mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-10-05 14:17:58 +02:00
check for superusers when creating normal teams
This commit is contained in:
@@ -1160,9 +1160,11 @@ func (c *Cluster) initHumanUsers() error {
|
||||
|
||||
additionalTeams := c.PgTeamMap.GetAdditionalTeams(c.Spec.TeamID, true)
|
||||
for _, additionalTeam := range additionalTeams {
|
||||
err := c.initTeamMembers(additionalTeam, false)
|
||||
if err != nil {
|
||||
return fmt.Errorf("Cannot create additional team %q for cluster owner by %q: %v", additionalTeam, c.Spec.TeamID, err)
|
||||
if !(util.SliceContains(superuserTeams, additionalTeam)) {
|
||||
err := c.initTeamMembers(additionalTeam, false)
|
||||
if err != nil {
|
||||
return fmt.Errorf("Cannot create additional team %q for cluster owner by %q: %v", additionalTeam, c.Spec.TeamID, err)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -26,7 +26,7 @@ var (
|
||||
Name: "teamAB",
|
||||
},
|
||||
Spec: acidv1.PostgresTeamSpec{
|
||||
AdditionalSuperuserTeams: map[string][]string{"teamA": []string{"teamB", "team24/7"}, "teamB": []string{"teamA", "team24/7"}},
|
||||
AdditionalSuperuserTeams: map[string][]string{"teamA": []string{"teamB", "team24/7"}, "teamB": []string{"teamA", "teamC", "team24/7"}},
|
||||
AdditionalTeams: map[string][]string{"teamA": []string{"teamC"}, "teamB": []string{}},
|
||||
AdditionalMembers: map[string][]string{"team24/7": []string{"optimusprime"}, "teamB": []string{"drno"}},
|
||||
},
|
||||
@@ -66,7 +66,7 @@ func TestLoadingPostgresTeamCRD(t *testing.T) {
|
||||
AdditionalMembers: nil,
|
||||
},
|
||||
"teamB": {
|
||||
AdditionalSuperuserTeams: []string{"teamA", "team24/7"},
|
||||
AdditionalSuperuserTeams: []string{"teamA", "teamC", "team24/7"},
|
||||
AdditionalTeams: []string{},
|
||||
AdditionalMembers: []string{"drno"},
|
||||
},
|
||||
@@ -153,17 +153,17 @@ func TestGetAdditionalSuperuserTeams(t *testing.T) {
|
||||
error string
|
||||
}{
|
||||
{
|
||||
"Check that additional teams are returned",
|
||||
"Check that additional superuser teams are returned",
|
||||
"teamA",
|
||||
false,
|
||||
[]string{"teamB", "team24/7"},
|
||||
"GetAdditionalTeams returns wrong list",
|
||||
},
|
||||
{
|
||||
"Check that additional teams are returned incl. transitive teams",
|
||||
"Check that additional superuser teams are returned incl. transitive superuser teams",
|
||||
"teamA",
|
||||
true,
|
||||
[]string{"teamB", "team24/7"},
|
||||
[]string{"teamB", "teamC", "team24/7"},
|
||||
"GetAdditionalTeams returns wrong list",
|
||||
},
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user