Skip to content

Commit 4d162e6

Browse files
authored
Merge pull request #46 from ConductorOne/add_enterprise_roles_provisioning
[BB-1012] add enterprise_roles provisioning
2 parents a1cde87 + 3b7e984 commit 4d162e6

File tree

13 files changed

+409
-297
lines changed

13 files changed

+409
-297
lines changed

.github/workflows/capabilities.yaml

Lines changed: 0 additions & 37 deletions
This file was deleted.
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
name: Generate capabilities and config schema
2+
3+
on:
4+
push:
5+
branches:
6+
- main
7+
8+
jobs:
9+
generate_outputs:
10+
if: github.actor != 'github-actions[bot]'
11+
runs-on: ubuntu-latest
12+
13+
steps:
14+
- name: Checkout code
15+
uses: actions/checkout@v4
16+
with:
17+
token: ${{ secrets.RELENG_GITHUB_TOKEN }}
18+
19+
- name: Setup Go
20+
uses: actions/setup-go@v5
21+
with:
22+
go-version-file: "go.mod"
23+
24+
- name: Build
25+
run: go build -o connector ./cmd/baton-slack
26+
27+
- name: Run and save config output
28+
run: ./connector config > config_schema.json
29+
30+
- name: Run and save capabilities output
31+
run: ./connector capabilities --partner-user-id "test-id" --partner-user-secret "test-secret" > baton_capabilities.json
32+
33+
- name: Commit changes
34+
uses: EndBug/add-and-commit@v9
35+
with:
36+
default_author: github_actions
37+
message: "Updating baton config schema and capabilities."
38+
add: |
39+
config_schema.json
40+
baton_capabilities.json

.github/workflows/ci.yaml

Lines changed: 62 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ jobs:
1111
- name: Checkout code
1212
uses: actions/checkout@v4
1313
- name: Run linters
14-
uses: golangci/golangci-lint-action@v6
14+
uses: golangci/golangci-lint-action@v8
1515
with:
1616
version: latest
1717
args: --timeout=3m
@@ -228,4 +228,65 @@ jobs:
228228
baton grants --entitlement="${{ env.CONNECTOR_ENTITLEMENT }}" --output-format=json | \
229229
jq --exit-status ".grants[].principal.id.resource == \"${{ env.CONNECTOR_PRINCIPAL }}\""
230230
231+
test-enterprise-roles:
232+
runs-on: ubuntu-latest
233+
env:
234+
BATON_LOG_LEVEL: debug
235+
236+
CONNECTOR_GRANT: 'enterpriseRole:Rl0K:assigned:user:U083SJ36LCD'
237+
CONNECTOR_ENTITLEMENT: 'enterpriseRole:Rl0K:assigned'
238+
CONNECTOR_PRINCIPAL: 'U083SJ36LCD'
239+
CONNECTOR_PRINCIPAL_TYPE: 'user'
240+
241+
BATON_TOKEN: "${{ secrets.BATON_TOKEN }}"
242+
BATON_ENTERPRISE_TOKEN: "${{ secrets.BATON_ENTERPRISE_TOKEN }}"
243+
244+
steps:
245+
- name: Install Go
246+
uses: actions/setup-go@v5
247+
with:
248+
go-version: 1.23.x
249+
- name: Checkout code
250+
uses: actions/checkout@v4
251+
- name: Build baton-slack
252+
run: go build ./cmd/baton-slack
253+
254+
- name: Run baton-slack
255+
run: ./baton-slack
256+
- name: Install baton
257+
run: ./scripts/get-baton.sh && mv baton /usr/local/bin
258+
259+
- name: Grant enterprise role first time
260+
run: |
261+
./baton-slack --grant-entitlement="${{ env.CONNECTOR_ENTITLEMENT }}" \
262+
--grant-principal="${{ env.CONNECTOR_PRINCIPAL }}" \
263+
--grant-principal-type="${{ env.CONNECTOR_PRINCIPAL_TYPE }}"
264+
265+
- name: Check for enterprise role grant before revoking
266+
run: |
267+
./baton-slack && \
268+
baton grants --entitlement="${{ env.CONNECTOR_ENTITLEMENT }}" --output-format=json | \
269+
jq --exit-status ".grants[].principal.id.resource == \"${{ env.CONNECTOR_PRINCIPAL }}\"" | grep -q "true"
270+
271+
- name: Revoke enterprise role grant
272+
run: ./baton-slack --revoke-grant="${{ env.CONNECTOR_GRANT }}"
273+
274+
- name: Check enterprise role grant was revoked
275+
run: |
276+
./baton-slack && \
277+
baton grants --entitlement="${{ env.CONNECTOR_ENTITLEMENT }}" --output-format=json | \
278+
jq --exit-status "if .grants then .grants[]?.principal.id.resource != \"${{ env.CONNECTOR_PRINCIPAL }}\" else . end"
279+
280+
- name: Grant enterprise role second time
281+
run: |
282+
./baton-slack --grant-entitlement="${{ env.CONNECTOR_ENTITLEMENT }}" \
283+
--grant-principal="${{ env.CONNECTOR_PRINCIPAL }}" \
284+
--grant-principal-type="${{ env.CONNECTOR_PRINCIPAL_TYPE }}"
285+
286+
- name: Check enterprise role was re-granted
287+
run: |
288+
./baton-slack && \
289+
baton grants --entitlement="${{ env.CONNECTOR_ENTITLEMENT }}" --output-format=json | \
290+
jq --exit-status ".grants[].principal.id.resource == \"${{ env.CONNECTOR_PRINCIPAL }}\"" | grep -q "true"
291+
231292

