-
Story
-
Resolution: Done
-
Critical
-
None
-
None
-
False
-
-
False
-
-
This is a follow up on the work for adding permission check on the various orchestrator plugin endpoint. A missing piece of the plugin is that there is no way to allow/disallow actions on some of the workflows - it is either the user authorized or not at all to perform an action, no matter what the workflow is.
This work will add the necessary controls for those user stories:
As an admin I want to allow to view a specific workflow for a group or user
As an admin I want to allow to execute a specific workflow for a group or user
As an admin I want to allow to view a specific workflow instance for a group or user
Related spike #flpath-1305
- is related to
-
FLPATH-2099 1.4 rc9 rbac update policy required for write and use policy does nothing
-
- Closed
-
-
FLPATH-1944 [qe] Test Finer Grained Permission on Workflows (automate tests)
-
- Closed
-
- relates to
-
FLPATH-2035 Fine grained auth polices/roles from policy.yaml look wrong in backstage ui roles edit page
-
- New
-
-
FLPATH-2032 Backstage UI create role only has "orchestrator.workflow" available
-
- Closed
-
-
FLPATH-2034 No apparent way to create fine grained auth roles in backstage ui
-
- Closed
-
-
FLPATH-2036 [doc] Permissions doc should specify what the workflowid is for fine grained auth permissions
-
- Closed
-
-
FLPATH-2033 [doc] Permissions.md doc has orchestrator.workflow.use as "read" policy
-
- Closed
-
- links to