Merge pull request #2431 from Infisical/misc/terraform-project-group-prereq

misc: setup prerequisites for terraform project group
This commit is contained in:
Maidul Islam
2024-09-23 11:21:46 -04:00
committed by GitHub
24 changed files with 556 additions and 233 deletions
+70 -22
View File
@@ -10,7 +10,7 @@ export const registerGroupRouter = async (server: FastifyZodProvider) => {
server.route({ server.route({
url: "/", url: "/",
method: "POST", method: "POST",
onRequest: verifyAuth([AuthMode.JWT]), onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
schema: { schema: {
body: z.object({ body: z.object({
name: z.string().trim().min(1).max(50).describe(GROUPS.CREATE.name), name: z.string().trim().min(1).max(50).describe(GROUPS.CREATE.name),
@@ -43,12 +43,59 @@ export const registerGroupRouter = async (server: FastifyZodProvider) => {
}); });
server.route({ server.route({
url: "/:currentSlug", url: "/:id",
method: "PATCH", method: "GET",
onRequest: verifyAuth([AuthMode.JWT]), onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
schema: { schema: {
params: z.object({ params: z.object({
currentSlug: z.string().trim().describe(GROUPS.UPDATE.currentSlug) id: z.string()
}),
response: {
200: GroupsSchema
}
},
handler: async (req) => {
const group = await server.services.group.getGroupById({
actor: req.permission.type,
actorId: req.permission.id,
actorAuthMethod: req.permission.authMethod,
actorOrgId: req.permission.orgId,
id: req.params.id
});
return group;
}
});
server.route({
url: "/",
method: "GET",
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
schema: {
response: {
200: GroupsSchema.array()
}
},
handler: async (req) => {
const groups = await server.services.org.getOrgGroups({
actor: req.permission.type,
actorId: req.permission.id,
orgId: req.permission.orgId,
actorAuthMethod: req.permission.authMethod,
actorOrgId: req.permission.orgId
});
return groups;
}
});
server.route({
url: "/:id",
method: "PATCH",
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
schema: {
params: z.object({
id: z.string().trim().describe(GROUPS.UPDATE.id)
}), }),
body: z body: z
.object({ .object({
@@ -70,7 +117,7 @@ export const registerGroupRouter = async (server: FastifyZodProvider) => {
}, },
handler: async (req) => { handler: async (req) => {
const group = await server.services.group.updateGroup({ const group = await server.services.group.updateGroup({
currentSlug: req.params.currentSlug, id: req.params.id,
actor: req.permission.type, actor: req.permission.type,
actorId: req.permission.id, actorId: req.permission.id,
actorAuthMethod: req.permission.authMethod, actorAuthMethod: req.permission.authMethod,
@@ -83,12 +130,12 @@ export const registerGroupRouter = async (server: FastifyZodProvider) => {
}); });
server.route({ server.route({
url: "/:slug", url: "/:id",
method: "DELETE", method: "DELETE",
onRequest: verifyAuth([AuthMode.JWT]), onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
schema: { schema: {
params: z.object({ params: z.object({
slug: z.string().trim().describe(GROUPS.DELETE.slug) id: z.string().trim().describe(GROUPS.DELETE.id)
}), }),
response: { response: {
200: GroupsSchema 200: GroupsSchema
@@ -96,7 +143,7 @@ export const registerGroupRouter = async (server: FastifyZodProvider) => {
}, },
handler: async (req) => { handler: async (req) => {
const group = await server.services.group.deleteGroup({ const group = await server.services.group.deleteGroup({
groupSlug: req.params.slug, id: req.params.id,
actor: req.permission.type, actor: req.permission.type,
actorId: req.permission.id, actorId: req.permission.id,
actorAuthMethod: req.permission.authMethod, actorAuthMethod: req.permission.authMethod,
@@ -109,11 +156,11 @@ export const registerGroupRouter = async (server: FastifyZodProvider) => {
server.route({ server.route({
