Implement Workflow Level Permissions

This commit is contained in:
Excellencedev committed 2025-12-31 05:11:28 +01:00
1 parent f367039e78
commit 1ff75aa822
7 files changed
+463 -3

No files matched your search

+4
View File
@@ -51,6 +51,10 @@ type ActionRunJob struct {
ConcurrencyGroup string `xorm:"index(repo_concurrency) NOT NULL DEFAULT ''"` // evaluated concurrency.group
ConcurrencyCancel bool `xorm:"NOT NULL DEFAULT FALSE"` // evaluated concurrency.cancel-in-progress
// TokenPermissions stores the parsed permissions from the workflow YAML (workflow + job level, clamped by repo max settings)
// This is JSON-encoded repo_model.ActionsTokenPermissions
TokenPermissions string `xorm:"TEXT"`
Started timeutil.TimeStamp
Stopped timeutil.TimeStamp
Created timeutil.TimeStamp `xorm:"created"`
+19 -3
View File
@@ -325,9 +325,25 @@ func GetActionsUserRepoPermission(ctx context.Context, repo *repo_model.Reposito
return perm, nil
}
// Get effective token permissions from repository settings
effectivePerms := actionsCfg.GetEffectiveTokenPermissions(task.IsForkPullRequest)
effectivePerms = actionsCfg.ClampPermissions(effectivePerms)
// Get effective token permissions
// First check if job has explicit permissions stored from workflow YAML
var effectivePerms repo_model.ActionsTokenPermissions
if err := task.LoadJob(ctx); err != nil {
return perm, err
}
if task.Job != nil && task.Job.TokenPermissions != "" {
// Use permissions parsed from workflow YAML (already clamped by repo max settings during insertion)
effectivePerms, err = repo_model.UnmarshalTokenPermissions(task.Job.TokenPermissions)
if err != nil {
// Fall back to repository settings if unmarshal fails
effectivePerms = actionsCfg.GetEffectiveTokenPermissions(task.IsForkPullRequest)
effectivePerms = actionsCfg.ClampPermissions(effectivePerms)
}
} else {
// No workflow permissions, use repository settings
effectivePerms = actionsCfg.GetEffectiveTokenPermissions(task.IsForkPullRequest)
effectivePerms = actionsCfg.ClampPermissions(effectivePerms)
}
// Set up per-unit access modes based on configured permissions
perm.units = repo.Units
+19
View File
@@ -261,6 +261,25 @@ func ForkPullRequestPermissions() ActionsTokenPermissions {
}
}
// MarshalTokenPermissions serializes ActionsTokenPermissions to JSON
func MarshalTokenPermissions(perms ActionsTokenPermissions) string {
data, err := json.Marshal(perms)
if err != nil {
return ""
}
return string(data)
}
// UnmarshalTokenPermissions deserializes JSON to ActionsTokenPermissions
func UnmarshalTokenPermissions(data string) (ActionsTokenPermissions, error) {
var perms ActionsTokenPermissions
if data == "" {
return perms, nil
}
err := json.Unmarshal([]byte(data), &perms)
return perms, err
}
type ActionsConfig struct {
DisabledWorkflows []string
// CollaborativeOwnerIDs is a list of owner IDs used to share actions from private repos.