Skip to content

Commit

Permalink
Merge pull request #943 from opendevstack/remove-edit-role-to-system-…
Browse files Browse the repository at this point in the history
…authenticated

remove edit role to system:authenticated
  • Loading branch information
gerardcl committed Feb 17, 2021
2 parents 7ee2182 + 5093882 commit 1b40195
Show file tree
Hide file tree
Showing 3 changed files with 1 addition and 17 deletions.
1 change: 1 addition & 0 deletions CHANGELOG.md
Expand Up @@ -7,6 +7,7 @@

### Added
- Add changelog enforcer as GitHub Action to workflow ([#891](https://github.com/opendevstack/ods-core/issues/891))
- Narrow down system:authenticated permissions when creating new ODS project ([#942](https://github.com/opendevstack/ods-core/issues/942))

## [3.0] - 2020-08-11

Expand Down
5 changes: 0 additions & 5 deletions create-projects/create-projects.sh
Expand Up @@ -117,9 +117,4 @@ else
oc policy add-role-to-group view system:authenticated -n "${PROJECT_ID}-dev"
oc policy add-role-to-group view system:authenticated -n "${PROJECT_ID}-test"
oc policy add-role-to-group view system:authenticated -n "${PROJECT_ID}-cd"

echo "Allow all authenticated users to edit the project"
oc policy add-role-to-group edit system:authenticated -n "${PROJECT_ID}-dev"
oc policy add-role-to-group edit system:authenticated -n "${PROJECT_ID}-test"
oc policy add-role-to-group edit system:authenticated -n "${PROJECT_ID}-cd"
fi
12 changes: 0 additions & 12 deletions create-projects/tests/run.sh
Expand Up @@ -47,10 +47,6 @@ oc mock --receive 'policy add-role-to-group view system:authenticated -n foo-dev
oc mock --receive 'policy add-role-to-group view system:authenticated -n foo-test' --times 1
oc mock --receive 'policy add-role-to-group view system:authenticated -n foo-cd' --times 1

oc mock --receive 'policy add-role-to-group edit system:authenticated -n foo-dev' --times 1
oc mock --receive 'policy add-role-to-group edit system:authenticated -n foo-test' --times 1
oc mock --receive 'policy add-role-to-group edit system:authenticated -n foo-cd' --times 1

../create-projects.sh --project foo

oc mock --verify
Expand All @@ -69,10 +65,6 @@ oc mock --receive 'policy add-role-to-group view system:authenticated -n foo-dev
oc mock --receive 'policy add-role-to-group view system:authenticated -n foo-test' --times 1
oc mock --receive 'policy add-role-to-group view system:authenticated -n foo-cd' --times 1

oc mock --receive 'policy add-role-to-group edit system:authenticated -n foo-dev' --times 1
oc mock --receive 'policy add-role-to-group edit system:authenticated -n foo-test' --times 1
oc mock --receive 'policy add-role-to-group edit system:authenticated -n foo-cd' --times 1

../create-projects.sh --project foo --admins foo.bar@example.com,baz.qux@example.com --groups=

oc mock --verify
Expand Down Expand Up @@ -100,10 +92,6 @@ oc mock --receive 'policy add-role-to-group view system:authenticated -n foo-dev
oc mock --receive 'policy add-role-to-group view system:authenticated -n foo-test' --times 0
oc mock --receive 'policy add-role-to-group view system:authenticated -n foo-cd' --times 0

oc mock --receive 'policy add-role-to-group edit system:authenticated -n foo-dev' --times 0
oc mock --receive 'policy add-role-to-group edit system:authenticated -n foo-test' --times 0
oc mock --receive 'policy add-role-to-group edit system:authenticated -n foo-cd' --times 0

../create-projects.sh --project foo --groups USERGROUP=foo,ADMINGROUP=bar,READONLYGROUP=baz

oc mock --verify
Expand Down

0 comments on commit 1b40195

Please sign in to comment.