Skip to content
Open
Show file tree
Hide file tree
Changes from 3 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 3 additions & 2 deletions cmd/harbor/root/project/robot/create.go
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,7 @@ import (
"github.com/goharbor/go-client/pkg/sdk/v2.0/models"
"github.com/goharbor/harbor-cli/pkg/api"
config "github.com/goharbor/harbor-cli/pkg/config/robot"
rmodel "github.com/goharbor/harbor-cli/pkg/models/robot"
"github.com/goharbor/harbor-cli/pkg/prompt"
"github.com/goharbor/harbor-cli/pkg/utils"
"github.com/goharbor/harbor-cli/pkg/views/robot/create"
Expand Down Expand Up @@ -166,12 +167,12 @@ Examples:
accesses = append(accesses, access)
}
// convert []models.permission to []*model.Access
perm := &create.RobotPermission{
perm := &rmodel.RobotPermission{
Namespace: opts.ProjectName,
Access: accesses,
Kind: "project", // Default to project level
}
opts.Permissions = []*create.RobotPermission{perm}
opts.Permissions = []*rmodel.RobotPermission{perm}
}
getProjectID, err := api.GetProject(opts.ProjectName, false)
if err != nil {
Expand Down
5 changes: 3 additions & 2 deletions cmd/harbor/root/project/robot/update.go
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@ import (

"github.com/goharbor/go-client/pkg/sdk/v2.0/models"
"github.com/goharbor/harbor-cli/pkg/api"
rmodel "github.com/goharbor/harbor-cli/pkg/models/robot"
"github.com/goharbor/harbor-cli/pkg/prompt"
"github.com/goharbor/harbor-cli/pkg/views/robot/update"
log "github.com/sirupsen/logrus"
Expand Down Expand Up @@ -147,12 +148,12 @@ Examples:
accesses = append(accesses, access)
}
// convert []models.permission to []*model.Access
perm := &update.RobotPermission{
perm := &rmodel.RobotPermission{
Kind: bot.Permissions[0].Kind,
Namespace: bot.Permissions[0].Namespace,
Access: accesses,
}
opts.Permissions = []*update.RobotPermission{perm}
opts.Permissions = []*rmodel.RobotPermission{perm}

err = updateRobotView(&opts)
if err != nil {
Expand Down
131 changes: 131 additions & 0 deletions cmd/harbor/root/robot/common.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,131 @@
// Copyright Project Harbor Authors
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package robot

import (
"fmt"

"github.com/goharbor/go-client/pkg/sdk/v2.0/models"
config "github.com/goharbor/harbor-cli/pkg/config/robot"
rmodel "github.com/goharbor/harbor-cli/pkg/models/robot"
"github.com/goharbor/harbor-cli/pkg/views/robot/create"
"github.com/goharbor/harbor-cli/pkg/views/robot/update"
"github.com/sirupsen/logrus"
)

func loadRobotConfigFromFile(configFile string, permissions *[]models.Permission, projectPermissionsMap map[string][]models.Permission, isUpdate bool, createOpts *create.CreateView, updateOpts *update.UpdateView) error {
fmt.Println("Loading configuration from: ", configFile)

loadedOpts, err := config.LoadRobotConfigFromFile(configFile)
if err != nil {
return fmt.Errorf("failed to load robot config from file: %v", err)
}

logrus.Info("Successfully loaded robot configuration")

