C50-2336-4C1C-91D8-7654577F52B3;22DAB91B-C2D8-4840-A173-1416EF1B882D;2026-07-23T09:15:35.803846;User;reader@bar.com;Capability;bar +FAB12495-6C01-47ED-ACD5-89F26598E6AE;5E32EE6A-1A73-4ACF-9C61-90E4D0D59261;2026-07-28T08:00:09.521191+00:00;Group;BA0AA734-206D-454E-AC95-14855B6901E4;Global; +656007CA-4B1C-4371-B476-389B232471B7;36202DFB-D106-440D-8B99-F11BC8D77C9C;2026-07-28T08:00:09.521196+00:00;Group;890CC44E-2D09-5ACE-A1C3-F62560AE45F8;Capability;bar +8E22A84B-202B-4D55-99AB-4D5338085488;2C561A6D-90F4-4649-80B3-76A854A64EA2;2026-07-28T08:00:09.521201+00:00;Group;12F13079-AD3A-5F64-9AD6-1A94D5F8C7C5;Capability;bar +27433F2F-A40D-4D9D-AB5A-FE662CF35E24;22DAB91B-C2D8-4840-A173-1416EF1B882D;2026-07-28T08:00:09.521205+00:00;Group;7C72E0F1-6FBA-5165-94EA-7EE4A75C35A2;Capability;bar +C8430FA1-5AFA-4926-A6C8-DB4080535CF4;6A2EE52C-6A9B-4A2A-B9C8-5851DD2D9A6F;2026-07-28T08:00:09.521209+00:00;Group;899F8F9E-3F7E-4EF3-A2CD-2E1DDA78E40A;Global; +32F8845E-72C8-4BFB-BAD6-2313AB2D7E02;A983CF2E-772E-437D-B9D8-5DDF769339D3;2026-07-28T08:00:09.521213+00:00;Group;7D3D7498-9075-4D1B-B6C1-AF6E95788C3B;Global; diff --git a/src/SelfService.Tests/Application/TestRbacApplicationService.cs b/src/SelfService.Tests/Application/TestRbacApplicationService.cs index 143e0de7..3879cfe9 100644 --- a/src/SelfService.Tests/Application/TestRbacApplicationService.cs +++ b/src/SelfService.Tests/Application/TestRbacApplicationService.cs @@ -1,4 +1,4 @@ -using Microsoft.EntityFrameworkCore; +using Microsoft.EntityFrameworkCore; using Microsoft.Extensions.DependencyInjection; using SelfService.Application; using SelfService.Domain.Models; @@ -402,7 +402,7 @@ await rbacSvc.IsUserPermitted( ( await rbacSvc.IsUserPermitted( "test01@dfds.cloud", - [new Permission { Namespace = RbacNamespace.CapabilityManagement, Name = "request-deletion" }], + [new Permission { Namespace = RbacNamespace.Capability, Name = "request-deletion" }], "test01" ) ).Permitted() @@ -590,7 +590,7 @@ await rbacSvc.IsUserPermitted( ( await rbacSvc.IsUserPermitted( "owner@bar.com", - [new Permission { Namespace = RbacNamespace.CapabilityMembershipManagement, Name = "create" }], + [new Permission { Namespace = RbacNamespace.Capability, Name = "invite-member" }], "bar" ) ).Permitted() @@ -600,7 +600,7 @@ await rbacSvc.IsUserPermitted( ( await rbacSvc.IsUserPermitted( "owner@bar.com", - [new Permission { Namespace = RbacNamespace.CapabilityMembershipManagement, Name = "delete" }], + [new Permission { Namespace = RbacNamespace.Capability, Name = "remove-member" }], "bar" ) ).Permitted() @@ -625,7 +625,7 @@ public async void CapabilityContributorAccessUsingDbStore() ( await rbacSvc.IsUserPermitted( "contributor@bar.com", - [new Permission { Namespace = RbacNamespace.CapabilityManagement, Name = "delete" }], + [new Permission { Namespace = RbacNamespace.Capability, Name = "remove-member" }], "bar" ) ).Permitted() @@ -665,7 +665,7 @@ await rbacSvc.IsUserPermitted( ( await rbacSvc.IsUserPermitted( "contributor@bar.com", - [new Permission { Namespace = RbacNamespace.CapabilityMembershipManagement, Name = "create" }], + [new Permission { Namespace = RbacNamespace.Capability, Name = "invite-member" }], "bar" ) ).Permitted() @@ -710,7 +710,7 @@ await rbacSvc.IsUserPermitted( ( await rbacSvc.IsUserPermitted( "reader@bar.com", - [new Permission { Namespace = RbacNamespace.CapabilityManagement, Name = "delete" }], + [new Permission { Namespace = RbacNamespace.Capability, Name = "remove-member" }], "bar" ) ).Permitted() diff --git a/src/SelfService.Tests/Application/TestRbacBulkAndMembers.cs b/src/SelfService.Tests/Application/TestRbacBulkAndMembers.cs index 8949e4e9..b0a68968 100644 --- a/src/SelfService.Tests/Application/TestRbacBulkAndMembers.cs +++ b/src/SelfService.Tests/Application/TestRbacBulkAndMembers.cs @@ -14,7 +14,17 @@ public async Task GrantPermissions_bulk_creates_all_on_success() populateDatabase: true, rbacRoleGrantsSeed: new List(), rbacGroupSeed: new List(), - rbacPermissionGrantsSeed: new List() + rbacPermissionGrantsSeed: new List + { + RbacPermissionGrant.New( + AssignedEntityType.User, + "ce@dfds.com", + RbacNamespace.Rbac, + "create", + RbacAccessType.Global, + "" + ), + } ); var svc = fixture.ApiApplication.Services.GetService()!; @@ -45,9 +55,12 @@ public async Task GrantPermissions_bulk_creates_all_on_success() await fixture.DbContext.SaveChangesAsync(); var allGrants = await fixture.DbContext.RbacPermissionGrants.ToListAsync(); - Assert.Equal(2, allGrants.Count); - Assert.Contains(allGrants, g => g.AssignedEntityId == "alice@dfds.com"); - Assert.Contains(allGrants, g => g.AssignedEntityId == "bob@dfds.com"); + var createdByBulk = allGrants + .Where(g => g.AssignedEntityId == "alice@dfds.com" || g.AssignedEntityId == "bob@dfds.com") + .ToList(); + Assert.Equal(2, createdByBulk.Count); + Assert.Contains(createdByBulk, g => g.AssignedEntityId == "alice@dfds.com"); + Assert.Contains(createdByBulk, g => g.AssignedEntityId == "bob@dfds.com"); } [Fact] @@ -57,7 +70,17 @@ public async Task GrantPermissions_bulk_rolls_back_atomically_on_failure() populateDatabase: true, rbacRoleGrantsSeed: new List(), rbacGroupSeed: new List(), - rbacPermissionGrantsSeed: new List() + rbacPermissionGrantsSeed: new List + { + RbacPermissionGrant.New( + AssignedEntityType.User, + "ce@dfds.com", + RbacNamespace.Rbac, + "create", + RbacAccessType.Global, + "" + ), + } ); var svc = fixture.ApiApplication.Services.GetService()!; @@ -94,7 +117,17 @@ public async Task GrantGroupGrant_accepts_service_principal_member() var fixture = await RbacTestData.NewInMemoryFixture( populateDatabase: true, - rbacPermissionGrantsSeed: new List(), + rbacPermissionGrantsSeed: new List + { + RbacPermissionGrant.New( + AssignedEntityType.User, + "ce@dfds.com", + RbacNamespace.Rbac, + "create", + RbacAccessType.Global, + "" + ), + }, rbacRoleGrantsSeed: new List(), rbacGroupSeed: new List { seedGroup } ); diff --git a/src/SelfService.Tests/Application/TestRbacGrantAuthorization.cs b/src/SelfService.Tests/Application/TestRbacGrantAuthorization.cs index 170514b7..48edeb7d 100644 --- a/src/SelfService.Tests/Application/TestRbacGrantAuthorization.cs +++ b/src/SelfService.Tests/Application/TestRbacGrantAuthorization.cs @@ -55,7 +55,7 @@ private static async Task NewScenario() RbacPermissionGrant.New( AssignedEntityType.Role, ownerRole.Id.ToString(), - RbacNamespace.CapabilityManagement, + RbacNamespace.Capability, "manage-permissions", RbacAccessType.Capability, "" diff --git a/src/SelfService.Tests/Infrastructure/Api/KafkaTopicRoutes/when_deleting_a_public_kafka_topic_as_cloud_engineer.cs b/src/SelfService.Tests/Infrastructure/Api/KafkaTopicRoutes/when_deleting_a_public_kafka_topic_as_cloud_engineer.cs index a52f2a32..2133f9d6 100644 --- a/src/SelfService.Tests/Infrastructure/Api/KafkaTopicRoutes/when_deleting_a_public_kafka_topic_as_cloud_engineer.cs +++ b/src/SelfService.Tests/Infrastructure/Api/KafkaTopicRoutes/when_deleting_a_public_kafka_topic_as_cloud_engineer.cs @@ -26,15 +26,15 @@ public async Task InitializeAsync() AssignedEntityType.User, "foo@bar.com", RbacNamespace.Topics, - "delete", + "delete-public", RbacAccessType.Capability, "foo" ), RbacPermissionGrant.New( AssignedEntityType.User, "foo@bar.com", - RbacNamespace.TopicsPublic, - "delete", + RbacNamespace.Topics, + "delete-public", RbacAccessType.Capability, "foo" ), diff --git a/src/SelfService.Tests/Infrastructure/Api/KafkaTopicRoutes/when_getting_public_topics_as_a_cloud_engineer.cs b/src/SelfService.Tests/Infrastructure/Api/KafkaTopicRoutes/when_getting_public_topics_as_a_cloud_engineer.cs index 2242a21d..013f9ebd 100644 --- a/src/SelfService.Tests/Infrastructure/Api/KafkaTopicRoutes/when_getting_public_topics_as_a_cloud_engineer.cs +++ b/src/SelfService.Tests/Infrastructure/Api/KafkaTopicRoutes/when_getting_public_topics_as_a_cloud_engineer.cs @@ -54,15 +54,15 @@ public async Task InitializeAsync() AssignedEntityType.User, "foo@bar.com", RbacNamespace.Topics, - "delete", + "delete-public", RbacAccessType.Global, "*" ), RbacPermissionGrant.New( AssignedEntityType.User, "foo@bar.com", - RbacNamespace.TopicsPublic, - "delete", + RbacNamespace.Topics, + "delete-public", RbacAccessType.Global, "*" ), diff --git a/src/SelfService.Tests/Infrastructure/Api/MembershipApplicationRoutes/when_getting_membership_application_approvals_as_approver.cs b/src/SelfService.Tests/Infrastructure/Api/MembershipApplicationRoutes/when_getting_membership_application_approvals_as_approver.cs index 6c84cdc8..34aba00c 100644 --- a/src/SelfService.Tests/Infrastructure/Api/MembershipApplicationRoutes/when_getting_membership_application_approvals_as_approver.cs +++ b/src/SelfService.Tests/Infrastructure/Api/MembershipApplicationRoutes/when_getting_membership_application_approvals_as_approver.cs @@ -28,7 +28,7 @@ public async Task