HasPermission checks if a set of scopes has permission for a given resource and HTTP method
(scopes []string, resource Resource, method string)
| 75 | |
| 76 | // HasPermission checks if a set of scopes has permission for a given resource and HTTP method |
| 77 | func HasPermission(scopes []string, resource Resource, method string) bool { |
| 78 | action := methodToAction[method] |
| 79 | if action == "" { |
| 80 | return false |
| 81 | } |
| 82 | |
| 83 | for _, scope := range scopes { |
| 84 | scopeResource, scopeAction := ParseScope(scope) |
| 85 | |
| 86 | // Check for wildcard resource |
| 87 | if scopeResource == ResourceAll { |
| 88 | if scopeAction == ActionAll || scopeAction == action { |
| 89 | return true |
| 90 | } |
| 91 | continue |
| 92 | } |
| 93 | |
| 94 | // Check for exact resource match |
| 95 | if scopeResource == resource { |
| 96 | if scopeAction == ActionAll || scopeAction == action { |
| 97 | return true |
| 98 | } |
| 99 | } |
| 100 | } |
| 101 | return false |
| 102 | } |