Add configurable permissions for Actions job tokens #36452
+1,178
−0
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Implements configurable permissions for Actions job tokens as proposed in #24635.
This PR adds support for:
permissions:keyword (GitHub Actions compatible)permissions:overrideChanges
Database
action_token_permissions- Stores default permission configurationsaction_task- Addedtoken_scopesfield for calculated permissionsCore Features
Permission Configuration (
models/actions/token_permissions.go)Workflow Parser (
modules/actions/permissions.go)permissions:from workflow YAMLread-all,write-all,{}) and map formatsToken Scope Calculation (
models/actions/task.go)REST API (
routers/api/v1/repo/actions_permissions.go)GET /repos/{owner}/{repo}/actions/permissionsPUT /repos/{owner}/{repo}/actions/permissionsDocumentation
docs/content/usage/actions-token-permissions.en-us.md)IMPLEMENTATION_NOTES.md)Examples
Workflow with Permissions
Job-Level Override
API Usage
Compatibility
permissions:syntaxSecurity
Testing
Checklist
Related Issues
Closes #24635
Future Enhancements
Note: This is a comprehensive implementation that provides the foundation for configurable Actions token permissions. The syntax is fully compatible with GitHub Actions, making migration seamless for users.