InitializeAsync() RbacPermissionGrant.New( AssignedEntityType.User, "foo@bar.com", - RbacNamespace.CapabilityMembershipManagement, + RbacNamespace.Capability, "read-requests", RbacAccessType.Capability, "foo" @@ -36,7 +36,7 @@ public async Task InitializeAsync() RbacPermissionGrant.New( AssignedEntityType.User, "foo@bar.com", - RbacNamespace.CapabilityMembershipManagement, + RbacNamespace.Capability, "manage-requests", RbacAccessType.Capability, "foo" diff --git a/src/SelfService.Tests/Infrastructure/Api/MembershipApplicationRoutes/when_getting_membership_application_approvals_as_member.cs b/src/SelfService.Tests/Infrastructure/Api/MembershipApplicationRoutes/when_getting_membership_application_approvals_as_member.cs index 8682b3ee..631e3056 100644 --- a/src/SelfService.Tests/Infrastructure/Api/MembershipApplicationRoutes/when_getting_membership_application_approvals_as_member.cs +++ b/src/SelfService.Tests/Infrastructure/Api/MembershipApplicationRoutes/when_getting_membership_application_approvals_as_member.cs @@ -29,7 +29,7 @@ public async Task InitializeAsync() RbacPermissionGrant.New( AssignedEntityType.User, "foo@bar.com", - RbacNamespace.CapabilityMembershipManagement, + RbacNamespace.Capability, "read-requests", RbacAccessType.Capability, "foo" @@ -37,7 +37,7 @@ public async Task InitializeAsync() RbacPermissionGrant.New( AssignedEntityType.User, "foo@bar.com", - RbacNamespace.CapabilityMembershipManagement, + RbacNamespace.Capability, "manage-requests", RbacAccessType.Capability, "foo" diff --git a/src/SelfService.Tests/Infrastructure/Api/MembershipApplicationRoutes/when_getting_membership_application_for_applicant.cs b/src/SelfService.Tests/Infrastructure/Api/MembershipApplicationRoutes/when_getting_membership_application_for_applicant.cs index 6c1e1070..be91544e 100644 --- a/src/SelfService.Tests/Infrastructure/Api/MembershipApplicationRoutes/when_getting_membership_application_for_applicant.cs +++ b/src/SelfService.Tests/Infrastructure/Api/MembershipApplicationRoutes/when_getting_membership_application_for_applicant.cs @@ -31,7 +31,7 @@ public async Task InitializeAsync() RbacPermissionGrant.New( AssignedEntityType.User, "foo@bar.com", - RbacNamespace.CapabilityMembershipManagement, + RbacNamespace.Capability, "read-requests", RbacAccessType.Capability, "foo" diff --git a/src/SelfService.Tests/Infrastructure/Api/MembershipApplicationRoutes/when_getting_membership_application_for_approver_that_has_NOT_approved.cs b/src/SelfService.Tests/Infrastructure/Api/MembershipApplicationRoutes/when_getting_membership_application_for_approver_that_has_NOT_approved.cs index 6b289ace..0d6afc71 100644 --- a/src/SelfService.Tests/Infrastructure/Api/MembershipApplicationRoutes/when_getting_membership_application_for_approver_that_has_NOT_approved.cs +++ b/src/SelfService.Tests/Infrastructure/Api/MembershipApplicationRoutes/when_getting_membership_application_for_approver_that_has_NOT_approved.cs @@ -30,7 +30,7 @@ public async Task InitializeAsync() RbacPermissionGrant.New( AssignedEntityType.User, "foo@bar.com", - RbacNamespace.CapabilityMembershipManagement, + RbacNamespace.Capability, "read-requests", RbacAccessType.Capability, "foo" @@ -38,7 +38,7 @@ public async Task InitializeAsync() RbacPermissionGrant.New( AssignedEntityType.User, "foo@bar.com", - RbacNamespace.CapabilityMembershipManagement, + RbacNamespace.Capability, "manage-requests", RbacAccessType.Capability, "foo" diff --git a/src/SelfService.Tests/Infrastructure/Api/MembershipApplicationRoutes/when_getting_membership_application_for_approver_that_has_approved.cs b/src/SelfService.Tests/Infrastructure/Api/MembershipApplicationRoutes/when_getting_membership_application_for_approver_that_has_approved.cs index bdc912d2..4ec31be7 100644 --- a/src/SelfService.Tests/Infrastructure/Api/MembershipApplicationRoutes/when_getting_membership_application_for_approver_that_has_approved.cs +++ b/src/SelfService.Tests/Infrastructure/Api/MembershipApplicationRoutes/when_getting_membership_application_for_approver_that_has_approved.cs @@ -28,7 +28,7 @@ public async Task InitializeAsync() RbacPermissionGrant.New( AssignedEntityType.User, "foo@bar.com", - RbacNamespace.CapabilityMembershipManagement, + RbacNamespace.Capability, "read-requests", RbacAccessType.Capability, "foo" @@ -36,7 +36,7 @@ public async Task InitializeAsync() RbacPermissionGrant.New( AssignedEntityType.User, "foo@bar.com", - RbacNamespace.CapabilityMembershipManagement, + RbacNamespace.Capability, "manage-requests", RbacAccessType.Capability, "foo" diff --git a/src/SelfService.Tests/Infrastructure/Api/TestCapabilityAwsAccountRoutes.cs b/src/SelfService.Tests/Infrastructure/Api/TestCapabilityAwsAccountRoutes.cs index 48cb30b4..3a44c2b9 100644 --- a/src/SelfService.Tests/Infrastructure/Api/TestCapabilityAwsAccountRoutes.cs +++ b/src/SelfService.Tests/Infrastructure/Api/TestCapabilityAwsAccountRoutes.cs @@ -133,7 +133,7 @@ public async Task get_capability_by_id_returns_expected_allow_on_aws_account_lin RbacPermissionGrant.New( AssignedEntityType.User, "foo@bar.com", - RbacNamespace.CapabilityManagement, + RbacNamespace.Capability, "read", RbacAccessType.Capability, stubCapability.Id.ToString() diff --git a/src/SelfService.Tests/Infrastructure/Api/TestCapabilityMembershipApplicationRoutes.cs b/src/SelfService.Tests/Infrastructure/Api/TestCapabilityMembershipApplicationRoutes.cs index 7983911f..17f90c61 100644 --- a/src/SelfService.Tests/Infrastructure/Api/TestCapabilityMembershipApplicationRoutes.cs +++ b/src/SelfService.Tests/Infrastructure/Api/TestCapabilityMembershipApplicationRoutes.cs @@ -284,7 +284,7 @@ public async Task get_membership_applications_for_a_capability_returns_expected_ RbacPermissionGrant.New( AssignedEntityType.User, "foo@bar.com", - RbacNamespace.CapabilityMembershipManagement, + RbacNamespace.Capability, "read-requests", RbacAccessType.Capability, stubCapability.Id.ToString() @@ -341,7 +341,7 @@ public async Task get_membership_applications_for_a_capability_returns_expected_ RbacPermissionGrant.New( AssignedEntityType.User, "foo@bar.com", - RbacNamespace.CapabilityMembershipManagement, + RbacNamespace.Capability, "read-requests", RbacAccessType.Capability, "foo" @@ -382,7 +382,7 @@ public async Task get_membership_applications_for_a_capability_returns_expected_ RbacPermissionGrant.New( AssignedEntityType.User, "foo@bar.com", - RbacNamespace.CapabilityMembershipManagement, + RbacNamespace.Capability, "read-requests", RbacAccessType.Capability, "foo" @@ -426,7 +426,7 @@ public async Task get_membership_applications_for_a_capability_returns_expected_ RbacPermissionGrant.New( AssignedEntityType.User, "foo@bar.com", - RbacNamespace.CapabilityMembershipManagement, + RbacNamespace.Capability, "read-requests", RbacAccessType.Capability, "foo" diff --git a/src/SelfService.Tests/TestDoubles/StubAuthenticationService.cs b/src/SelfService.Tests/TestDoubles/StubAuthenticationService.cs index e402d2e0..7b4bbf94 100644 --- a/src/SelfService.Tests/TestDoubles/StubAuthenticationService.cs +++ b/src/SelfService.Tests/TestDoubles/StubAuthenticationService.cs @@ -224,6 +224,11 @@ public bool CanDeleteDemoRecording(PortalUser portalUser) return _authorized; } + public bool CanReadDemoSignups(PortalUser portalUser) + { + return _authorized; + } + public bool IsAuthorizedToCreateReleaseNotes(PortalUser portalUser) { return _authorized; diff --git a/src/SelfService/Application/RbacApplicationService.cs b/src/SelfService/Application/RbacApplicationService.cs index 73e65855..34cb7562 100644 --- a/src/SelfService/Application/RbacApplicationService.cs +++ b/src/SelfService/Application/RbacApplicationService.cs @@ -3,6 +3,7 @@ using SelfService.Domain.Exceptions; using SelfService.Domain.Models; using SelfService.Domain.Queries; +using SelfService.Infrastructure.Api; using SelfService.Infrastructure.Persistence; namespace SelfService.Application; @@ -15,6 +16,7 @@ public class RbacApplicationService : IRbacApplicationService private readonly IRbacGroupRepository _groupRepository; private readonly IPermissionQuery _permissionQuery; private readonly IRbacRoleRepository _roleRepository; + private readonly IHttpContextAccessor _httpContextAccessor; private readonly RbacCache _cache; public RbacApplicationService( @@ -23,7 +25,8 @@ public RbacApplicationService( IRbacGroupMemberRepository groupMemberRepository, IRbacGroupRepository groupRepository, IPermissionQuery permissionQuery, - IRbacRoleRepository roleRepository + IRbacRoleRepository roleRepository, + IHttpContextAccessor httpContextAccessor ) { _permissionGrantRepository = permissionGrantRepository; @@ -32,13 +35,21 @@ IRbacRoleRepository roleRepository _groupRepository = groupRepository; _permissionQuery = permissionQuery; _roleRepository = roleRepository; + _httpContextAccessor = httpContextAccessor; _cache = new RbacCache(); } public async