Add adult/kids media groups for media split
The media services are splitting into an adult (fafflix) and kids (cheeztv) tier, and Authentik group membership will drive the media proxy's routing and authorization. This adds the two-tier RBAC groups so users can be assigned the right media access ahead of the provider/application wiring. - Add akP-media-fafflix and akP-media-cheeztv per-service permission entitlements (unbound, so they surface in the hierarchical ak_groups claim for the proxy) - Add akR-media-adult role nesting both fafflix and cheeztv (adults reach both) - Add akR-media-kids role nesting only cheeztv (kids reach kids services only)
This commit is contained in:
@@ -0,0 +1,6 @@
|
||||
# Permission group akP-media-cheeztv (name = filename). Per-service entitlement
|
||||
# for the kids ("cheeztv") media tier: NOT bound to any application (no
|
||||
# `application` field), so it does not gate OIDC. It exists purely to appear in
|
||||
# the user's hierarchical `ak_groups` claim, which the media proxy reads to
|
||||
# decide whether to route/authorize the cheeztv backend.
|
||||
attributes: {}
|
||||
@@ -0,0 +1,6 @@
|
||||
# Permission group akP-media-fafflix (name = filename). Per-service entitlement
|
||||
# for the adult ("fafflix") media tier: NOT bound to any application (no
|
||||
# `application` field), so it does not gate OIDC. It exists purely to appear in
|
||||
# the user's hierarchical `ak_groups` claim, which the media proxy reads to
|
||||
# decide whether to route/authorize the fafflix backend.
|
||||
attributes: {}
|
||||
@@ -0,0 +1,8 @@
|
||||
# Role akR-media-adult (name = filename): adult media tier. Adults reach both the
|
||||
# adult ("fafflix") and kids ("cheeztv") services, so this role nests both
|
||||
# per-service entitlements. Membership propagates child -> parent, so a member
|
||||
# appears in both permission groups in the hierarchical `ak_groups` claim and the
|
||||
# media proxy routes/authorizes them for fafflix and cheeztv.
|
||||
permissions:
|
||||
- akP-media-fafflix
|
||||
- akP-media-cheeztv
|
||||
@@ -0,0 +1,7 @@
|
||||
# Role akR-media-kids (name = filename): kids media tier. Kids reach only the
|
||||
# kids ("cheeztv") service, so this role nests just that per-service entitlement.
|
||||
# Membership propagates child -> parent, so a member appears in akP-media-cheeztv
|
||||
# in the hierarchical `ak_groups` claim and the media proxy routes/authorizes
|
||||
# them for cheeztv only (never fafflix).
|
||||
permissions:
|
||||
- akP-media-cheeztv
|
||||
Reference in New Issue
Block a user