lahirujayathilake opened a new pull request, #484:
URL: https://github.com/apache/airavata-custos/pull/484

   Adds an authorization model for Custos admins, fine-grained privileges plus 
named role bundles that group privileges together.
   
   ## Architecture
   
   Two layers,
   
    - **Privileges** - declared keys (`amie:read`, `hpc:write`, 
`privileges:grant`, `roles:manage`, etc.) granted directly to a user.
   - **Roles** - named bundles of privileges. Granting a role to a user is 
shorthand for granting every privilege the role carries. Update to a role's 
bundle propagates to every holder.
   
   A user's `effective set = direct grants UNION privileges` from every role 
they hold. The auth middleware caches this set per user.
   
   ## Models
   
   - `user_privileges` - direct grants (revoke is DELETE; history in 
`audit_events`)
   - `roles` - role definitions (`name`, `description`, `is_system`)
   - `role_privileges` - many-to-many relationship
   - `user_roles` - role assignments (revoke is DELETE; history in 
`audit_events`)
   
   `audit_events` (existing core table) is the single source of grant/revoke 
history.
   
   ## Identification
   
   Caller is identified via the `X-Custos-User-Id` header. A JWT-verification 
middleware (the planned implementation) will set this from the verified `sub` 
claim after validating against the IdP's JWKS endpoint.
   
   ## Bootstrap
   
   If `CUSTOS_BOOTSTRAP_ADMIN_EMAIL` is set, the server idempotently creates a 
`super_admin` role carrying `privileges:grant` + `roles:manage` and grants it 
to the named user on first start.
   
   ## API contract
   
   - `GET /user/privileges` - caller's effective set
   - `GET /privileges/catalog` - declared privilege keys
   - `GET|POST|DELETE /users/{id}/privileges...` - direct grant management
   - `GET|POST|PUT|DELETE /roles...` - role CRUD + bundle management
   - `GET|POST|DELETE /users/{id}/roles...` - role assignments
   
   Privilege management endpoints gated on `privileges:grant`; role management 
gated on `roles:manage`.
   
   ## Dev tooling
   
   - `dev-ops/compose/seeds/dev_users_and_roles.sql` - seeds 4 dev users 
(`dev-admin`, `dev-operator`, `dev-auditor`, `dev-researcher`) plus `operator` 
and `auditor` roles


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to