feat(api): aplica autorização por papel e posse nos jobs - #176
Merged
Merged
Conversation
- centraliza a política de autorização das operações de jobs - restringe operações ao profissional de RH proprietário do recurso - remove o bypass geral de posse para auditor - valida papéis do Keycloak antes de resolver a conta local - nega tokens sem papel conhecido ou com papéis conflitantes - aplica autorização antes de mutações e da abertura de streams SSE - protege criação, listagem, consulta, parâmetros, ações e reprocessamento - mantém preflight CORS fora da política de negócio - atualiza documentação e cobertura de autorização
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Objetivo
Aplicar uma política central de autorização às operações de jobs, considerando o papel do usuário autenticado e a posse persistida do recurso.
Closes #104
Alterações
profissional-rhauditorprofissional-rheauditorsubautenticado e da conta local associadausuario_iddo profissional autenticadoRotas cobertas
POST /jobsGET /jobsGET /jobs/{id}GET /jobs/{id}/eventsPOST /jobs/{id}/parametersPOST /jobs/{id}/actionsPOST /jobs/{id}/reprocessarRegras de acesso
403403401Documentação
Testes