mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-01 11:09:15 +02:00
usage_viewer saw account-wide usage but only its own request logs, so the people reviewing cost could not drill into the requests behind it. The role now also holds Read on agent_network.logs, which makes the access-log and session endpoints return every caller's rows instead of self-scoping. Logs can contain captured prompts, so this widens what the role exposes; policies, guardrails, budgets and settings stay hidden. Co-authored-by: Misha Bragin <bangvalo@gmail.com>
66 lines
2.0 KiB
Go
66 lines
2.0 KiB
Go
package roles
|
|
|
|
import (
|
|
"github.com/netbirdio/netbird/management/server/permissions/modules"
|
|
"github.com/netbirdio/netbird/management/server/permissions/operations"
|
|
"github.com/netbirdio/netbird/management/server/types"
|
|
)
|
|
|
|
// UsageViewer is the regular User baseline plus read access to the
|
|
// aggregated Agent Network usage and cost overview and to the account-wide
|
|
// request-level access logs (which can contain captured prompts), and
|
|
// read-only access to the resources the usage and log filters and display
|
|
// columns resolve against: users and groups (identity filters and name
|
|
// resolution), peers (agent principals in the caller column), and the
|
|
// provider list (provider and model filter options — the manager redacts
|
|
// connection config such as upstream URLs and operator-supplied header
|
|
// values for callers holding read without update). It sees no policies,
|
|
// guardrails, budgets, or Agent Network settings.
|
|
var UsageViewer = RolePermissions{
|
|
Role: types.UserRoleUsageViewer,
|
|
AutoAllowNew: map[operations.Operation]bool{
|
|
operations.Read: false,
|
|
operations.Create: false,
|
|
operations.Update: false,
|
|
operations.Delete: false,
|
|
},
|
|
Permissions: Permissions{
|
|
modules.AgentNetworkUsage: {
|
|
operations.Read: true,
|
|
operations.Create: false,
|
|
operations.Update: false,
|
|
operations.Delete: false,
|
|
},
|
|
modules.AgentNetworkLogs: {
|
|
operations.Read: true,
|
|
operations.Create: false,
|
|
operations.Update: false,
|
|
operations.Delete: false,
|
|
},
|
|
modules.AgentNetworkProviders: {
|
|
operations.Read: true,
|
|
operations.Create: false,
|
|
operations.Update: false,
|
|
operations.Delete: false,
|
|
},
|
|
modules.Users: {
|
|
operations.Read: true,
|
|
operations.Create: false,
|
|
operations.Update: false,
|
|
operations.Delete: false,
|
|
},
|
|
modules.Groups: {
|
|
operations.Read: true,
|
|
operations.Create: false,
|
|
operations.Update: false,
|
|
operations.Delete: false,
|
|
},
|
|
modules.Peers: {
|
|
operations.Read: true,
|
|
operations.Create: false,
|
|
operations.Update: false,
|
|
operations.Delete: false,
|
|
},
|
|
},
|
|
}
|