Class: Conjur::Role

Inherits:
RestClient::Resource
  • Object
show all
Includes:
Exists, PathBased
Defined in:
lib/conjur/role.rb

Instance Method Summary collapse

Methods included from PathBased

#account, #kind

Methods included from Exists

#exists?

Instance Method Details

#all(options = {}) ⇒ Object



48
49
50
51
52
53
54
55
56
57
58
# File 'lib/conjur/role.rb', line 48

def all(options = {})
  query_string = "?all"
  
  if filter = options.delete(:filter)
    filter = [filter] unless filter.is_a?(Array)
    (query_string << "&" << filter.to_query("filter")) unless filter.empty?
  end
  JSON.parse(self[query_string].get(options)).collect do |id|
    Role.new(Conjur::Authz::API.host, self.options)[Conjur::API.parse_role_id(id).join('/')]
  end
end

#create(options = {}) ⇒ Object



38
39
40
41
42
43
44
45
46
# File 'lib/conjur/role.rb', line 38

def create(options = {})
  log do |logger|
    logger << "Creating role #{kind}:#{identifier}"
    unless options.empty?
      logger << " with options #{options.to_json}"
    end
  end
  self.put(options)
end

#grant_to(member, options = {}) ⇒ Object



64
65
66
67
68
69
70
71
72
# File 'lib/conjur/role.rb', line 64

def grant_to(member, options={})
  log do |logger|
    logger << "Granting role #{identifier} to #{member}"
    unless options.blank?
      logger << " with options #{options.to_json}"
    end
  end
  self["?members&member=#{query_escape member}"].put(options)
end

#identifierObject Also known as: id



28
29
30
# File 'lib/conjur/role.rb', line 28

def identifier
  match_path(3..-1)
end

#member_of?(other_role) ⇒ Boolean

Returns:

  • (Boolean)


60
61
62
# File 'lib/conjur/role.rb', line 60

def member_of?(other_role)
  not all(filter: (other_role.roleid rescue other_role)).empty?
end

#membersObject



92
93
94
95
96
# File 'lib/conjur/role.rb', line 92

def members
  JSON.parse(self["?members"].get(options)).collect do |json|
    RoleGrant.parse_from_json(json, self.options)
  end
end

#permitted?(resource_id, privilege, options = {}) ⇒ Boolean

Returns:

  • (Boolean)


84
85
86
87
88
89
90
# File 'lib/conjur/role.rb', line 84

def permitted?(resource_id, privilege, options = {})
  # NOTE: in previous versions there was 'kind' passed separately. Now it is part of id
  self["?check&resource_id=#{query_escape resource_id}&privilege=#{query_escape privilege}"].get(options)
  true
rescue RestClient::ResourceNotFound
  false
end

#revoke_from(member, options = {}) ⇒ Object



74
75
76
77
78
79
80
81
82
# File 'lib/conjur/role.rb', line 74

def revoke_from(member, options = {})
  log do |logger|
    logger << "Revoking role #{identifier} from #{member}"
    unless options.empty?
      logger << " with options #{options.to_json}"
    end
  end
  self["?members&member=#{query_escape member}"].delete(options)
end

#roleidObject



34
35
36
# File 'lib/conjur/role.rb', line 34

def roleid
  [ , kind, identifier ].join(':')
end