-
Notifications
You must be signed in to change notification settings - Fork 32
/
policies.go
137 lines (115 loc) · 3.32 KB
/
policies.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
package api
import (
"context"
"net/url"
"github.com/arigatomachine/cli/envelope"
"github.com/arigatomachine/cli/identity"
"github.com/arigatomachine/cli/primitive"
)
// PoliciesClient makes proxied requests to the registry's policies endpoints
type PoliciesClient struct {
client *Client
}
// PolicyAttachmentResult is the payload returned for a policy_attachment object
type PolicyAttachmentResult struct {
ID *identity.ID `json:"id"`
Version uint8 `json:"version"`
Body *primitive.PolicyAttachment `json:"body"`
}
// PoliciesResult is the payload returned for a policy object
type PoliciesResult struct {
ID *identity.ID `json:"id"`
Version uint8 `json:"version"`
Body *primitive.Policy `json:"body"`
}
// Create creates a new policy
func (p *PoliciesClient) Create(ctx context.Context, policy *primitive.Policy) (*PoliciesResult, error) {
ID, err := identity.NewMutable(policy)
if err != nil {
return nil, err
}
env := envelope.Unsigned{
ID: &ID,
Version: 1,
Body: policy,
}
req, _, err := p.client.NewRequest("POST", "/policies", nil, env, true)
if err != nil {
return nil, err
}
res := PoliciesResult{}
_, err = p.client.Do(ctx, req, &res, nil, nil)
return &res, err
}
// List retrieves relevant policiies by orgID and/or name
func (p *PoliciesClient) List(ctx context.Context, orgID *identity.ID, name string) ([]PoliciesResult, error) {
v := &url.Values{}
if orgID != nil {
v.Set("org_id", orgID.String())
}
if name != "" {
v.Set("name", name)
}
req, _, err := p.client.NewRequest("GET", "/policies", v, nil, true)
if err != nil {
return nil, err
}
policies := []PoliciesResult{}
_, err = p.client.Do(ctx, req, &policies, nil, nil)
return policies, err
}
// Attach attaches a policy to a team
func (p *PoliciesClient) Attach(ctx context.Context, org, policy, team *identity.ID) error {
attachment := primitive.PolicyAttachment{
OrgID: org,
OwnerID: team,
PolicyID: policy,
}
ID, err := identity.NewMutable(&attachment)
if err != nil {
return err
}
env := envelope.Unsigned{
ID: &ID,
Version: 1,
Body: &attachment,
}
req, _, err := p.client.NewRequest("POST", "/policy-attachments", nil, &env, true)
if err != nil {
return err
}
_, err = p.client.Do(ctx, req, nil, nil, nil)
return err
}
// Detach deletes a specific attachment
func (p *PoliciesClient) Detach(ctx context.Context, attachmentID *identity.ID) error {
req, _, err := p.client.NewRequest("DELETE", "/policy-attachments/"+attachmentID.String(), nil, nil, true)
if err != nil {
return err
}
_, err = p.client.Do(ctx, req, nil, nil, nil)
if err != nil {
return err
}
return nil
}
// AttachmentsList retrieves all policy attachments for an org
func (p *PoliciesClient) AttachmentsList(ctx context.Context, orgID, ownerID, policyID *identity.ID) ([]PolicyAttachmentResult, error) {
v := &url.Values{}
if orgID != nil {
v.Set("org_id", orgID.String())
}
if ownerID != nil {
v.Set("owner_id", ownerID.String())
}
if policyID != nil {
v.Set("policy_id", policyID.String())
}
req, _, err := p.client.NewRequest("GET", "/policy-attachments", v, nil, true)
if err != nil {
return nil, err
}
attachments := []PolicyAttachmentResult{}
_, err = p.client.Do(ctx, req, &attachments, nil, nil)
return attachments, err
}