add resourcescope to AttributesRecord when determine whether the user can list namespace

This commit is contained in:
wanjunlei
2020-06-24 22:55:33 +08:00
parent dba32a1c5b
commit 9a02d77093

View File

@@ -702,10 +702,9 @@ func (t *tenantOperator) Auditing(user user.Info, queryParam *auditingv1alpha1.Q
listEvts := authorizer.AttributesRecord{
User: user,
Verb: "list",
APIGroup: "",
APIVersion: "v1",
Resource: "namespaces",
ResourceRequest: true,
ResourceScope: request.ClusterScope,
}
decision, _, err := t.authorizer.Authorize(listEvts)
if err != nil {