.github/workflows/main.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ jobs:
1414
- name: Checkout code
1515
uses: actions/checkout@v3
1616
- name: Run linters
17-
uses: golangci/golangci-lint-action@v6
17+
uses: golangci/golangci-lint-action@v8
1818
with:
1919
version: latest
2020
args: --timeout=3m
@@ -38,4 +38,4 @@ jobs:
3838
if: always()
3939
uses: guyarb/[email protected]
4040
with:
41-
test-results: test.json
41+
test-results: test.json

.golangci.yml

Lines changed: 112 additions & 92 deletions
Original file line numberDiff line numberDiff line change
@@ -1,96 +1,116 @@
1-
#AUTO GENERATED CODE. UPDATE THE CONFIG IN BATON-TEMPLATE FIRST
2-
linters-settings:
3-
exhaustive:
4-
default-signifies-exhaustive: true
5-
gocritic:
6-
enabled-checks:
7-
- ruleguard
8-
# The list of supported checkers can be find in https://go-critic.github.io/overview.
9-
settings:
10-
underef:
11-
# Whether to skip (*x).method() calls where x is a pointer receiver.
12-
skipRecvDeref: false
13-
ruleguard:
14-
rules: "${configDir}/tools/rules.go"
15-
govet:
16-
enable-all: true
17-
disable:
18-
- fieldalignment # too strict
19-
- shadow # complains too much about shadowing errors. All research points to this being fine.
20-
nakedret:
21-
max-func-lines: 0
22-
nolintlint:
23-
allow-no-explanation: [forbidigo, tracecheck, gomnd, gochecknoinits, makezero]
24-
require-explanation: true
25-
require-specific: true
26-
revive:
27-
ignore-generated-header: true
28-
severity: error
29-
rules:
30-
- name: atomic
31-
- name: line-length-limit
32-
arguments: [200]
33-
# These are functions that we use without checking the errors often. Most of these can't return an error even
34-
# though they implement an interface that can.
35-
- name: unhandled-error
36-
arguments:
37-
- fmt.Printf
38-
- fmt.Println
39-
- fmt.Fprint
40-
- fmt.Fprintf
41-
- fmt.Fprintln
42-
- os.Stderr.Sync
43-
- sb.WriteString
44-
- buf.WriteString
45-
- hasher.Write
46-
- os.Setenv
47-
- os.RemoveAll
48-
- name: var-naming
49-
arguments: [["ID", "URL", "HTTP", "API"], []]
50-
tenv:
51-
all: true
1+
version: "2"
522
linters:
53-
disable-all: true
3+
default: none
544
enable:
55-
- errcheck # Errcheck is a program for checking for unchecked errors in go programs. These unchecked errors can be critical bugs in some cases
56-
- gosimple # Linter for Go source code that specializes in simplifying a code
57-
- govet # Vet examines Go source code and reports suspicious constructs, such as Printf calls whose arguments do not align with the format string
58-
- ineffassign # Detects when assignments to existing variables are not used
59-
- staticcheck # Staticcheck is a go vet on steroids, applying a ton of static analysis checks
60-
- typecheck # Like the front-end of a Go compiler, parses and type-checks Go code
61-
- unused # Checks Go code for unused constants, variables, functions and types
62-
- asasalint # Check for pass []any as any in variadic func(...any)
63-
- asciicheck # Simple linter to check that your code does not contain non-ASCII identifiers
64-
- bidichk # Checks for dangerous unicode character sequences
65-
- bodyclose # checks whether HTTP response body is closed successfully
66-
- durationcheck # check for two durations multiplied together
67-
- errorlint # errorlint is a linter for that can be used to find code that will cause problems with the error wrapping scheme introduced in Go 1.13.
68-
- exhaustive # check exhaustiveness of enum switch statements
69-
- forbidigo # Forbids identifiers
70-
- gochecknoinits # Checks that no init functions are present in Go code
71-
- goconst # Finds repeated strings that could be replaced by a constant
72-
- gocritic # Provides diagnostics that check for bugs, performance and style issues.
73-
- godot # Check if comments end in a period
74-
- goimports # In addition to fixing imports, goimports also formats your code in the same style as gofmt.
75-
- gomoddirectives # Manage the use of 'replace', 'retract', and 'excludes' directives in go.mod.
76-
- goprintffuncname # Checks that printf-like functions are named with f at the end
77-
- gosec # Inspects source code for security problems
78-
- nakedret # Finds naked returns in functions greater than a specified function length
79-
- nilerr # Finds the code that returns nil even if it checks that the error is not nil.
80-
- noctx # noctx finds sending http request without context.Context
81-
- nolintlint # Reports ill-formed or insufficient nolint directives
82-
- nonamedreturns # Reports all named returns
83-
- nosprintfhostport # Checks for misuse of Sprintf to construct a host with port in a URL.
84-
- predeclared # find code that shadows one of Go's predeclared identifiers
85-
- revive # Fast, configurable, extensible, flexible, and beautiful linter for Go. Drop-in replacement of golint.
86-
- tenv # tenv is analyzer that detects using os.Setenv instead of t.Setenv since Go1.17
87-
- tparallel # tparallel detects inappropriate usage of t.Parallel() method in your Go test codes
88-
- unconvert # Remove unnecessary type conversions
89-
- usestdlibvars # detect the possibility to use variables/constants from the Go standard library
90-
- whitespace # Tool for detection of leading and trailing whitespace
5+
- asasalint
6+
- asciicheck
7+
- bidichk
8+
- bodyclose
9+
- durationcheck
10+
- errcheck
11+
- errorlint
12+
- exhaustive
13+
- forbidigo
14+
- gochecknoinits
15+
- goconst
16+
- gocritic
17+
- godot
18+
- gomoddirectives
19+
- goprintffuncname
20+
- gosec
21+
- govet
22+
- ineffassign
23+
- nakedret
24+
- nilerr
25+
- noctx
26+
- nolintlint
27+
- nonamedreturns
28+
- nosprintfhostport
29+
- predeclared
30+
- revive
31+
- staticcheck
32+
- tparallel
33+
- unconvert
34+
- unused
35+
- usestdlibvars
36+
- whitespace
37+
settings:
38+
exhaustive:
39+
default-signifies-exhaustive: true
40+
gocritic:
41+
enabled-checks:
42+
- ruleguard
43+
settings:
44+
ruleguard:
45+
rules: ${base-path}/tools/rules.go
46+
underef:
47+
skipRecvDeref: false
48+
govet:
49+
disable:
50+
- fieldalignment
51+
- shadow
52+
enable-all: true
53+
nakedret:
54+
max-func-lines: 0
55+
nolintlint:
56+
require-explanation: true
57+
require-specific: true
58+
allow-no-explanation:
59+
- forbidigo
60+
- tracecheck
61+
- gomnd
62+
- gochecknoinits
63+
- makezero
64+
revive:
65+
severity: error
66+
rules:
67+
- name: atomic
68+
- name: line-length-limit
69+
arguments:
70+
- 200
71+
- name: unhandled-error
72+
arguments:
73+
- fmt.Printf
74+
- fmt.Println
75+
- fmt.Fprint
76+
- fmt.Fprintf
77+
- fmt.Fprintln
78+
- os.Stderr.Sync
79+
- sb.WriteString
80+
- buf.WriteString
81+
- hasher.Write
82+
- os.Setenv
83+
- os.RemoveAll
84+
- name: var-naming
85+
arguments:
86+
- - ID
87+
- URL
88+
- HTTP
89+
- API
90+
- []
91+
exclusions:
92+
generated: lax
93+
presets:
94+
- comments
95+
- common-false-positives
96+
- legacy
97+
- std-error-handling
98+
rules:
99+
- linters:
100+
- godot
101+
source: (TODO)
102+
paths:
103+
- third_party$
104+
- builtin$
105+
- examples$
91106
issues:
92107
max-same-issues: 50
93-
exclude-rules:
94-
# Don't require TODO comments to end in a period
95-
- source: "(TODO)"
96-
linters: [godot]
108+
formatters:
109+
enable:
110+
- goimports
111+
exclusions:
112+
generated: lax
113+
paths:
114+
- third_party$
115+
- builtin$
116+
- examples$

.gon-amd64.json

Lines changed: 0 additions & 13 deletions
This file was deleted.

0 commit comments

Comments
 (0)