auth: warn on unknown [[oper]] privilege names instead of silently dropping them
All checks were successful
CI / check (push) Successful in 3m53s

This commit is contained in:
Jean Chevronnet 2026-07-17 12:45:41 +00:00
parent cfe05481d6
commit 1fb3615b7e
No known key found for this signature in database
4 changed files with 76 additions and 14 deletions

View file

@ -130,6 +130,18 @@ impl Config {
}
map
}
// (account, unrecognised-privilege-name) pairs across all [[oper]] blocks, so
// the caller can warn about a typo that would otherwise silently grant nothing.
pub fn oper_priv_warnings(&self) -> Vec<(String, String)> {
self.oper
.iter()
.flat_map(|o| {
let (_, unknown) = echo_api::Privs::parse_names(&o.privs);
unknown.into_iter().map(move |name| (o.account.clone(), name))
})
.collect()
}
}
// The service modules to bring up at burst. Each name maps to a compiled-in