// Apply configuration based on operation type
if isUpdate && updateOpts != nil {
// Update mode: Only update specific fields selectively
if loadedOpts.Description != "" {
updateOpts.Description = loadedOpts.Description
}
if loadedOpts.Duration != 0 {
updateOpts.Duration = loadedOpts.Duration
}
} else if !isUpdate && createOpts != nil {
// Create mode: Full assignment
*createOpts = *loadedOpts
}

var systemPermFound bool
for _, perm := range loadedOpts.Permissions {
if perm.Kind == "system" && perm.Namespace == "/" {
systemPermFound = true

if isUpdate {
// Append for updates
for _, access := range perm.Access {
*permissions = append(*permissions, models.Permission{
Resource: access.Resource,
Action: access.Action,
})
}
} else {
// Replace for creates
*permissions = make([]models.Permission, len(perm.Access))
for i, access := range perm.Access {
(*permissions)[i] = models.Permission{
Resource: access.Resource,
Action: access.Action,
}
}
}
} else if perm.Kind == "project" {
var projectPerms []models.Permission
for _, access := range perm.Access {
projectPerms = append(projectPerms, models.Permission{
Resource: access.Resource,
Action: access.Action,
})
}
projectPermissionsMap[perm.Namespace] = projectPerms
}
}

if !systemPermFound {
return fmt.Errorf("robot configuration must include system-level permissions")
}

logrus.Infof("Loaded robot config with %d system permissions and %d project-specific permissions",
len(*permissions), len(projectPermissionsMap))

return nil
}

func loadFromConfigFileForCreate(opts *create.CreateView, configFile string, permissions *[]models.Permission, projectPermissionsMap map[string][]models.Permission) error {
return loadRobotConfigFromFile(configFile, permissions, projectPermissionsMap, false, opts, nil)
}

func loadFromConfigFileForUpdate(opts *update.UpdateView, configFile string, permissions *[]models.Permission, projectPermissionsMap map[string][]models.Permission) error {
return loadRobotConfigFromFile(configFile, permissions, projectPermissionsMap, true, nil, opts)
}

func buildMergedPermissions(projectPermissionsMap map[string][]models.Permission, accessesSystem []*models.Access) []*rmodel.RobotPermission {
var mergedPermissions []*rmodel.RobotPermission

// Add project permissions
for projectName, projectPermissions := range projectPermissionsMap {
var accessesProject []*models.Access
for _, perm := range projectPermissions {
accessesProject = append(accessesProject, &models.Access{
Resource: perm.Resource,
Action: perm.Action,
})
}
mergedPermissions = append(mergedPermissions, &rmodel.RobotPermission{
Namespace: projectName,
Access: accessesProject,
Kind: "project",
})
}

// Add system permissions
mergedPermissions = append(mergedPermissions, &rmodel.RobotPermission{
Namespace: "/",
Access: accessesSystem,
Kind: "system",
})
Copy link

Copilot AI Aug 18, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

System permissions are always added regardless of whether accessesSystem is empty. This could create empty system permission entries. Consider checking if len(accessesSystem) > 0 before adding system permissions, similar to how it was handled in the original buildMergedPermissionsForUpdate function.

Suggested change
})
if len(accessesSystem) > 0 {
mergedPermissions = append(mergedPermissions, &rmodel.RobotPermission{
Namespace: "/",
Access: accessesSystem,
Kind: "system",
})
}

Copilot uses AI. Check for mistakes.

return mergedPermissions
}
106 changes: 2 additions & 104 deletions cmd/harbor/root/robot/create.go
Original file line number Diff line number Diff line change
Expand Up @@ -91,7 +91,7 @@ Examples:

// Handle config file or interactive input
if configFile != "" {
if err := loadFromConfigFile(&opts, configFile, &permissions, projectPermissionsMap); err != nil {
if err := loadFromConfigFileForCreate(&opts, configFile, &permissions, projectPermissionsMap); err != nil {
return err
}
} else {
Expand Down Expand Up @@ -121,51 +121,6 @@ Examples:
return cmd
}

func loadFromConfigFile(opts *create.CreateView, configFile string, permissions *[]models.Permission, projectPermissionsMap map[string][]models.Permission) error {
fmt.Println("Loading configuration from: ", configFile)

loadedOpts, err := config.LoadRobotConfigFromFile(configFile)
if err != nil {
return fmt.Errorf("failed to load robot config from file: %v", err)
}

