Security to-do list: accepted items, kept on the server
ci / fork-checks (pull_request) Successful in 1m57s
ci / build (pull_request) Successful in 7m44s

This commit is contained in:
2026-09-28 20:26:09 -07:00
parent 94a3a762b0
commit 4c53da5947
26 changed files with 1107 additions and 5 deletions
+4 -1
View File
@@ -304,7 +304,10 @@ impl Default for DefaultPermissions {
| Permission::SysDlpPolicyGet
| Permission::SysDlpPolicyUpdate
| Permission::SysDlpReviewGet
| Permission::SysDlpReviewUpdate => {
| Permission::SysDlpReviewUpdate
// inbuxa: every security check is server-wide (security
// to-do list spec)
| Permission::SysSecurityAccept => {
default.superuser.push(permission);
}
// inbuxa: AL-12: tenant administrators lock and delegate
@@ -31,7 +31,8 @@ use types::id::Id;
/// Granted to the default administrator roles: "Explain this"
/// (ai-explain spec, EX-4: superuser by default), the audit log, account
/// locks and legal holds (audit-hold-lock spec, AU-9, AL-12, LH-13), and
/// the data inventory (personal-data catalog spec).
/// the data inventory (personal-data catalog spec), and accepting security
/// to-do items (security to-do list spec).
const ADMIN_GRANTS: &[Permission] = &[
Permission::SysAiExplain,
Permission::SysAuditGet,
@@ -52,6 +53,7 @@ const ADMIN_GRANTS: &[Permission] = &[
Permission::SysDlpPolicyUpdate,
Permission::SysDlpReviewGet,
Permission::SysDlpReviewUpdate,
Permission::SysSecurityAccept,
];
/// Granted to the server-level Compliance Officer role once it exists: