mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-03 02:21:17 +02:00
Implement Workflow Level Permissions
This commit is contained in:
1 parent
f367039e78
commit
1ff75aa822
7 files changed
+463
-3
No files matched your search
@@ -51,6 +51,10 @@ type ActionRunJob struct {
|
||||
ConcurrencyGroup string `xorm:"index(repo_concurrency) NOT NULL DEFAULT ''"` // evaluated concurrency.group
|
||||
ConcurrencyCancel bool `xorm:"NOT NULL DEFAULT FALSE"` // evaluated concurrency.cancel-in-progress
|
||||
|
||||
// TokenPermissions stores the parsed permissions from the workflow YAML (workflow + job level, clamped by repo max settings)
|
||||
// This is JSON-encoded repo_model.ActionsTokenPermissions
|
||||
TokenPermissions string `xorm:"TEXT"`
|
||||
|
||||
Started timeutil.TimeStamp
|
||||
Stopped timeutil.TimeStamp
|
||||
Created timeutil.TimeStamp `xorm:"created"`
|
||||
|
||||
@@ -325,9 +325,25 @@ func GetActionsUserRepoPermission(ctx context.Context, repo *repo_model.Reposito
|
||||
return perm, nil
|
||||
}
|
||||
|
||||
// Get effective token permissions from repository settings
|
||||
effectivePerms := actionsCfg.GetEffectiveTokenPermissions(task.IsForkPullRequest)
|
||||
effectivePerms = actionsCfg.ClampPermissions(effectivePerms)
|
||||
// Get effective token permissions
|
||||
// First check if job has explicit permissions stored from workflow YAML
|
||||
var effectivePerms repo_model.ActionsTokenPermissions
|
||||
if err := task.LoadJob(ctx); err != nil {
|
||||
return perm, err
|
||||
}
|
||||
if task.Job != nil && task.Job.TokenPermissions != "" {
|
||||
// Use permissions parsed from workflow YAML (already clamped by repo max settings during insertion)
|
||||
effectivePerms, err = repo_model.UnmarshalTokenPermissions(task.Job.TokenPermissions)
|
||||
if err != nil {
|
||||
// Fall back to repository settings if unmarshal fails
|
||||
effectivePerms = actionsCfg.GetEffectiveTokenPermissions(task.IsForkPullRequest)
|
||||
effectivePerms = actionsCfg.ClampPermissions(effectivePerms)
|
||||
}
|
||||
} else {
|
||||
// No workflow permissions, use repository settings
|
||||
effectivePerms = actionsCfg.GetEffectiveTokenPermissions(task.IsForkPullRequest)
|
||||
effectivePerms = actionsCfg.ClampPermissions(effectivePerms)
|
||||
}
|
||||
|
||||
// Set up per-unit access modes based on configured permissions
|
||||
perm.units = repo.Units
|
||||
|
||||
@@ -261,6 +261,25 @@ func ForkPullRequestPermissions() ActionsTokenPermissions {
|
||||
}
|
||||
}
|
||||
|
||||
// MarshalTokenPermissions serializes ActionsTokenPermissions to JSON
|
||||
func MarshalTokenPermissions(perms ActionsTokenPermissions) string {
|
||||
data, err := json.Marshal(perms)
|
||||
if err != nil {
|
||||
return ""
|
||||
}
|
||||
return string(data)
|
||||
}
|
||||
|
||||
// UnmarshalTokenPermissions deserializes JSON to ActionsTokenPermissions
|
||||
func UnmarshalTokenPermissions(data string) (ActionsTokenPermissions, error) {
|
||||
var perms ActionsTokenPermissions
|
||||
if data == "" {
|
||||
return perms, nil
|
||||
}
|
||||
err := json.Unmarshal([]byte(data), &perms)
|
||||
return perms, err
|
||||
}
|
||||
|
||||
type ActionsConfig struct {
|
||||
DisabledWorkflows []string
|
||||
// CollaborativeOwnerIDs is a list of owner IDs used to share actions from private repos.
|
||||
|
||||
Reference in new issue
Block a user