Add adult/kids media groups for media split
The media services are splitting into an adult (fafflix) and kids (cheeztv) tier, and Authentik group membership will drive the media proxy's routing and authorization. This adds the two-tier RBAC groups so users can be assigned the right media access ahead of the provider/application wiring. - Add akP-media-fafflix and akP-media-cheeztv per-service permission entitlements (unbound, so they surface in the hierarchical ak_groups claim for the proxy) - Add akR-media-adult role nesting both fafflix and cheeztv (adults reach both) - Add akR-media-kids role nesting only cheeztv (kids reach kids services only)
This commit is contained in:
@@ -0,0 +1,8 @@
|
||||
# Role akR-media-adult (name = filename): adult media tier. Adults reach both the
|
||||
# adult ("fafflix") and kids ("cheeztv") services, so this role nests both
|
||||
# per-service entitlements. Membership propagates child -> parent, so a member
|
||||
# appears in both permission groups in the hierarchical `ak_groups` claim and the
|
||||
# media proxy routes/authorizes them for fafflix and cheeztv.
|
||||
permissions:
|
||||
- akP-media-fafflix
|
||||
- akP-media-cheeztv
|
||||
@@ -0,0 +1,7 @@
|
||||
# Role akR-media-kids (name = filename): kids media tier. Kids reach only the
|
||||
# kids ("cheeztv") service, so this role nests just that per-service entitlement.
|
||||
# Membership propagates child -> parent, so a member appears in akP-media-cheeztv
|
||||
# in the hierarchical `ak_groups` claim and the media proxy routes/authorizes
|
||||
# them for cheeztv only (never fafflix).
|
||||
permissions:
|
||||
- akP-media-cheeztv
|
||||
Reference in New Issue
Block a user