feat(server-nestjs): add Sécurité role to project system - #2675
Closed
shikanime wants to merge 8 commits into
Closed
feat(server-nestjs): add Sécurité role to project system#2675shikanime wants to merge 8 commits into
shikanime wants to merge 8 commits into
Conversation
Refs #2655 Co-authored-by: Automata <automata@shikanime.studio> Signed-off-by: Shikanime Deva <william.phetsinorath@shikanime.studio> Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr> Change-Id: Ideb5f2523e57a27b0fd5c77ca3b0b80b6a6a6964
Nexus testing utils use @msw/data Collection for faker-seeded project and repository models. Server initialized empty, handlers added in beforeEach. Refs #2655 Co-authored-by: Automata <automata@shikanime.studio> Signed-off-by: Shikanime Deva <william.phetsinorath@shikanime.studio> Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr> Change-Id: I1dc2e1d7e61d11c96c70279104c2672d6a6a6964
Vault testing utils use @msw/data Collection for faker-seeded secret engines and secrets. Server initialized empty, handlers added in beforeEach. Refs #2655 Co-authored-by: Automata <automata@shikanime.studio> Signed-off-by: Shikanime Deva <william.phetsinorath@shikanime.studio> Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr> Change-Id: I1ed87e505cc5a57922bdc0fa62621c596a6a6964
Registry testing utils use @msw/data Collection for faker-seeded Harbor projects, robots, quotas, members, repositories. Handlers split into per- resource subfunctions. makeRobotPermissions() extracted as factory. Refs #2655 Co-authored-by: Automata <automata@shikanime.studio> Signed-off-by: Shikanime Deva <william.phetsinorath@shikanime.studio> Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr> Change-Id: I3040943080a743eb0d3e5a55f782a9766a6a6964
Split makeNexusHandlers into per-resource subfunctions for readability: - makeNexusRepositoriesHandlers (maven/npm hosted + group CRUD) - makeNexusPrivilegesHandlers - makeNexusRolesHandlers - makeNexusSecurityHandlers Refs #2655 Co-authored-by: Automata <automata@shikanime.studio> Signed-off-by: Shikanime Deva <william.phetsinorath@shikanime.studio> Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr> Change-Id: I874229d36d4916baa5bc056f3c2c62886a6a6964
Split makeVaultHandlers into per-resource subfunctions for readability: - makeVaultKvHandlers (kv read/write/metadata/list) - makeVaultSysHandlers (policies, mounts, approle, auth methods) - makeVaultIdentityHandlers (identity group CRUD) - makeVaultTokenHandlers (token creation) Preserve existing factory functions: makeProjectWithDetails, makeZoneWithDetails, makeVaultSecret, makeVaultSecretMetadata Refs #2655 Co-authored-by: Automata <automata@shikanime.studio> Signed-off-by: Shikanime Deva <william.phetsinorath@shikanime.studio> Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr> Change-Id: If9d9d123a0a479f6ae769647190c1bca6a6a6964
…functions Split makeRegistryHandlers into per-resource subfunctions for readability: - makeRegistryProjectsHandlers - makeRegistryRepositoriesHandlers - makeRegistryQuotasHandlers - makeRegistryMembersHandlers - makeRegistryRobotsHandlers - makeRegistryRetentionsHandlers (db-free) Refs #2655 Co-authored-by: Automata <automata@shikanime.studio> Signed-off-by: Shikanime Deva <william.phetsinorath@shikanime.studio> Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr> Change-Id: I9f36acac127736e6e62883818eade0ee6a6a6964
shikanime
force-pushed
the
feature/add-security-role
branch
2 times, most recently
from
September 4, 2026 09:10
d0329d1 to
ddda755
Compare
- Add Security role with position 2 and permissions SEE_SECRETS|LIST_ENVIRONMENTS|LIST_REPOSITORIES - Update Developer role position from 2 → 3 - Update ReadOnly role position from 3 → 4 - Update test expectations accordingly
shikanime
force-pushed
the
feature/add-security-role
branch
from
September 4, 2026 09:11
ddda755 to
233cdfb
Compare
4 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Issues liées
Issues numéro:
Quel est le comportement actuel ?
Le système de rôles de projet n'a pas de rôle "Sécurité" dédié aux tâches de sécurité. Les rôles existants sont :
Quel est le nouveau comportement ?
SEE_SECRETS | LIST_ENVIRONMENTS | LIST_REPOSITORIES/${slug}/console/securityCe rôle permet aux équipes de sécurité d'accéder aux informations sensibles nécessaires à l'audit et au monitoring sans avoir accès aux opérations de développement.
Cette PR introduit-elle un breaking change ?
Non. Cette PR est rétrocompatible. Les rôles existants conservent leurs permissions.
Autres informations
Tests : Tous les 23 tests du module projet passent.
Documentation : À mettre à jour dans les docs d'API projet.
Migration : Aucune migration requise pour les projets existants.