1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
//! API token scopes: what a token may do on top of its role.
use super::{AuthError, AuthResult};
/// What an API token may do on top of its role. A token with no scopes has
/// the role's whole reach (agents administer their org by default); scopes
/// only ever narrow it.
#[derive(Debug, Clone, PartialEq, Eq)]
pub enum Scope {
/// Read-only tools, never secret values.
Read,
/// `read`, plus deploys, redeploys, rollbacks, scaling and builds.
Deploy,
/// Everything the role allows, including tokens and members.
Admin,
/// Tools whose name matches a glob: `tool:app_*`.
Tools(String),
}
impl Scope {
pub fn parse(s: &str) -> AuthResult<Scope> {
let s = s.trim();
match s {
"read" => Ok(Scope::Read),
"deploy" => Ok(Scope::Deploy),
"admin" => Ok(Scope::Admin),
_ => match s.strip_prefix("tool:") {
Some(g)
if !g.is_empty()
&& g.len() <= 128
&& g.bytes()
.all(|b| b.is_ascii_alphanumeric() || b"_.-*?[]!^".contains(&b)) =>
{
Ok(Scope::Tools(g.to_string()))
}
_ => Err(AuthError::Invalid(format!(
"scope {s:?}: read, deploy, admin or tool:GLOB"
))),
},
}
}
pub fn as_string(&self) -> String {
match self {
Scope::Read => "read".into(),
Scope::Deploy => "deploy".into(),
Scope::Admin => "admin".into(),
Scope::Tools(g) => format!("tool:{g}"),
}
}
/// Check a list, normalized and without duplicates.
pub fn normalize(v: &[String]) -> AuthResult<Vec<String>> {
if v.len() > 32 {
return Err(AuthError::Invalid("at most 32 scopes".into()));
}
let mut out: Vec<String> = Vec::new();
for s in v {
let s = Scope::parse(s)?.as_string();
if !out.contains(&s) {
out.push(s);
}
}
Ok(out)
}
}