method: "GET", method: "GET",
url: "/:slug/users", url: "/:id/users",
onRequest: verifyAuth([AuthMode.JWT]), onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
schema: { schema: {
params: z.object({ params: z.object({
slug: z.string().trim().describe(GROUPS.LIST_USERS.slug) id: z.string().trim().describe(GROUPS.LIST_USERS.id)
}), }),
querystring: z.object({ querystring: z.object({
offset: z.coerce.number().min(0).max(100).default(0).describe(GROUPS.LIST_USERS.offset), offset: z.coerce.number().min(0).max(100).default(0).describe(GROUPS.LIST_USERS.offset),
@@ -141,24 +188,25 @@ export const registerGroupRouter = async (server: FastifyZodProvider) => {
}, },
handler: async (req) => { handler: async (req) => {
const { users, totalCount } = await server.services.group.listGroupUsers({ const { users, totalCount } = await server.services.group.listGroupUsers({
groupSlug: req.params.slug, id: req.params.id,
actor: req.permission.type, actor: req.permission.type,
actorId: req.permission.id, actorId: req.permission.id,
actorAuthMethod: req.permission.authMethod, actorAuthMethod: req.permission.authMethod,
actorOrgId: req.permission.orgId, actorOrgId: req.permission.orgId,
...req.query ...req.query
}); });
return { users, totalCount }; return { users, totalCount };
} }
}); });
server.route({ server.route({
method: "POST", method: "POST",
url: "/:slug/users/:username", url: "/:id/users/:username",
onRequest: verifyAuth([AuthMode.JWT]), onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
schema: { schema: {
params: z.object({ params: z.object({
slug: z.string().trim().describe(GROUPS.ADD_USER.slug), id: z.string().trim().describe(GROUPS.ADD_USER.id),
username: z.string().trim().describe(GROUPS.ADD_USER.username) username: z.string().trim().describe(GROUPS.ADD_USER.username)
}), }),
response: { response: {
@@ -173,7 +221,7 @@ export const registerGroupRouter = async (server: FastifyZodProvider) => {
}, },
handler: async (req) => { handler: async (req) => {
const user = await server.services.group.addUserToGroup({ const user = await server.services.group.addUserToGroup({
groupSlug: req.params.slug, id: req.params.id,
username: req.params.username, username: req.params.username,
actor: req.permission.type, actor: req.permission.type,
actorId: req.permission.id, actorId: req.permission.id,
@@ -187,11 +235,11 @@ export const registerGroupRouter = async (server: FastifyZodProvider) => {
server.route({ server.route({
method: "DELETE", method: "DELETE",
url: "/:slug/users/:username", url: "/:id/users/:username",
onRequest: verifyAuth([AuthMode.JWT]), onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
schema: { schema: {
params: z.object({ params: z.object({
slug: z.string().trim().describe(GROUPS.DELETE_USER.slug), id: z.string().trim().describe(GROUPS.DELETE_USER.id),
username: z.string().trim().describe(GROUPS.DELETE_USER.username) username: z.string().trim().describe(GROUPS.DELETE_USER.username)
}), }),
response: { response: {
@@ -206,7 +254,7 @@ export const registerGroupRouter = async (server: FastifyZodProvider) => {
}, },
handler: async (req) => { handler: async (req) => {
const user = await server.services.group.removeUserFromGroup({ const user = await server.services.group.removeUserFromGroup({
groupSlug: req.params.slug, id: req.params.id,
username: req.params.username, username: req.params.username,
actor: req.permission.type, actor: req.permission.type,
actorId: req.permission.id, actorId: req.permission.id,
+47 -27
View File
@@ -3,7 +3,7 @@ import slugify from "@sindresorhus/slugify";
import { OrgMembershipRole, TOrgRoles } from "@app/db/schemas"; import { OrgMembershipRole, TOrgRoles } from "@app/db/schemas";
import { isAtLeastAsPrivileged } from "@app/lib/casl"; import { isAtLeastAsPrivileged } from "@app/lib/casl";