Task IsUserPermitted(string user, List permissions, string objectId) { var resp = new PermittedResponse(); - permissions.ForEach(p => resp.PermissionMatrix.TryAdd($"{p.Namespace}-{p.Name}", new PermissionMatrix(p))); + permissions.ForEach(p => + { + var key = $"{p.Namespace}-{p.Name}"; + if (!resp.PermissionMatrix.ContainsKey(key)) + { + resp.PermissionMatrix[key] = new PermissionMatrix(p); + } + }); // user level var userPermissions = await GetPermissionGrantsForUser(user); @@ -59,6 +70,14 @@ public async Task IsUserPermitted(string user, List permission.Type != RbacAccessType.Global) + .ToList(); + combinedRoles = combinedRoles.Where(role => role.Type != RbacAccessType.Global).ToList(); + } + // If the user has no explicit capability role for this resource, apply Guest role permissions as default var isCapabilityCheck = permissions.Any(p => p.AccessType == RbacAccessType.Capability); if ( @@ -125,6 +144,13 @@ bool Evaluate(RbacPermissionGrant p) return resp; } + private bool ReducedPermissionsRequested() + { + return _httpContextAccessor.HttpContext?.Items.ContainsKey( + ReducedPermissionsMiddleware.ReducedPermissionsContextKey + ) == true; + } + public async Task> GetPermissionGrantsForRoleGrants(List roleGrants) { var payload = new List(); @@ -296,21 +322,13 @@ public async Task> GetAssignableRoles() [TransactionalBoundary] public async Task GrantPermission(string user, RbacPermissionGrant permissionGrant) { - //PermittedResponse? canUserCreateGlobalRbac; switch (permissionGrant.Type) { case var a when a == RbacAccessType.Global: - /* - canUserCreateGlobalRbac = await IsUserPermitted( - user, - new List { new(RbacNamespace.Rbac, "create", "", RbacAccessType.Global) }, - permissionGrant.Resource ?? "" - ); - if (!canUserCreateGlobalRbac.Permitted()) + if (!await HasGlobalPermission(user, RbacNamespace.Rbac, "create")) { throw new UnauthorizedAccessException(); } - */ await _permissionGrantRepository.Add( RbacPermissionGrant.New( permissionGrant.AssignedEntityType, @@ -324,26 +342,11 @@ await _permissionGrantRepository.Add( break; case var a when a == RbacAccessType.Capability: - /* - canUserCreateGlobalRbac = await IsUserPermitted( - user, - new List { new(RbacNamespace.Rbac, "create", "", RbacAccessType.Global) }, - permissionGrant.Resource ?? "" - ); - var canUserCreateCapabilityRbac = await IsUserPermitted( - user, - new List - { - new(RbacNamespace.CapabilityManagement, "manage-permissions", "", RbacAccessType.Capability), - }, - permissionGrant.Resource ?? "" - ); - - if (!canUserCreateGlobalRbac.Permitted() && !canUserCreateCapabilityRbac.Permitted()) + if (!await HasCapabilityManagePermissions(user, permissionGrant.Resource ?? "")) { throw new UnauthorizedAccessException(); } - */ + await _permissionGrantRepository.Add( RbacPermissionGrant.New( permissionGrant.AssignedEntityType, @@ -385,17 +388,10 @@ public async Task RevokePermission(string user, string id) if (permissionLookup == null) throw new Exception("Permission grant not found"); - PermittedResponse? canUserCreateGlobalRbac; switch (permissionLookup.Type) { case var a when a == RbacAccessType.Global: - - canUserCreateGlobalRbac = await IsUserPermitted( - user, - new List { new(RbacNamespace.Rbac, "delete", "", RbacAccessType.Global) }, - permissionLookup.Resource ?? "" - ); - if (!canUserCreateGlobalRbac.Permitted()) + if (!await HasGlobalPermission(user, RbacNamespace.Rbac, "delete")) { throw new UnauthorizedAccessException(); } @@ -403,24 +399,11 @@ public async Task RevokePermission(string user, string id) await _permissionGrantRepository.Remove(permissionLookup.Id); break; case var a when a == RbacAccessType.Capability: - canUserCreateGlobalRbac = await IsUserPermitted( - user, - new List { new(RbacNamespace.Rbac, "delete", "", RbacAccessType.Global) }, - permissionLookup.Resource ?? "" - ); - var canUserCreateCapabilityRbac = await IsUserPermitted( - user, - new List - { - new(RbacNamespace.CapabilityManagement, "manage-permissions", "", RbacAccessType.Capability), - }, - permissionLookup.Resource ?? "" - ); - - if (!canUserCreateGlobalRbac.Permitted() && !canUserCreateCapabilityRbac.Permitted()) + if (!await HasCapabilityManagePermissions(user, permissionLookup.Resource ?? "")) { throw new UnauthorizedAccessException(); } + await _permissionGrantRepository.Remove(permissionLookup.Id); break; default: @@ -456,6 +439,25 @@ private async Task HasGlobalPermission(string user, RbacNamespace ns, stri ); } + private async Task HasCapabilityManagePermissions(string user, string capabilityId) + { + if (string.IsNullOrWhiteSpace(capabilityId)) + { + return false; + } + + return ( + await IsUserPermitted( + user, + new List + { + new(RbacNamespace.Capability, "manage-permissions", "", RbacAccessType.Capability), + }, + capabilityId + ) + ).Permitted(); + } + [TransactionalBoundary] public async Task GrantRoleGrant(string user, RbacRoleGrant roleGrant, bool userInitiated = false) { @@ -470,21 +472,7 @@ public async Task GrantRoleGrant(string user, RbacRoleGrant roleGrant, bool user throw new UnauthorizedAccessException(); } - var canManage = ( - await IsUserPermitted( - user, - new List - { - new( - RbacNamespace.CapabilityManagement, - "manage-permissions", - "", - RbacAccessType.Capability - ), - }, - roleGrant.Resource ?? "" - ) - ).Permitted(); + var canManage = await HasCapabilityManagePermissions(user, roleGrant.Resource ?? ""); var userGrantsToSelf = roleGrant.AssignedEntityType == AssignedEntityType.User @@ -571,17 +559,10 @@ public async Task> GrantRoleGrants(string user, L if (roleGrant == null) throw new Exception("Role grant not found"); - PermittedResponse? canUserDeleteGlobalRbac; switch (roleGrant.Type) { case var a when a == RbacAccessType.Global: - - canUserDeleteGlobalRbac = await IsUserPermitted( - user, - new List { new(RbacNamespace.Rbac, "delete", "", RbacAccessType.Global) }, - roleGrant.Resource ?? "" - ); - if (!canUserDeleteGlobalRbac.Permitted()) + if (!await HasGlobalPermission(user, RbacNamespace.Rbac, "delete")) { throw new UnauthorizedAccessException(); } @@ -589,25 +570,11 @@ public async Task> GrantRoleGrants(string user, L await _roleGrantRepository.Remove(roleGrant.Id); break; case var a when a == RbacAccessType.Capability: - - canUserDeleteGlobalRbac = await IsUserPermitted( - user, - new List { new(RbacNamespace.Rbac, "delete", "", RbacAccessType.Global) }, - roleGrant.Resource ?? "" - ); - var canUserDeleteCapabilityRbac = await IsUserPermitted( - user, - new List - { - new(RbacNamespace.CapabilityManagement, "manage-permissions", "", RbacAccessType.Capability), - }, - roleGrant.Resource ?? "" - ); - - if (!canUserDeleteGlobalRbac.Permitted() && !canUserDeleteCapabilityRbac.Permitted()) + if (!await HasCapabilityManagePermissions(user, roleGrant.Resource ?? "")) { throw new UnauthorizedAccessException(); } + await _roleGrantRepository.Remove(roleGrant.Id); break; default: @@ -634,17 +601,10 @@ public async Task RevokeCapabilityRoleGrant(UserId userId, CapabilityId capabili [TransactionalBoundary] public async Task CreateRole(string user, RbacRole role) { - /* - var canUserCreateGlobalRbac = await IsUserPermitted( - user, - new List { new(RbacNamespace.Rbac, "create", "", RbacAccessType.Global) }, - "" - ); - if (!canUserCreateGlobalRbac.Permitted()) + if (!await HasGlobalPermission(user, RbacNamespace.Rbac, "create")) { throw new UnauthorizedAccessException(); } - */ var newRole = RbacRole.New( ownerId: role.OwnerId, @@ -668,12 +628,7 @@ public async Task> GetSystemGroups() public async Task DeleteRole(string user, string roleId) { _cache.Reset(); - var canUserDeleteGlobalRbac = await IsUserPermitted( - user, - new List { new(RbacNamespace.Rbac, "delete", "", RbacAccessType.Global) }, - "" - ); - if (!canUserDeleteGlobalRbac.Permitted()) + if (!await HasGlobalPermission(user, RbacNamespace.Rbac, "delete")) { throw new UnauthorizedAccessException(); } @@ -689,17 +644,10 @@ public async Task DeleteRole(string user, string roleId) [TransactionalBoundary] public async Task CreateGroup(string user, RbacGroup group) { - /* - var canUserCreateGlobalRbac = await IsUserPermitted( - user, - new List { new(RbacNamespace.Rbac, "create", "", RbacAccessType.Global) }, - "" - ); - if (!canUserCreateGlobalRbac.Permitted()) + if (!await HasGlobalPermission(user, RbacNamespace.Rbac, "create")) { throw new UnauthorizedAccessException(); } - */ var newGroup = RbacGroup.New(name: group.Name, description: group.Description, members: group.Members); await _groupRepository.Add(newGroup); @@ -711,12 +659,7 @@ public async Task CreateGroup(string user, RbacGroup group) public async Task DeleteGroup(string user, string groupId) { _cache.Reset(); - var canUserDeleteGlobalRbac = await IsUserPermitted( - user, - new List { new(RbacNamespace.Rbac, "delete", "", RbacAccessType.Global) }, - "" - ); - if (!canUserDeleteGlobalRbac.Permitted()) + if (!await HasGlobalPermission(user, RbacNamespace.Rbac, "delete")) { throw new UnauthorizedAccessException(); } @@ -731,17 +674,10 @@ public async Task DeleteGroup(string user, string groupId) [TransactionalBoundary] public async Task GrantGroupGrant(string user, RbacGroupMember membership) { - /* - var canUserCreateGlobalRbac = await IsUserPermitted( - user, - new List { new(RbacNamespace.Rbac, "create", "", RbacAccessType.Global) }, - "" - ); - if (!canUserCreateGlobalRbac.Permitted()) + if (!await HasGlobalPermission(user, RbacNamespace.Rbac, "create")) { throw new UnauthorizedAccessException(); } - */ var group = await _groupRepository.FindById(RbacGroupId.Parse(membership.GroupId)); if (group == null) @@ -758,12 +694,7 @@ public async Task GrantGroupGrant(string user, RbacGroupMember public async Task RevokeGroupGrant(string user, RbacGroupMember membership) { _cache.Reset(); - var canUserDeleteGlobalRbac = await IsUserPermitted( - user, - new List { new(RbacNamespace.Rbac, "delete", "", RbacAccessType.Global) }, - "" - ); - if (!canUserDeleteGlobalRbac.Permitted()) + if (!await HasGlobalPermission(user, RbacNamespace.Rbac, "delete")) { throw new UnauthorizedAccessException(); } @@ -795,9 +726,9 @@ public async Task CanModifyCapabilityRbac(string user, string id) { new() { - Namespace = RbacNamespace.CapabilityManagement, + Namespace = RbacNamespace.Capability, Name = "manage-permissions", - AccessType = RbacAccessType.Global, + AccessType = RbacAccessType.Capability, }, new() { @@ -865,48 +796,34 @@ public static List BootstrapPermissions() new(RbacNamespace.Topics, "read-public", "Read public topics", RbacAccessType.Capability), new(RbacNamespace.Topics, "update", "Update topics", RbacAccessType.Capability), new(RbacNamespace.Topics, "delete", "Delete topics", RbacAccessType.Capability), - new(RbacNamespace.CapabilityManagement, "receive-alerts", "Receive Alarms", RbacAccessType.Capability), - new( - RbacNamespace.CapabilityManagement, - "receive-cost", - "Receive cost summary reports", - RbacAccessType.Capability - ), + new(RbacNamespace.Topics, "delete-public", "Delete public topics", RbacAccessType.Capability), + new(RbacNamespace.Capability, "receive-alerts", "Receive Alarms", RbacAccessType.Capability), + new(RbacNamespace.Capability, "receive-cost", "Receive cost summary reports", RbacAccessType.Capability), + new(RbacNamespace.Capability, "request-deletion", "Request Capability deletion", RbacAccessType.Capability), new( - RbacNamespace.CapabilityManagement, - "request-deletion", - "Request Capability deletion", - RbacAccessType.Capability - ), - new( - RbacNamespace.CapabilityManagement, + RbacNamespace.Capability, "manage-permissions", "Manage Capability permissions", RbacAccessType.Capability ), + new(RbacNamespace.Capability, "read-self-assess", "Self assessment permissions", RbacAccessType.Capability), new( - RbacNamespace.CapabilityManagement, - "read-self-assess", - "Self assessment permissions", - RbacAccessType.Capability - ), - new( - RbacNamespace.CapabilityManagement, + RbacNamespace.Capability, "create-self-assess", "Self assessment permissions", RbacAccessType.Capability ), - new(RbacNamespace.CapabilityMembershipManagement, "create", "Invite new member", RbacAccessType.Capability), - new(RbacNamespace.CapabilityMembershipManagement, "delete", "Remove member", RbacAccessType.Capability), - new(RbacNamespace.CapabilityMembershipManagement, "read", "See member list", RbacAccessType.Capability), + new(RbacNamespace.Capability, "invite-member", "Invite new member", RbacAccessType.Capability), + new(RbacNamespace.Capability, "remove-member", "Remove member", RbacAccessType.Capability), + new(RbacNamespace.Capability, "read-members", "See member list", RbacAccessType.Capability), new( - RbacNamespace.CapabilityMembershipManagement, + RbacNamespace.Capability, "read-requests", "Read invitation/application requests", RbacAccessType.Capability ), new( - RbacNamespace.CapabilityMembershipManagement, + RbacNamespace.Capability, "manage-requests", "Approve/decline member requests", RbacAccessType.Capability @@ -917,8 +834,8 @@ public static List BootstrapPermissions() new(RbacNamespace.TagsAndMetadata, "delete", "Delete", RbacAccessType.Capability), new(RbacNamespace.Aws, "create", "Create context/cloud resources", RbacAccessType.Capability), new(RbacNamespace.Aws, "read", "Read context/cloud resources", RbacAccessType.Capability), - new(RbacNamespace.Aws, "manage-provider", "Read resources in AWS account", RbacAccessType.Capability), - new(RbacNamespace.Aws, "read-provider", "Manage resources in AWS account", RbacAccessType.Capability), + new(RbacNamespace.Aws, "manage-provider", "Manage resources in AWS account", RbacAccessType.Capability), + new(RbacNamespace.Aws, "read-provider", "Read resources in AWS account", RbacAccessType.Capability), new(RbacNamespace.Finout, "read-dashboards", "See all DFDS dashboards", RbacAccessType.Global), new( RbacNamespace.Finout, @@ -964,21 +881,16 @@ public static List BootstrapPermissions() RbacAccessType.Global ), new( - RbacNamespace.SystemAdmin, + RbacNamespace.Capability, "view-deleted-capabilities", "View deleted capabilities", RbacAccessType.Global ), - new(RbacNamespace.SystemAdmin, "unset-capability-tags", "Unset capability tags", RbacAccessType.Global), - new(RbacNamespace.SystemAdmin, "create-demo-recording", "Create demo recordings", RbacAccessType.Global), - new(RbacNamespace.SystemAdmin, "update-demo-recording", "Update demo recordings", RbacAccessType.Global), - new(RbacNamespace.SystemAdmin, "delete-demo-recording", "Delete demo recordings", RbacAccessType.Global), - new( - RbacNamespace.SystemAdmin, - "manage-permission-matrix", - "Manage permission matrix", - RbacAccessType.Global - ), + new(RbacNamespace.Capability, "unset-capability-tags", "Unset capability tags", RbacAccessType.Global), + new(RbacNamespace.Demos, "create", "Create demo recordings", RbacAccessType.Global), + new(RbacNamespace.Demos, "update", "Update demo recordings", RbacAccessType.Global), + new(RbacNamespace.Demos, "delete", "Delete demo recordings", RbacAccessType.Global), + new(RbacNamespace.Demos, "read-signups", "Read demo signups", RbacAccessType.Global), new( RbacNamespace.SystemAdmin, "synchronize-aws-ecr-and-database-ecr", @@ -986,53 +898,53 @@ public static List BootstrapPermissions() RbacAccessType.Global ), new( - RbacNamespace.SystemAdmin, + RbacNamespace.Capability, "bypass-membership-approvals", "Bypass membership approvals", RbacAccessType.Global ), new( - RbacNamespace.SystemAdmin, + RbacNamespace.SelfAssessment, "manage-self-assessment-options", "Manage self-assessment options", RbacAccessType.Global ), - new(RbacNamespace.SystemAdmin, "create-release-notes", "Create release notes", RbacAccessType.Global), - new(RbacNamespace.SystemAdmin, "update-release-note", "Update release note", RbacAccessType.Global), + new(RbacNamespace.ReleaseNotes, "create", "Create release notes", RbacAccessType.Global), + new(RbacNamespace.ReleaseNotes, "update", "Update release note", RbacAccessType.Global), new( - RbacNamespace.SystemAdmin, + RbacNamespace.ReleaseNotes, "toggle-release-note-is-active", "Toggle release note active state", RbacAccessType.Global ), new( - RbacNamespace.SystemAdmin, + RbacNamespace.ReleaseNotes, "list-draft-release-notes", "List draft release notes", RbacAccessType.Global ), - new(RbacNamespace.SystemAdmin, "remove-release-note", "Remove release note", RbacAccessType.Global), - new(RbacNamespace.SystemAdmin, "create-event", "Create events", RbacAccessType.Global), - new(RbacNamespace.SystemAdmin, "update-event", "Update events", RbacAccessType.Global), - new(RbacNamespace.SystemAdmin, "delete-event", "Delete events", RbacAccessType.Global), - new(RbacNamespace.SystemAdmin, "create-news-item", "Create news items", RbacAccessType.Global), - new(RbacNamespace.SystemAdmin, "update-news-item", "Update news items", RbacAccessType.Global), - new(RbacNamespace.SystemAdmin, "delete-news-item", "Delete news items", RbacAccessType.Global), - new(RbacNamespace.SystemAdmin, "get-user-emails", "Get user emails", RbacAccessType.Global), + new(RbacNamespace.ReleaseNotes, "delete", "Remove release note", RbacAccessType.Global), + new(RbacNamespace.Events, "create", "Create events", RbacAccessType.Global), + new(RbacNamespace.Events, "update", "Update events", RbacAccessType.Global), + new(RbacNamespace.Events, "delete", "Delete events", RbacAccessType.Global), + new(RbacNamespace.News, "create", "Create news items", RbacAccessType.Global), + new(RbacNamespace.News, "update", "Update news items", RbacAccessType.Global), + new(RbacNamespace.News, "delete", "Delete news items", RbacAccessType.Global), + new(RbacNamespace.Users, "read", "Get user