mirror of
https://github.com/goharbor/harbor.git
synced 2024-11-23 10:45:45 +01:00
Merge pull request #14344 from reasonerjt/fix-14303-1.10
[Cherrypick - 1.10] Add "*" to the claim set in the token for /v2 apis
This commit is contained in:
commit
a1465a199c
@ -194,6 +194,16 @@ func resourceScopes(sCtx security.Context, rc rbac.Resource) map[string]struct{}
|
||||
res[s] = struct{}{}
|
||||
}
|
||||
}
|
||||
|
||||
// "*" is needed in the token for some API in notary server
|
||||
// see https://github.com/goharbor/harbor/issues/14303#issuecomment-788010900
|
||||
// and https://github.com/theupdateframework/notary/blob/84287fd8df4f172c9a8289641cdfa355fc86989d/server/server.go#L200
|
||||
_, ok1 := res["push"]
|
||||
_, ok2 := res["pull"]
|
||||
_, ok3 := res["delete"]
|
||||
if ok1 && ok2 && ok3 {
|
||||
res["*"] = struct{}{}
|
||||
}
|
||||
return res
|
||||
}
|
||||
|
||||
|
@ -326,6 +326,7 @@ func TestResourceScopes(t *testing.T) {
|
||||
"scanner-pull": {},
|
||||
"push": {},
|
||||
"delete": {},
|
||||
"*": {},
|
||||
},
|
||||
},
|
||||
{
|
||||
|
Loading…
Reference in New Issue
Block a user