import { BadRequestError, ForbiddenRequestError } from "@app/lib/errors"; import { BadRequestError, ForbiddenRequestError, NotFoundError } from "@app/lib/errors";
import { alphaNumericNanoId } from "@app/lib/nanoid"; import { alphaNumericNanoId } from "@app/lib/nanoid";
import { TGroupProjectDALFactory } from "@app/services/group-project/group-project-dal"; import { TGroupProjectDALFactory } from "@app/services/group-project/group-project-dal";
import { TOrgDALFactory } from "@app/services/org/org-dal"; import { TOrgDALFactory } from "@app/services/org/org-dal";
@@ -21,6 +21,7 @@ import {
TAddUserToGroupDTO, TAddUserToGroupDTO,
TCreateGroupDTO, TCreateGroupDTO,
TDeleteGroupDTO, TDeleteGroupDTO,
TGetGroupByIdDTO,
TListGroupUsersDTO, TListGroupUsersDTO,
TRemoveUserFromGroupDTO, TRemoveUserFromGroupDTO,
TUpdateGroupDTO TUpdateGroupDTO
@@ -29,7 +30,7 @@ import { TUserGroupMembershipDALFactory } from "./user-group-membership-dal";
type TGroupServiceFactoryDep = { type TGroupServiceFactoryDep = {
userDAL: Pick<TUserDALFactory, "find" | "findUserEncKeyByUserIdsBatch" | "transaction" | "findOne">; userDAL: Pick<TUserDALFactory, "find" | "findUserEncKeyByUserIdsBatch" | "transaction" | "findOne">;
groupDAL: Pick<TGroupDALFactory, "create" | "findOne" | "update" | "delete" | "findAllGroupMembers">; groupDAL: Pick<TGroupDALFactory, "create" | "findOne" | "update" | "delete" | "findAllGroupMembers" | "findById">;
groupProjectDAL: Pick<TGroupProjectDALFactory, "find">; groupProjectDAL: Pick<TGroupProjectDALFactory, "find">;
orgDAL: Pick<TOrgDALFactory, "findMembership" | "countAllOrgMembers">; orgDAL: Pick<TOrgDALFactory, "findMembership" | "countAllOrgMembers">;
userGroupMembershipDAL: Pick< userGroupMembershipDAL: Pick<
@@ -95,7 +96,7 @@ export const groupServiceFactory = ({
}; };
const updateGroup = async ({ const updateGroup = async ({
currentSlug, id,
name, name,
slug, slug,
role, role,
@@ -121,8 +122,10 @@ export const groupServiceFactory = ({
message: "Failed to update group due to plan restrictio Upgrade plan to update group." message: "Failed to update group due to plan restrictio Upgrade plan to update group."
}); });
const group = await groupDAL.findOne({ orgId: actorOrgId, slug: currentSlug }); const group = await groupDAL.findOne({ orgId: actorOrgId, id });
if (!group) throw new BadRequestError({ message: `Failed to find group with slug ${currentSlug}` }); if (!group) {
throw new BadRequestError({ message: `Failed to find group with ID ${id}` });
}
let customRole: TOrgRoles | undefined; let customRole: TOrgRoles | undefined;
if (role) { if (role) {
@@ -140,8 +143,7 @@ export const groupServiceFactory = ({
const [updatedGroup] = await groupDAL.update( const [updatedGroup] = await groupDAL.update(
{ {
orgId: actorOrgId, id: group.id
slug: currentSlug
}, },
{ {
name, name,
@@ -158,7 +160,7 @@ export const groupServiceFactory = ({
return updatedGroup; return updatedGroup;
}; };
const deleteGroup = async ({ groupSlug, actor, actorId, actorAuthMethod, actorOrgId }: TDeleteGroupDTO) => { const deleteGroup = async ({ id, actor, actorId, actorAuthMethod, actorOrgId }: TDeleteGroupDTO) => {
if (!actorOrgId) throw new BadRequestError({ message: "Failed to create group without organization" }); if (!actorOrgId) throw new BadRequestError({ message: "Failed to create group without organization" });
const { permission } = await permissionService.getOrgPermission( const { permission } = await permissionService.getOrgPermission(
@@ -178,15 +180,39 @@ export const groupServiceFactory = ({
}); });
const [group] = await groupDAL.delete({ const [group] = await groupDAL.delete({
orgId: actorOrgId, id,
slug: groupSlug orgId: actorOrgId
}); });
return group; return group;
}; };
const getGroupById = async ({ id, actor, actorId, actorAuthMethod, actorOrgId }: TGetGroupByIdDTO) => {