emails", RbacAccessType.Global), new( - RbacNamespace.CapabilityManagement, - "batch-create-capabilities", - "Create capabilities in batch as administrator", + RbacNamespace.Capability, + "manage-requests", + "Approve/decline member requests across capabilities", RbacAccessType.Global ), new( - RbacNamespace.SystemAdmin, - "delete-membership-application-as-admin", - "Delete membership applications as administrator", + RbacNamespace.Capability, + "batch-create-capabilities", + "Create capabilities in batch as administrator", RbacAccessType.Global ), new( - RbacNamespace.SystemAdmin, + RbacNamespace.Topics, "retry-creating-message-contract", "Retry failed message contract creation as administrator", RbacAccessType.Global diff --git a/src/SelfService/Domain/Models/RbacNamespace.cs b/src/SelfService/Domain/Models/RbacNamespace.cs index d7303654..d5839601 100644 --- a/src/SelfService/Domain/Models/RbacNamespace.cs +++ b/src/SelfService/Domain/Models/RbacNamespace.cs @@ -6,17 +6,20 @@ namespace SelfService.Domain.Models; [JsonConverter(typeof(RbacNamespaceJsonConverter))] public class RbacNamespace : ValueObject { - // topics, capability-management, capability-membership-management, tags-and-metadata, aws, finout, azure, rbac, service-catalogue, system-admin, system-legacy public static readonly RbacNamespace Topics = new("topics"); - public static readonly RbacNamespace TopicsPublic = new("topics-public"); - public static readonly RbacNamespace CapabilityManagement = new("capability-management"); - public static readonly RbacNamespace CapabilityMembershipManagement = new("capability-membership-management"); + public static readonly RbacNamespace Capability = new("capability"); public static readonly RbacNamespace TagsAndMetadata = new("tags-and-metadata"); public static readonly RbacNamespace Aws = new("aws"); public static readonly RbacNamespace Finout = new("finout"); public static readonly RbacNamespace Azure = new("azure"); public static readonly RbacNamespace Rbac = new("rbac"); public static readonly RbacNamespace ServiceCatalogue = new("service-catalogue"); + public static readonly RbacNamespace Demos = new("demos"); + public static readonly RbacNamespace ReleaseNotes = new("release-notes"); + public static readonly RbacNamespace Events = new("events"); + public static readonly RbacNamespace News = new("news"); + public static readonly RbacNamespace Users = new("users"); + public static readonly RbacNamespace SelfAssessment = new("self-assessment"); public static readonly RbacNamespace SystemAdmin = new("system-admin"); public static readonly RbacNamespace SystemLegacy = new("system-legacy"); @@ -57,14 +60,8 @@ public static bool TryParse(string input, out RbacNamespace rbacNamespace) case "topics": rbacNamespace = Topics; break; - case "topics-public": - rbacNamespace = TopicsPublic; - break; - case "capability-management": - rbacNamespace = CapabilityManagement; - break; - case "capability-membership-management": - rbacNamespace = CapabilityMembershipManagement; + case "capability": + rbacNamespace = Capability; break; case "tags-and-metadata": rbacNamespace = TagsAndMetadata; @@ -84,6 +81,24 @@ public static bool TryParse(string input, out RbacNamespace rbacNamespace) case "service-catalogue": rbacNamespace = ServiceCatalogue; break; + case "demos": + rbacNamespace = Demos; + break; + case "release-notes": + rbacNamespace = ReleaseNotes; + break; + case "events": + rbacNamespace = Events; + break; + case "news": + rbacNamespace = News; + break; + case "users": + rbacNamespace = Users; + break; + case "self-assessment": + rbacNamespace = SelfAssessment; + break; case "system-admin": rbacNamespace = SystemAdmin; break; diff --git a/src/SelfService/Domain/Services/AuthorizationService.cs b/src/SelfService/Domain/Services/AuthorizationService.cs index 881fe5e4..af6e0e7f 100644 --- a/src/SelfService/Domain/Services/AuthorizationService.cs +++ b/src/SelfService/Domain/Services/AuthorizationService.cs @@ -14,7 +14,6 @@ public class AuthorizationService : IAuthorizationService private readonly IMessageContractRepository _messageContractRepository; private readonly IKafkaTopicRepository _kafkaTopicRepository; private readonly IMembershipApplicationRepository _membershipApplicationRepository; - private readonly IHttpContextAccessor _httpContextAccessor; private readonly IRbacApplicationService _rbacApplicationService; public AuthorizationService( @@ -26,7 +25,6 @@ public AuthorizationService( IMessageContractRepository messageContractRepository, IKafkaTopicRepository kafkaTopicRepository, IMembershipApplicationRepository membershipApplicationRepository, - IHttpContextAccessor httpContextAccessor, IRbacApplicationService rbacApplicationService ) { @@ -39,7 +37,6 @@ IRbacApplicationService rbacApplicationService _messageContractRepository = messageContractRepository; _kafkaTopicRepository = kafkaTopicRepository; _membershipApplicationRepository = membershipApplicationRepository; - _httpContextAccessor = httpContextAccessor; } public async Task CanAddTopic(UserId userId, CapabilityId capabilityId, KafkaClusterId clusterId) @@ -91,8 +88,8 @@ public async Task CanDeleteTopic(PortalUser portalUser, KafkaTopic kafkaTo return await HasPermission( portalUser.Id, RbacAccessType.Capability, - RbacNamespace.TopicsPublic, - "delete", + RbacNamespace.Topics, + "delete-public", kafkaTopic.CapabilityId ); } @@ -108,40 +105,32 @@ public async Task CanDeleteTopic(PortalUser portalUser, KafkaTopic kafkaTo public bool CanViewDeletedCapabilities(PortalUser portalUser) { - return IsCloudEngineerEnabled(portalUser, "view-deleted-capabilities"); + return HasPermission(portalUser, RbacAccessType.Global, RbacNamespace.Capability, "view-deleted-capabilities"); } public bool CanUnsetCapabilityTags(PortalUser portalUser) { - return IsCloudEngineerEnabled(portalUser, "unset-capability-tags"); + return HasPermission(portalUser, RbacAccessType.Global, RbacNamespace.Capability, "unset-capability-tags"); } public bool CanCreateDemoRecording(PortalUser portalUser) { - return IsCloudEngineerEnabled(portalUser, "create-demo-recording"); + return HasPermission(portalUser, RbacAccessType.Global, RbacNamespace.Demos, "create"); } public bool CanUpdateDemoRecording(PortalUser portalUser) { - return IsCloudEngineerEnabled(portalUser, "update-demo-recording"); + return HasPermission(portalUser, RbacAccessType.Global, RbacNamespace.Demos, "update"); } public bool CanDeleteDemoRecording(PortalUser portalUser) { - return IsCloudEngineerEnabled(portalUser, "delete-demo-recording"); + return HasPermission(portalUser, RbacAccessType.Global, RbacNamespace.Demos, "delete"); } - private bool IsCloudEngineerEnabled(PortalUser portalUser, string permissionName) + public bool CanReadDemoSignups(PortalUser portalUser) { - if ( - _httpContextAccessor.HttpContext != null - && _httpContextAccessor.HttpContext.Items.ContainsKey("userPermissions") - ) - { - return false; - } - - return HasPermission(portalUser, RbacAccessType.Global, RbacNamespace.SystemAdmin, permissionName); + return HasPermission(portalUser, RbacAccessType.Global, RbacNamespace.Demos, "read-signups"); } private bool HasPermission( @@ -180,21 +169,30 @@ private async Task HasPermission( string resourceId = "" ) { - return ( - await _rbacApplicationService.IsUserPermitted( - userId, - new List + var permissionsToCheck = new List + { + new() + { + Namespace = permissionNamespace, + Name = permissionName, + AccessType = scope, + }, + }; + + // Any non-global scope should also be satisfied by equivalent global grants. + if (scope != RbacAccessType.Global) + { + permissionsToCheck.Add( + new() { - new() - { - Namespace = permissionNamespace, - Name = permissionName, - AccessType = scope, - }, - }, - resourceId - ) - ).Permitted(); + Namespace = permissionNamespace, + Name = permissionName, + AccessType = RbacAccessType.Global, + } + ); + } + + return (await _rbacApplicationService.IsUserPermitted(userId, permissionsToCheck, resourceId)).Permitted(); } public async Task CanReadConsumers(PortalUser portalUser, KafkaTopic kafkaTopic) @@ -260,7 +258,7 @@ public async Task CanReadMembershipApplications(UserId userId, MembershipA var hasReadRequestsPermission = await HasPermission( userId, RbacAccessType.Capability, - RbacNamespace.CapabilityMembershipManagement, + RbacNamespace.Capability, "read-requests", application.CapabilityId ); @@ -273,7 +271,7 @@ public async Task CanApproveMembershipApplications(UserId userId, Membersh return await HasPermission( userId, RbacAccessType.Capability, - RbacNamespace.CapabilityMembershipManagement, + RbacNamespace.Capability, "manage-requests", application.CapabilityId ); @@ -284,7 +282,7 @@ public async Task CanApproveMembershipApplications(UserId userId, Capabili return await HasPermission( userId, RbacAccessType.Capability, - RbacNamespace.CapabilityMembershipManagement, + RbacNamespace.Capability, "manage-requests", capabilityId ); @@ -395,7 +393,7 @@ public async Task CanViewAllApplications(UserId userId, CapabilityId capab return await HasPermission( userId, RbacAccessType.Capability, - RbacNamespace.CapabilityMembershipManagement, + RbacNamespace.Capability, "read-requests", capabilityId ); @@ -406,7 +404,7 @@ public async Task CanDeleteCapability(UserId userId, CapabilityId capabili return await HasPermission( userId, RbacAccessType.Capability, - RbacNamespace.CapabilityManagement, + RbacNamespace.Capability, "request-deletion", capabilityId ); @@ -414,12 +412,17 @@ public async Task CanDeleteCapability(UserId userId, CapabilityId capabili public bool CanManagePermissionMatrix(PortalUser portalUser) { - return IsCloudEngineerEnabled(portalUser, "manage-permission-matrix"); + return HasPermission(portalUser, RbacAccessType.Global, RbacNamespace.Rbac, "update"); } public bool CanSynchronizeAwsECRAndDatabaseECR(PortalUser portalUser) { - return IsCloudEngineerEnabled(portalUser, "synchronize-aws-ecr-and-database-ecr"); + return HasPermission( + portalUser, + RbacAccessType.Global, + RbacNamespace.SystemAdmin, + "synchronize-aws-ecr-and-database-ecr" + ); } public async Task CanGetCapabilityJsonMetadata(PortalUser portalUser, CapabilityId capabilityId) @@ -457,20 +460,20 @@ public async Task CanSetCapabilityJsonMetadata(PortalUser portalUser, Capa } public bool CanBypassMembershipApprovals(PortalUser portalUser) - { - return IsCloudEngineerEnabled(portalUser, "bypass-membership-approvals"); - } - - public bool CanBatchCreateCapabilities(PortalUser portalUser) { return HasPermission( portalUser, RbacAccessType.Global, - RbacNamespace.CapabilityManagement, - "batch-create-capabilities" + RbacNamespace.Capability, + "bypass-membership-approvals" ); } + public bool CanBatchCreateCapabilities(PortalUser portalUser) + { + return HasPermission(portalUser, RbacAccessType.Global, RbacNamespace.Capability, "batch-create-capabilities"); + } + public async Task CanDeleteMembershipApplication( PortalUser portalUser, UserId userId, @@ -481,15 +484,13 @@ MembershipApplicationId membershipApplicationId var hasPermission = await HasPermission( portalUser.Id, RbacAccessType.Capability, - RbacNamespace.CapabilityMembershipManagement, + RbacNamespace.Capability, "manage-requests", membershipApp.CapabilityId ); var isApplicant = membershipApp.Applicant == userId; - return isApplicant - || hasPermission - || IsCloudEngineerEnabled(portalUser, "delete-membership-application-as-admin"); + return isApplicant || hasPermission; } public async Task CanRemoveMember(UserId requesterId, CapabilityId capabilityId) @@ -497,8 +498,8 @@ public async Task CanRemoveMember(UserId requesterId, CapabilityId capabil return await HasPermission( requesterId, RbacAccessType.Capability, - RbacNamespace.CapabilityMembershipManagement, - "delete", + RbacNamespace.Capability, + "remove-member", capabilityId ); } @@ -508,8 +509,8 @@ public async Task CanInviteToCapability(UserId userId, CapabilityId capabi return await HasPermission( userId, RbacAccessType.Capability, - RbacNamespace.CapabilityMembershipManagement, - "create", + RbacNamespace.Capability, + "invite-member", capabilityId ); } @@ -519,8 +520,8 @@ public async Task CanViewMembershipApplications(UserId userId, CapabilityI return await HasPermission( userId, RbacAccessType.Capability, - RbacNamespace.CapabilityMembershipManagement, - "read", + RbacNamespace.Capability, + "read-requests", capabilityId ); } @@ -545,9 +546,14 @@ public async Task CanRetryCreatingMessageContract(PortalUser portalUser, M "update", kafkaTopic.CapabilityId ); - bool isCloudEngineer = IsCloudEngineerEnabled(portalUser, "retry-creating-message-contract"); + bool hasGlobalRetryPermission = HasPermission( + portalUser, + RbacAccessType.Global, + RbacNamespace.Topics, + "retry-creating-message-contract" + ); - return isCloudEngineer || canCreateMessageContract; + return hasGlobalRetryPermission || canCreateMessageContract; } public async Task CanSelfAssess(UserId userId, CapabilityId capabilityId) @@ -572,66 +578,76 @@ public async Task CanSelfAssess(UserId userId, CapabilityId capabilityId) public bool CanManageSelfAssessmentOptions(PortalUser portalUser) { - return IsCloudEngineerEnabled(portalUser, "manage-self-assessment-options"); + return HasPermission( + portalUser, + RbacAccessType.Global, + RbacNamespace.SelfAssessment, + "manage-self-assessment-options" + ); } public bool IsAuthorizedToCreateReleaseNotes(PortalUser portalUser) { - return IsCloudEngineerEnabled(portalUser, "create-release-notes"); + return HasPermission(portalUser, RbacAccessType.Global, RbacNamespace.ReleaseNotes, "create"); } public bool IsAuthorizedToUpdateReleaseNote(PortalUser portalUser) { - return IsCloudEngineerEnabled(portalUser, "update-release-note"); + return HasPermission(portalUser, RbacAccessType.Global, RbacNamespace.ReleaseNotes, "update"); } public bool IsAuthorizedToToggleReleaseNoteIsActive(PortalUser portalUser) { - return IsCloudEngineerEnabled(portalUser, "toggle-release-note-is-active"); + return HasPermission( + portalUser, + RbacAccessType.Global, + RbacNamespace.ReleaseNotes, + "toggle-release-note-is-active" + ); } public bool IsAuthorizedToListDraftReleaseNotes(PortalUser portalUser) { - return IsCloudEngineerEnabled(portalUser, "list-draft-release-notes"); + return HasPermission(portalUser, RbacAccessType.Global, RbacNamespace.ReleaseNotes, "list-draft-release-notes"); } public bool IsAuthorizedToRemoveReleaseNote(PortalUser portalUser) { - return IsCloudEngineerEnabled(portalUser, "remove-release-note"); + return HasPermission(portalUser, RbacAccessType.Global, RbacNamespace.ReleaseNotes, "delete"); } public bool CanCreateEvent(PortalUser portalUser) { - return IsCloudEngineerEnabled(portalUser, "create-event"); + return HasPermission(portalUser, RbacAccessType.Global, RbacNamespace.Events, "create"); } public bool CanUpdateEvent(PortalUser portalUser) { - return IsCloudEngineerEnabled(portalUser, "update-event"); + return HasPermission(portalUser, RbacAccessType.Global, RbacNamespace.Events, "update"); } public bool CanDeleteEvent(PortalUser portalUser) { - return IsCloudEngineerEnabled(portalUser, "delete-event"); + return HasPermission(portalUser, RbacAccessType.Global, RbacNamespace.Events, "delete"); } public bool CanCreateNewsItem(PortalUser portalUser) { - return IsCloudEngineerEnabled(portalUser, "create-news-item"); + return HasPermission(portalUser, RbacAccessType.Global, RbacNamespace.News, "create"); } public bool CanUpdateNewsItem(PortalUser portalUser) { - return IsCloudEngineerEnabled(portalUser, "update-news-item"); + return HasPermission(portalUser, RbacAccessType.Global, RbacNamespace.News, "update"); } public bool CanDeleteNewsItem(PortalUser portalUser) { - return IsCloudEngineerEnabled(portalUser, "delete-news-item"); + return HasPermission(portalUser, RbacAccessType.Global, RbacNamespace.News, "delete"); } public bool CanGetUserEmails(PortalUser portalUser) { - return IsCloudEngineerEnabled(portalUser, "get-user-emails"); + return HasPermission(portalUser, RbacAccessType.Global, RbacNamespace.Users, "read"); } } diff --git a/src/SelfService/Domain/Services/IAuthorizationService.cs b/src/SelfService/Domain/Services/IAuthorizationService.cs index d8844d0f..b18569a6 100644 --- a/src/SelfService/Domain/Services/IAuthorizationService.cs +++ b/src/SelfService/Domain/Services/IAuthorizationService.cs @@ -51,6 +51,7 @@ MembershipApplicationId membershipApplicationId bool CanCreateDemoRecording(PortalUser portalUser); bool CanUpdateDemoRecording(PortalUser portalUser); bool CanDeleteDemoRecording(PortalUser portalUser); + bool CanReadDemoSignups(PortalUser portalUser); bool CanCreateEvent(PortalUser portalUser); bool CanUpdateEvent(PortalUser portalUser); diff --git a/src/SelfService/Infrastructure/Api/Capabilities/CapabilityController.cs b/src/SelfService/Infrastructure/Api/Capabilities/CapabilityController.cs index 94e77157..df5541d1 100644 --- a/src/SelfService/Infrastructure/Api/Capabilities/CapabilityController.cs +++ b/src/SelfService/Infrastructure/Api/Capabilities/CapabilityController.cs @@ -541,7 +541,7 @@ [FromBody] NewAzureResourceRequest request [ProducesResponseType(typeof(AwsAccountApiResource), StatusCodes.Status200OK)] [ProducesResponseType(typeof(ProblemDetails), StatusCodes.Status401Unauthorized, "application/problem+json")] [ProducesResponseType(typeof(ProblemDetails), StatusCodes.Status404NotFound, "application/problem+json")] - [RequiresPermission("capability-management", "read-self-assess")] + [RequiresPermission("capability", "read-self-assess")] public async Task GetSelfAssessments(string id) { if (!User.TryGetUserId(out var userId)) @@ -566,7 +566,7 @@ public async Task GetSelfAssessments(string