10000 fix: add org role read permissions · coder/coder@a3db217 · GitHub
[go: up one dir, main page]

Skip to content

Commit a3db217

Browse files
committed
fix: add org role read permissions
1 parent cccdf1e commit a3db217

File tree

1 file changed

+4
-2
lines changed

1 file changed

+4
-2
lines changed

coderd/rbac/roles.go

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -307,7 +307,8 @@ func ReloadBuiltinRoles(opts *RoleOptions) {
307307
Identifier: RoleAuditor(),
308308
DisplayName: "Auditor",
309309
Site: Permissions(map[string][]policy.Action{
310-
ResourceAuditLog.Type: {policy.ActionRead},
310+
ResourceAssignOrgRole.Type: {policy.ActionRead},
311+
ResourceAuditLog.Type: {policy.ActionRead},
311312
// Allow auditors to see the resources that audit logs reflect.
312313
ResourceTemplate.Type: {policy.ActionRead, policy.ActionViewInsights},
313314
ResourceUser.Type: {policy.ActionRead},
@@ -327,7 +328,8 @@ func ReloadBuiltinRoles(opts *RoleOptions) {
327328
Identifier: RoleTemplateAdmin(),
328329
DisplayName: "Template Admin",
329330
Site: Permissions(map[string][]policy.Action{
330-
ResourceTemplate.Type: ResourceTemplate.AvailableActions(),
331+
ResourceAssignOrgRole.Type: {policy.ActionRead},
332+
ResourceTemplate.Type: ResourceTemplate.AvailableActions(),
331333
// CRUD all files, even those they did not upload.
332334
ResourceFile.Type: {policy.ActionCreate, policy.ActionRead},
333335
ResourceWorkspace.Type: {policy.ActionRead},

0 commit comments

Comments
 (0)
0