if (!actorOrgId) {
throw new BadRequestError({ message: "Failed to read group without organization" });
}
const { permission } = await permissionService.getOrgPermission(
actor,
actorId,
actorOrgId,
actorAuthMethod,
actorOrgId
);
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Read, OrgPermissionSubjects.Groups);
const group = await groupDAL.findById(id);
if (!group) {
throw new NotFoundError({
message: `Cannot find group with ID ${id}`
});
}
return group;
};
const listGroupUsers = async ({ const listGroupUsers = async ({
groupSlug, id,
offset, offset,
limit, limit,
username, username,
@@ -208,12 +234,12 @@ export const groupServiceFactory = ({
const group = await groupDAL.findOne({ const group = await groupDAL.findOne({
orgId: actorOrgId, orgId: actorOrgId,
slug: groupSlug id
}); });
if (!group) if (!group)
throw new BadRequestError({ throw new BadRequestError({
message: `Failed to find group with slug ${groupSlug}` message: `Failed to find group with ID ${id}`
}); });
const users = await groupDAL.findAllGroupMembers({ const users = await groupDAL.findAllGroupMembers({
@@ -229,14 +255,7 @@ export const groupServiceFactory = ({
return { users, totalCount: count }; return { users, totalCount: count };
}; };
const addUserToGroup = async ({ const addUserToGroup = async ({ id, username, actor, actorId, actorAuthMethod, actorOrgId }: TAddUserToGroupDTO) => {
groupSlug,
username,
actor,
actorId,
actorAuthMethod,
actorOrgId
}: TAddUserToGroupDTO) => {
if (!actorOrgId) throw new BadRequestError({ message: "Failed to create group without organization" }); if (!actorOrgId) throw new BadRequestError({ message: "Failed to create group without organization" });
const { permission } = await permissionService.getOrgPermission( const { permission } = await permissionService.getOrgPermission(
@@ -251,12 +270,12 @@ export const groupServiceFactory = ({
// check if group with slug exists // check if group with slug exists
const group = await groupDAL.findOne({ const group = await groupDAL.findOne({
orgId: actorOrgId, orgId: actorOrgId,
slug: groupSlug id
}); });
if (!group) if (!group)
throw new BadRequestError({ throw new BadRequestError({
message: `Failed to find group with slug ${groupSlug}` message: `Failed to find group with ID ${id}`
}); });
const { permission: groupRolePermission } = await permissionService.getOrgPermissionByRole(group.role, actorOrgId); const { permission: groupRolePermission } = await permissionService.getOrgPermissionByRole(group.role, actorOrgId);
@@ -285,7 +304,7 @@ export const groupServiceFactory = ({
}; };
const removeUserFromGroup = async ({ const removeUserFromGroup = async ({
groupSlug, id,
username, username,
actor, actor,
actorId, actorId,
@@ -306,12 +325,12 @@ export const groupServiceFactory = ({
// check if group with slug exists // check if group with slug exists
const group = await groupDAL.findOne({ const group = await groupDAL.findOne({
orgId: actorOrgId, orgId: actorOrgId,
slug: groupSlug id
}); });
if (!group) if (!group)
throw new BadRequestError({ throw new BadRequestError({
message: `Failed to find group with slug ${groupSlug}` message: `Failed to find group with ID ${id}`
}); });
const { permission: groupRolePermission } = await permissionService.getOrgPermissionByRole(group.role, actorOrgId); const { permission: groupRolePermission } = await permissionService.getOrgPermissionByRole(group.role, actorOrgId);
@@ -342,6 +361,7 @@ export const groupServiceFactory = ({
deleteGroup, deleteGroup,
listGroupUsers, listGroupUsers,
addUserToGroup, addUserToGroup,
removeUserFromGroup removeUserFromGroup,
getGroupById
}; };
}; };
+9 -5
View File
@@ -17,7 +17,7 @@ export type TCreateGroupDTO = {
} & TGenericPermission; } & TGenericPermission;
export type TUpdateGroupDTO = { export type TUpdateGroupDTO = {
