From 982ea74185f4f10763c4f8c64c9bfdcf5a89228e Mon Sep 17 00:00:00 2001 From: hongming Date: Sat, 25 Jul 2020 08:58:59 +0800 Subject: [PATCH] fix RBAC authorizer Signed-off-by: hongming --- pkg/apiserver/authorization/authorizerfactory/rbac.go | 2 +- pkg/models/iam/am/am.go | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/pkg/apiserver/authorization/authorizerfactory/rbac.go b/pkg/apiserver/authorization/authorizerfactory/rbac.go index 53aae31a5..a39cbaeb2 100644 --- a/pkg/apiserver/authorization/authorizerfactory/rbac.go +++ b/pkg/apiserver/authorization/authorizerfactory/rbac.go @@ -249,7 +249,7 @@ func (r *RBACAuthorizer) visitRulesFor(requestAttributes authorizer.Attributes, workspace = requestAttributes.GetWorkspace() } - if workspaceRoleBindings, err := r.am.ListWorkspaceRoleBindings("", requestAttributes.GetWorkspace()); err != nil { + if workspaceRoleBindings, err := r.am.ListWorkspaceRoleBindings("", workspace); err != nil { if !visitor(nil, "", nil, err) { return } diff --git a/pkg/models/iam/am/am.go b/pkg/models/iam/am/am.go index 90d1d46cb..2c43baca1 100644 --- a/pkg/models/iam/am/am.go +++ b/pkg/models/iam/am/am.go @@ -843,12 +843,12 @@ func (am *amOperator) CreateOrUpdateNamespaceRole(namespace string, role *rbacv1 var aggregateRoles []string if err := json.Unmarshal([]byte(role.Annotations[iamv1alpha2.AggregationRolesAnnotation]), &aggregateRoles); err == nil { for _, roleName := range aggregateRoles { - role, err := am.GetNamespaceRole(namespace, roleName) + aggregationRole, err := am.GetNamespaceRole(namespace, roleName) if err != nil { klog.Error(err) return nil, err } - role.Rules = append(role.Rules, role.Rules...) + role.Rules = append(role.Rules, aggregationRole.Rules...) } }