logrus.Info("Successfully loaded robot configuration")
*opts = *loadedOpts

// Extract system-level and project permissions
var systemPermFound bool
for _, perm := range opts.Permissions {
if perm.Kind == "system" && perm.Namespace == "/" {
systemPermFound = true
*permissions = make([]models.Permission, len(perm.Access))
for i, access := range perm.Access {
(*permissions)[i] = models.Permission{
Resource: access.Resource,
Action: access.Action,
}
}
} else if perm.Kind == "project" {
var projectPerms []models.Permission
for _, access := range perm.Access {
projectPerms = append(projectPerms, models.Permission{
Resource: access.Resource,
Action: access.Action,
})
}
projectPermissionsMap[perm.Namespace] = projectPerms
}
}

if !systemPermFound {
return fmt.Errorf("system robot configuration must include system-level permissions")
}

logrus.Infof("Loaded system robot with %d system permissions and %d project-specific permissions",
len(*permissions), len(projectPermissionsMap))

return nil
}

func handleInteractiveInput(opts *create.CreateView, all bool, permissions *[]models.Permission, projectPermissionsMap map[string][]models.Permission) error {
// Show interactive form if needed
if opts.Name == "" || opts.Duration == 0 {
Expand Down Expand Up @@ -224,7 +179,7 @@ func getProjectPermissions(opts *create.CreateView, projectPermissionsMap map[st
}

func handleMultipleProjectsPermissions(projectPermissionsMap map[string][]models.Permission) error {
selectedProjects, err := getMultipleProjectsFromUser()
selectedProjects, err := prompt.GetProjectNamesFromUser()
if err != nil {
return fmt.Errorf("error selecting projects: %v", err)
}
Expand Down Expand Up @@ -269,35 +224,6 @@ func handlePerProjectPermissions(opts *create.CreateView, projectPermissionsMap
return nil
}

func buildMergedPermissions(projectPermissionsMap map[string][]models.Permission, accessesSystem []*models.Access) []*create.RobotPermission {
var mergedPermissions []*create.RobotPermission

// Add project permissions
for projectName, projectPermissions := range projectPermissionsMap {
var accessesProject []*models.Access
for _, perm := range projectPermissions {
accessesProject = append(accessesProject, &models.Access{
Resource: perm.Resource,
Action: perm.Action,
})
}
mergedPermissions = append(mergedPermissions, &create.RobotPermission{
Namespace: projectName,
Access: accessesProject,
Kind: "project",
})
}

// Add system permissions
mergedPermissions = append(mergedPermissions, &create.RobotPermission{
Namespace: "/",
Access: accessesSystem,
Kind: "system",
})

return mergedPermissions
}

func createRobotAndHandleResponse(opts *create.CreateView, exportToFile bool) error {
response, err := api.CreateRobot(*opts)
if err != nil {
Expand Down Expand Up @@ -367,34 +293,6 @@ func exportSecretToFile(name, secret, creationTime string, expiresAt int64) {
fmt.Printf("Secret saved to %s\n", filename)
}

func getMultipleProjectsFromUser() ([]string, error) {
allProjects, err := api.ListAllProjects()
if err != nil {
return nil, fmt.Errorf("failed to list projects: %v", err)
}

var selectedProjects []string
var projectOptions []huh.Option[string]

for _, p := range allProjects.Payload {
projectOptions = append(projectOptions, huh.NewOption(p.Name, p.Name))
}

err = huh.NewForm(
huh.NewGroup(
huh.NewNote().
Title("Multiple Project Selection").
Description("Select the projects to assign the same permissions to this robot account."),
huh.NewMultiSelect[string]().
Title("Select projects").
Options(projectOptions...).
Value(&selectedProjects),
),
).WithTheme(huh.ThemeCharm()).WithWidth(80).Run()

return selectedProjects, err
}

func promptMoreProjects() (bool, error) {
var addMore bool
err := huh.NewForm(
Expand Down
Loading
Loading