mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-02 15:10:43 +02:00
WIP
This commit is contained in:
1 parent
9a69f65ee4
commit
43e96d5ead
9 files changed
+230
-1
No files matched your search
@@ -0,0 +1,43 @@
|
||||
// Copyright 2024 The Gitea Authors. All rights reserved.
|
||||
// SPDX-License-Identifier: MIT
|
||||
|
||||
package actions
|
||||
|
||||
import (
|
||||
"context"
|
||||
|
||||
repo_model "code.gitea.io/gitea/models/repo"
|
||||
user_model "code.gitea.io/gitea/models/user"
|
||||
"code.gitea.io/gitea/modules/json"
|
||||
)
|
||||
|
||||
// GetOrgActionsConfig loads the ActionsConfig for an organization from user settings
|
||||
// It returns a default config if no setting is found
|
||||
func GetOrgActionsConfig(ctx context.Context, orgID int64) (*repo_model.ActionsConfig, error) {
|
||||
val, err := user_model.GetUserSetting(ctx, orgID, "actions.config")
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
cfg := &repo_model.ActionsConfig{}
|
||||
if val == "" {
|
||||
// Return defaults if no config exists
|
||||
return cfg, nil
|
||||
}
|
||||
|
||||
if err := json.Unmarshal([]byte(val), cfg); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
return cfg, nil
|
||||
}
|
||||
|
||||
// SetOrgActionsConfig saves the ActionsConfig for an organization to user settings
|
||||
func SetOrgActionsConfig(ctx context.Context, orgID int64, cfg *repo_model.ActionsConfig) error {
|
||||
bs, err := json.Marshal(cfg)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
return user_model.SetUserSetting(ctx, orgID, "actions.config", string(bs))
|
||||
}
|
||||
@@ -280,6 +280,19 @@ func GetActionsUserRepoPermission(ctx context.Context, repo *repo_model.Reposito
|
||||
if err != nil || !exist {
|
||||
return perm, err
|
||||
}
|
||||
|
||||
// Check Organization Cross-Repo Access Policy
|
||||
if repo.OwnerID == taskRepo.OwnerID && repo.Owner.IsOrganization() {
|
||||
orgCfg, err := actions_model.GetOrgActionsConfig(ctx, repo.OwnerID)
|
||||
if err != nil {
|
||||
return perm, err
|
||||
}
|
||||
if !orgCfg.AllowCrossRepoAccess {
|
||||
// Deny access if cross-repo is disabled in Org
|
||||
return perm, nil
|
||||
}
|
||||
}
|
||||
|
||||
if !actionsCfg.IsCollaborativeOwner(taskRepo.OwnerID) || !taskRepo.IsPrivate {
|
||||
// The task repo can access the current repo only if the task repo is private and
|
||||
// the owner of the task repo is a collaborative owner of the current repo.
|
||||
|
||||
@@ -240,6 +240,8 @@ type ActionsConfig struct {
|
||||
DefaultTokenPermissions *ActionsTokenPermissions `json:"default_token_permissions,omitempty"`
|
||||
// MaxTokenPermissions defines the maximum permissions (cannot be exceeded by workflow permissions keyword)
|
||||
MaxTokenPermissions *ActionsTokenPermissions `json:"max_token_permissions,omitempty"`
|
||||
// AllowCrossRepoAccess indicates if actions in this repo/org can access other repos in the same org
|
||||
AllowCrossRepoAccess bool `json:"allow_cross_repo_access,omitempty"`
|
||||
}
|
||||
|
||||
func (cfg *ActionsConfig) EnableWorkflow(file string) {
|
||||
|
||||
@@ -10,6 +10,7 @@ import (
|
||||
"strings"
|
||||
|
||||
"code.gitea.io/gitea/models/db"
|
||||
|
||||
"code.gitea.io/gitea/modules/cache"
|
||||
setting_module "code.gitea.io/gitea/modules/setting"
|
||||
"code.gitea.io/gitea/modules/util"
|
||||
|
||||
Reference in new issue
Block a user