id) [ProducesResponseType(typeof(AwsAccountApiResource), StatusCodes.Status200OK)] [ProducesResponseType(typeof(ProblemDetails), StatusCodes.Status401Unauthorized, "application/problem+json")] [ProducesResponseType(typeof(ProblemDetails), StatusCodes.Status404NotFound, "application/problem+json")] - [RequiresPermission("capability-management", "create-self-assess")] + [RequiresPermission("capability", "create-self-assess")] public async Task UpdateSelfAssessment( string id, [FromBody] SelfAssessmentRequest selfAssessmentRequest @@ -1156,7 +1156,7 @@ public async Task RequestKafkaClusterAccess(string id, string clu [ProducesResponseType(StatusCodes.Status204NoContent)] [ProducesResponseType(typeof(ProblemDetails), StatusCodes.Status401Unauthorized, "application/problem+json")] [ProducesResponseType(typeof(ProblemDetails), StatusCodes.Status404NotFound, "application/problem+json")] - [RequiresPermission("capability-management", "request-deletion")] + [RequiresPermission("capability", "request-deletion")] public async Task RequestCapabilityDeletion(string id, UserId user) { // Verify user and fetch userId @@ -1214,7 +1214,7 @@ public async Task RequestCapabilityDeletion(string id, UserId use [ProducesResponseType(StatusCodes.Status204NoContent)] [ProducesResponseType(typeof(ProblemDetails), StatusCodes.Status401Unauthorized, "application/problem+json")] [ProducesResponseType(typeof(ProblemDetails), StatusCodes.Status404NotFound, "application/problem+json")] - [RequiresPermission("capability-management", "request-deletion")] + [RequiresPermission("capability", "request-deletion")] public async Task CancelCapabilityDeletionRequest(string id) { // Verify user and fetch userId @@ -1557,7 +1557,7 @@ public async Task GetConfigurationLevel([FromRoute] string id) [ProducesResponseType(typeof(AwsAccountApiResource), StatusCodes.Status200OK)] [ProducesResponseType(typeof(ProblemDetails), StatusCodes.Status401Unauthorized, "application/problem+json")] [ProducesResponseType(typeof(ProblemDetails), StatusCodes.Status404NotFound, "application/problem+json")] - [RequiresPermission("capability-management", "read-self-assess")] + [RequiresPermission("capability", "read-self-assess")] public async Task GetSelfAssessmentOptions() { if (!User.TryGetUserId(out var userId)) @@ -1604,7 +1604,7 @@ public async Task AddSelfAssessmentOption([FromBody] AddSelfAsses [ProducesResponseType(typeof(ProblemDetails), StatusCodes.Status400BadRequest, "application/problem+json")] [ProducesResponseType(typeof(ProblemDetails), StatusCodes.Status401Unauthorized, "application/problem+json")] [ProducesResponseType(typeof(ProblemDetails), StatusCodes.Status404NotFound, "application/problem+json")] - [RequiresPermission("capability-management", "create-self-assess")] + [RequiresPermission("capability", "create-self-assess")] public async Task UpdateSelfAssessmentOption( [FromRoute] string id, [FromBody] UpdateSelfAssessmentOptionRequest request diff --git a/src/SelfService/Infrastructure/Api/Demos/DemoRecordingController.cs b/src/SelfService/Infrastructure/Api/Demos/DemoRecordingController.cs index 9677282e..20a18c49 100644 --- a/src/SelfService/Infrastructure/Api/Demos/DemoRecordingController.cs +++ b/src/SelfService/Infrastructure/Api/Demos/DemoRecordingController.cs @@ -181,8 +181,8 @@ public async Task GetActiveSignups() ); } - var isCloudEngineer = _authorizationService.CanSynchronizeAwsECRAndDatabaseECR(User.ToPortalUser()); - if (!isCloudEngineer) + var canReadSignups = _authorizationService.CanReadDemoSignups(User.ToPortalUser()); + if (!canReadSignups) return Unauthorized(); return Ok(_apiResourceFactory.Convert(await _demoApplicationService.GetActiveSignups())); diff --git a/src/SelfService/Infrastructure/Api/RBAC/RbacController.cs b/src/SelfService/Infrastructure/Api/RBAC/RbacController.cs index fe865386..fb6d31b2 100644 --- a/src/SelfService/Infrastructure/Api/RBAC/RbacController.cs +++ b/src/SelfService/Infrastructure/Api/RBAC/RbacController.cs @@ -764,7 +764,8 @@ public async Task GetPermissionMatrix() roleGrants.Select(g => new PermissionMatrixGrantDto( role.Id.ToString(), g.Namespace.ToString(), - g.Permission + g.Permission, + g.Type.ToString() )) ); } @@ -801,11 +802,45 @@ public async Task SetRolePermissions(string roleId, [FromBody] Se ); var allPermissions = Permission.BootstrapPermissions(); - var unknownPermissions = request - .Permissions.Where(p => - !allPermissions.Any(ap => ap.Namespace.ToString() == p.Namespace && ap.Name == p.Name) - ) - .ToList(); + var unknownPermissions = new List(); + var ambiguousPermissions = new List(); + var entries = new List(); + + foreach (var p in request.Permissions) + { + var matches = allPermissions + .Where(ap => ap.Namespace.ToString() == p.Namespace && ap.Name == p.Name) + .ToList(); + + if (!matches.Any()) + { + unknownPermissions.Add(p); + continue; + } + + if (!string.IsNullOrWhiteSpace(p.AccessType)) + { + matches = matches + .Where(ap => + string.Equals(ap.AccessType.ToString(), p.AccessType, StringComparison.OrdinalIgnoreCase) + ) + .ToList(); + + if (!matches.Any()) + { + unknownPermissions.Add(p); + continue; + } + } + else if (matches.Count > 1) + { + ambiguousPermissions.Add(p); + continue; + } + + var matching = matches.Single(); + entries.Add(new RolePermissionEntry(matching.Namespace, matching.Name, matching.AccessType)); + } if (unknownPermissions.Any()) return BadRequest( @@ -813,17 +848,19 @@ public async Task SetRolePermissions(string roleId, [FromBody] Se { Title = "Unknown permissions", Detail = - $"The following permissions are not recognised: {string.Join(", ", unknownPermissions.Select(p => $"{p.Namespace}/{p.Name}"))}", + $"The following permissions are not recognised: {string.Join(", ", unknownPermissions.Select(p => string.IsNullOrWhiteSpace(p.AccessType) ? $"{p.Namespace}/{p.Name}" : $"{p.Namespace}/{p.Name}/{p.AccessType}"))}", } ); - var entries = request - .Permissions.Select(p => - { - var matching = allPermissions.First(ap => ap.Namespace.ToString() == p.Namespace && ap.Name == p.Name); - return new RolePermissionEntry(matching.Namespace, matching.Name, matching.AccessType); - }) - .ToList(); + if (ambiguousPermissions.Any()) + return BadRequest( + new ProblemDetails + { + Title = "Ambiguous permissions", + Detail = + $"The following permissions match multiple access types and must include AccessType: {string.Join(", ", ambiguousPermissions.Select(p => $"{p.Namespace}/{p.Name}"))}", + } + ); await _rbacApplicationService.SetPermissionsForRole(roleId, entries); return NoContent(); @@ -832,9 +869,9 @@ public async Task SetRolePermissions(string roleId, [FromBody] Se public record PermissionDto(string Namespace, string Name, string Description, string AccessType); -public record PermissionMatrixGrantDto(string RoleId, string Namespace, string Permission); +public record PermissionMatrixGrantDto(string RoleId, string Namespace, string Permission, string AccessType); -public record SetRolePermissionEntry(string Namespace, string Name); +public record SetRolePermissionEntry(string Namespace, string Name, string? AccessType = null); public record SetRolePermissionsRequest(List Permissions); diff --git a/src/SelfService/Infrastructure/Api/ReducedPermissionsMiddleware.cs b/src/SelfService/Infrastructure/Api/ReducedPermissionsMiddleware.cs new file mode 100644 index 00000000..cd172315 --- /dev/null +++ b/src/SelfService/Infrastructure/Api/ReducedPermissionsMiddleware.cs @@ -0,0 +1,22 @@ +using Microsoft.Extensions.Primitives; + +namespace SelfService.Infrastructure.Api; + +public class ReducedPermissionsMiddleware : IMiddleware +{ + public const string ReducedPermissionsContextKey = "reducedPermissionsRequested"; + + public ReducedPermissionsMiddleware() { } + + public async Task InvokeAsync(HttpContext context, RequestDelegate next) + { + context.Request.Headers.TryGetValue("x-selfservice-permissions", out StringValues permissions); + + if (permissions.ToString().Equals("1")) + { + context.Items[ReducedPermissionsContextKey] = true; + } + + await next(context); + } +} diff --git a/src/SelfService/Infrastructure/Api/UserAction.cs b/src/SelfService/Infrastructure/Api/UserAction.cs index d2acde9a..f697fff7 100644 --- a/src/SelfService/Infrastructure/Api/UserAction.cs +++ b/src/SelfService/Infrastructure/Api/UserAction.cs @@ -90,9 +90,9 @@ public static IApplicationBuilder UseUserActionMiddleware(this IApplicationBuild return app.UseMiddleware(); } - public static IApplicationBuilder UseUserImpersonationMiddleware(this IApplicationBuilder app) + public static IApplicationBuilder UseReducedPermissionsMiddleware(this IApplicationBuilder app) { - return app.UseMiddleware(); + return app.UseMiddleware(); } } diff --git a/src/SelfService/Infrastructure/Api/UserImpersonation.cs b/src/SelfService/Infrastructure/Api/UserImpersonation.cs deleted file mode 