currentSlug: string; id: string;
} & Partial<{ } & Partial<{
name: string; name: string;
slug: string; slug: string;
@@ -26,23 +26,27 @@ export type TUpdateGroupDTO = {
TGenericPermission; TGenericPermission;
export type TDeleteGroupDTO = { export type TDeleteGroupDTO = {
groupSlug: string; id: string;
} & TGenericPermission;
export type TGetGroupByIdDTO = {
id: string;
} & TGenericPermission; } & TGenericPermission;
export type TListGroupUsersDTO = { export type TListGroupUsersDTO = {
groupSlug: string; id: string;
offset: number; offset: number;
limit: number; limit: number;
username?: string; username?: string;
} & TGenericPermission; } & TGenericPermission;
export type TAddUserToGroupDTO = { export type TAddUserToGroupDTO = {
groupSlug: string; id: string;
username: string; username: string;
} & TGenericPermission; } & TGenericPermission;
export type TRemoveUserFromGroupDTO = { export type TRemoveUserFromGroupDTO = {
groupSlug: string; id: string;
username: string; username: string;
} & TGenericPermission; } & TGenericPermission;
@@ -346,7 +346,7 @@ export const permissionServiceFactory = ({
const isCustomRole = !Object.values(ProjectMembershipRole).includes(role as ProjectMembershipRole); const isCustomRole = !Object.values(ProjectMembershipRole).includes(role as ProjectMembershipRole);
if (isCustomRole) { if (isCustomRole) {
const projectRole = await projectRoleDAL.findOne({ slug: role, projectId }); const projectRole = await projectRoleDAL.findOne({ slug: role, projectId });
if (!projectRole) throw new BadRequestError({ message: "Role not found" }); if (!projectRole) throw new BadRequestError({ message: `Role not found: ${role}` });
return { return {
permission: buildProjectPermission([ permission: buildProjectPermission([
{ role: ProjectMembershipRole.Custom, permissions: projectRole.permissions } { role: ProjectMembershipRole.Custom, permissions: projectRole.permissions }
+12 -11
View File
@@ -5,26 +5,27 @@ export const GROUPS = {
role: "The role of the group to create." role: "The role of the group to create."
}, },
UPDATE: { UPDATE: {
currentSlug: "The current slug of the group to update.", id: "The id of the group to update",
name: "The new name of the group to update to.", name: "The new name of the group to update to.",
slug: "The new slug of the group to update to.", slug: "The new slug of the group to update to.",
role: "The new role of the group to update to." role: "The new role of the group to update to."
}, },
DELETE: { DELETE: {
id: "The id of the group to delete",
slug: "The slug of the group to delete" slug: "The slug of the group to delete"
}, },
LIST_USERS: { LIST_USERS: {
slug: "The slug of the group to list users for", id: "The id of the group to list users for",
offset: "The offset to start from. If you enter 10, it will start from the 10th user.", offset: "The offset to start from. If you enter 10, it will start from the 10th user.",
limit: "The number of users to return.", limit: "The number of users to return.",
username: "The username to search for." username: "The username to search for."
}, },
ADD_USER: { ADD_USER: {
slug: "The slug of the group to add the user to.", id: "The id of the group to add the user to.",
username: "The username of the user to add to the group." username: "The username of the user to add to the group."
}, },
DELETE_USER: { DELETE_USER: {
slug: "The slug of the group to remove the user from.", id: "The id of the group to remove the user from.",
username: "The username of the user to remove from the group." username: "The username of the user to remove from the group."
} }
} as const; } as const;
@@ -409,21 +410,21 @@ export const PROJECTS = {
secretSnapshotId: "The ID of the snapshot to rollback to." secretSnapshotId: "The ID of the snapshot to rollback to."
