Redact provider connection config for read-only viewers and canonicalize Bedrock ids in setup

The provider read grant now serves usage_viewer the display surface only:
the manager blanks upstream URL, operator-typed header values, identity
header names, and the TLS override for callers holding read without
update. The me/setup model intersection compares declared ids through the
same normalization the proxy's parser applies, so a Bedrock declaration
in region/version form still advertises when its canonical id is
allowlisted. Docs and comments now say account-wide for the logs
exclusion and describe the real group source shared with enforcement.
This commit is contained in:
mlsmaycon
2026-08-27 08:07:20 +00:00
parent 6b38bd9c71
commit c995d89830
7 changed files with 199 additions and 8 deletions
@@ -11,8 +11,12 @@ import (
// to the resources the usage filters and display columns resolve against:
// users and groups (identity filters and name resolution), peers (agent
// principals in the caller column), and the provider list (provider and
// model filter options). It sees no policies and no request-level access
// logs (which can contain captured prompts).
// model filter options — the manager redacts connection config such as
// upstream URLs and operator-supplied header values for callers holding
// read without update). It sees no policies and no account-wide
// request-level access logs (which can contain captured prompts); its own
// requests remain readable through the self-scoped endpoints, like any
// caller's.
var UsageViewer = RolePermissions{
Role: types.UserRoleUsageViewer,
AutoAllowNew: map[operations.Operation]bool{