100644 index 8fe296c7..00000000 --- a/src/SelfService/Infrastructure/Api/UserImpersonation.cs +++ /dev/null @@ -1,29 +0,0 @@ -using Microsoft.Extensions.Primitives; -using SelfService.Infrastructure.Api.Capabilities; - -namespace SelfService.Infrastructure.Api; - -public class UserImpersonation : IMiddleware -{ - public UserImpersonation() { } - - private enum UserPermissions - { - CloudEngineer, - } - - public async Task InvokeAsync(HttpContext context, RequestDelegate next) - { - context.Request.Headers.TryGetValue("x-selfservice-permissions", out StringValues permissions); - - if (permissions.ToString().Equals("1")) - { - if (context.User.ToPortalUser().Roles.Count(x => x.ToString().Equals("CloudEngineer")) == 1) - { - context.Items["userPermissions"] = UserPermissions.CloudEngineer; - } - } - - await next(context); - } -} diff --git a/src/SelfService/Program.cs b/src/SelfService/Program.cs index e34695e1..b751f95c 100644 --- a/src/SelfService/Program.cs +++ b/src/SelfService/Program.cs @@ -32,7 +32,7 @@ builder.AddRbac(); builder.Services.AddTransient(); builder.Services.AddTransient(); - builder.Services.AddTransient(); + builder.Services.AddTransient(); // **PLEASE NOTE** : keep this as the last configuration! builder.ConfigureAspects(); @@ -56,7 +56,7 @@ app.UseMemberAutoProvisioner(); app.UseUserActionMiddleware(); - app.UseUserImpersonationMiddleware(); + app.UseReducedPermissionsMiddleware(); app.UseAuthCheckerMiddleware(); app.Run(); diff --git a/tools/config.json b/tools/config.json index 2f4fe670..9949be09 100644 --- a/tools/config.json +++ b/tools/config.json @@ -1,4 +1,4 @@ -{ +{ "debug": true, "apiUrl": "https://ssu-preview.hellman.oxygen.dfds.cloud/api", "groups": [ @@ -16,6 +16,45 @@ "emcla@dfds.com" ] }, + { + "name": "CapabilityOwnersBar", + "roles": [ + { + "roleName": "Owner", + "scope": "Capability", + "resource": "bar" + } + ], + "members": [ + "owner@bar.com" + ] + }, + { + "name": "CapabilityContributorsBar", + "roles": [ + { + "roleName": "Contributor", + "scope": "Capability", + "resource": "bar" + } + ], + "members": [ + "contributor@bar.com" + ] + }, + { + "name": "CapabilityReadersBar", + "roles": [ + { + "roleName": "Reader", + "scope": "Capability", + "resource": "bar" + } + ], + "members": [ + "reader@bar.com" + ] + }, { "name": "BatchCapabilityCreators", "existingId": "899F8F9E-3F7E-4EF3-A2CD-2E1DDA78E40A", @@ -49,20 +88,22 @@ "read-public", "read-private", "update", - "delete" + "delete", + "retry-creating-message-contract" ], - "capability-management": [ + "demos": [ + "read-signups" + ], + "capability": [ "receive-alerts", "receive-cost", "request-deletion", "manage-permissions", "read-self-assess", - "create-self-assess" - ], - "capability-membership-management": [ - "create", - "delete", - "read", + "create-self-assess", + "invite-member", + "remove-member", + "read-members", "read-requests", "manage-requests" ], @@ -109,12 +150,10 @@ "update", "delete" ], - "capability-management": [ - "receive-alerts" - ], - "capability-membership-management": [ - "create", - "read", + "capability": [ + "receive-alerts", + "invite-member", + "read-members", "read-requests", "manage-requests" ], @@ -152,8 +191,8 @@ "read-public", "read-private" ], - "capability-membership-management": [ - "read", + "capability": [ + "read-members", "read-requests" ], "tags-and-metadata": [ @@ -180,8 +219,8 @@ "topics": [ "read-public" ], - "capability-membership-management": [ - "read" + "capability": [ + "read-members" ], "tags-and-metadata": [ "read" @@ -200,21 +239,30 @@ "read-public", "read-private", "update", - "delete" + "delete", + "delete-public", + "retry-creating-message-contract" + ], + "demos": [ + "create", + "update", + "delete", + "read-signups" ], - "capability-management": [ + "capability": [ "receive-alerts", "receive-cost", "request-deletion", "manage-permissions", "read-self-assess", "create-self-assess", - "batch-create-capabilities" - ], - "capability-membership-management": [ - "create", - "delete", - "read", + "batch-create-capabilities", + "view-deleted-capabilities", + "bypass-membership-approvals", + "unset-capability-tags", + "invite-member", + "remove-member", + "read-members", "read-requests", "manage-requests" ], @@ -254,30 +302,31 @@ "system-legacy": [ "read" ], - "system-admin": [ - "view-deleted-capabilities", - "unset-capability-tags", - "create-demo-recording", - "update-demo-recording", - "delete-demo-recording", - "manage-permission-matrix", - "synchronize-aws-ecr-and-database-ecr", - "bypass-membership-approvals", - "manage-self-assessment-options", - "create-release-notes", - "update-release-note", + "self-assessment": [ + "manage-self-assessment-options" + ], + "release-notes": [ + "create", + "update", "toggle-release-note-is-active", "list-draft-release-notes", - "remove-release-note", - "create-event", - "update-event", - "delete-event", - "create-news-item", - "update-news-item", - "delete-news-item", - "get-user-emails", - "delete-membership-application-as-admin", - "retry-creating-message-contract", + "delete" + ], + "events": [ + "create", + "update", + "delete" + ], + "news": [ + "create", + "update", + "delete" + ], + "users": [ + "read" + ], + "system-admin": [ + "synchronize-aws-ecr-and-database-ecr", "manage-json-schemas" ] } @@ -286,7 +335,7 @@ "name": "BatchCapabilityCreator", "existingId": "6A2EE52C-6A9B-4A2A-B9C8-5851DD2D9A6F", "permissions": { - "capability-management": [ + "capability": [ "batch-create-capabilities" ] } diff --git a/tools/config_skeleton.json b/tools/config_skeleton.json index 13fefe23..69c259fb 100644 --- a/tools/config_skeleton.json +++ b/tools/config_skeleton.json @@ -31,20 +31,22 @@ "read-public", "read-private", "update", - "delete" + "delete", + "retry-creating-message-contract" + ], + "demos": [ + "read-signups" ], - "capability-management": [ + "capability": [ "receive-alerts", "receive-cost", "request-deletion", "manage-permissions", "read-self-assess", - "create-self-assess" - ], - "capability-membership-management": [ - "create", - "delete", - "read", + "create-self-assess", + "invite-member", + "remove-member", + "read-members", "read-requests", "manage-requests" ], @@ -91,12 +93,10 @@ "update", "delete" ], - "capability-management": [ - "receive-alerts" - ], - "capability-membership-management": [ - "create", - "read", + "capability": [ + "receive-alerts", + "invite-member", + "read-members", "read-requests", "manage-requests" ], @@ -134,8 +134,8 @@ "read-public", "read-private" ], - "capability-membership-management": [ - "read", + "capability": [ + "read-members", "read-requests" ], "tags-and-metadata": [ @@ -162,8 +162,8 @@ "topics": [ "read-public" ], - "capability-membership-management": [ - "read" + "capability": [ + "read-members" ], "tags-and-metadata": [ "read" @@ -184,19 +184,20 @@ "update", "delete" ], - "capability-management": [ + "capability": [ "receive-alerts", "receive-cost", "request-deletion", "manage-permissions", "read-self-assess", "create-self-assess", - "batch-create-capabilities" - ], - "capability-membership-management": [ - "create", - "delete", - "read", + "batch-create-capabilities", + "view-deleted-capabilities", + "bypass-membership-approvals", + "unset-capability-tags", + "invite-member", + "remove-member", + "read-members", "read-requests", "manage-requests" ], @@ -237,14 +238,10 @@ "read" ], "system-admin": [ - "view-deleted-capabilities", - "unset-capability-tags", "create-demo-recording", "update-demo-recording", "delete-demo-recording", - "manage-permission-matrix", "synchronize-aws-ecr-and-database-ecr", - "bypass-membership-approvals", "manage-self-assessment-options", "create-release-notes", "update-release-note", @@ -257,9 +254,7 @@ "create-news-item", "update-news-item", "delete-news-item", - "get-user-emails", - "delete-membership-application-as-admin", - "retry-creating-message-contract" + "get-user-emails" ] } }, @@ -267,7 +262,7 @@ "name": "BatchCapabilityCreator", "existingId": "6A2EE52C-6A9B-4A2A-B9C8-5851DD2D9A6F", "permissions": { - "capability-management": [ + "capability": [ "batch-create-capabilities" ] } diff --git a/tools/generate-rbac-seed.py b/tools/generate-rbac-seed.py index 7e5ae7ab..045f3d09 100644 --- a/tools/generate-rbac-seed.py +++ b/tools/generate-rbac-seed.py @@ -1,7 +1,7 @@ import csv import json import uuid -from datetime import datetime +from datetime import datetime, UTC from pathlib import Path @@ -15,7 +15,7 @@ def new_uuid(): def now_iso(): - return datetime.utcnow().isoformat() + return datetime.now(UTC).isoformat() def stable_uuid(kind, name): @@ -24,7 +24,8 @@ def stable_uuid(kind, name): def load_config(): - with open(CONFIG_PATH, "r", encoding="utf-8") as f: + # utf-8-sig transparently handles files saved with or without BOM. + with open(CONFIG_PATH, "r", encoding="utf-8-sig") as f: return json.load(f)