}, },
ADD_GROUP_TO_PROJECT: { ADD_GROUP_TO_PROJECT: {
projectSlug: "The slug of the project to add the group to.", projectId: "The ID of the project to add the group to.",
groupSlug: "The slug of the group to add to the project.", groupId: "The ID of the group to add to the project.",
role: "The role for the group to assume in the project." role: "The role for the group to assume in the project."
}, },
UPDATE_GROUP_IN_PROJECT: { UPDATE_GROUP_IN_PROJECT: {
projectSlug: "The slug of the project to update the group in.", projectId: "The ID of the project to update the group in.",
groupSlug: "The slug of the group to update in the project.", groupId: "The ID of the group to update in the project.",
roles: "A list of roles to update the group to." roles: "A list of roles to update the group to."
}, },
REMOVE_GROUP_FROM_PROJECT: { REMOVE_GROUP_FROM_PROJECT: {
projectSlug: "The slug of the project to delete the group from.", projectId: "The ID of the project to delete the group from.",
groupSlug: "The slug of the group to delete from the project." groupId: "The ID of the group to delete from the project."
}, },
LIST_GROUPS_IN_PROJECT: { LIST_GROUPS_IN_PROJECT: {
projectSlug: "The slug of the project to list groups for." projectId: "The ID of the project to list groups for."
}, },
LIST_INTEGRATION: { LIST_INTEGRATION: {
workspaceId: "The ID of the project to list integrations for." workspaceId: "The ID of the project to list integrations for."
@@ -8,6 +8,7 @@ import {
ProjectUserMembershipRolesSchema ProjectUserMembershipRolesSchema
} from "@app/db/schemas"; } from "@app/db/schemas";
import { PROJECTS } from "@app/lib/api-docs"; import { PROJECTS } from "@app/lib/api-docs";
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
import { verifyAuth } from "@app/server/plugins/auth/verify-auth"; import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
import { AuthMode } from "@app/services/auth/auth-type"; import { AuthMode } from "@app/services/auth/auth-type";
import { ProjectUserMembershipTemporaryMode } from "@app/services/project-membership/project-membership-types"; import { ProjectUserMembershipTemporaryMode } from "@app/services/project-membership/project-membership-types";
@@ -15,8 +16,11 @@ import { ProjectUserMembershipTemporaryMode } from "@app/services/project-member
export const registerGroupProjectRouter = async (server: FastifyZodProvider) => { export const registerGroupProjectRouter = async (server: FastifyZodProvider) => {
server.route({ server.route({
method: "POST", method: "POST",
url: "/:projectSlug/groups/:groupSlug", url: "/:projectId/groups/:groupId",
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]), onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
config: {
rateLimit: writeLimit
},
schema: { schema: {
description: "Add group to project", description: "Add group to project",
security: [ security: [
@@ -25,17 +29,39 @@ export const registerGroupProjectRouter = async (server: FastifyZodProvider) =>
} }
], ],
params: z.object({ params: z.object({
projectSlug: z.string().trim().describe(PROJECTS.ADD_GROUP_TO_PROJECT.projectSlug), projectId: z.string().trim().describe(PROJECTS.ADD_GROUP_TO_PROJECT.projectId),
groupSlug: z.string().trim().describe(PROJECTS.ADD_GROUP_TO_PROJECT.groupSlug) groupId: z.string().trim().describe(PROJECTS.ADD_GROUP_TO_PROJECT.groupId)
}),
body: z.object({
role: z
.string()
.trim()
.min(1)
.default(ProjectMembershipRole.NoAccess)
.describe(PROJECTS.ADD_GROUP_TO_PROJECT.role)
}), }),
body: z
.object({
role: z
.string()
.trim()
.min(1)
.default(ProjectMembershipRole.NoAccess)
.describe(PROJECTS.ADD_GROUP_TO_PROJECT.role),
roles: z
.array(
z.union([
z.object({
role: z.string(),
isTemporary: z.literal(false).default(false)
}),
z.object({
role: z.string(),
isTemporary: z.literal(true),
temporaryMode: z.nativeEnum(ProjectUserMembershipTemporaryMode),
temporaryRange: z.string().refine((val) => ms(val) > 0, "Temporary range must be a positive number"),
temporaryAccessStartTime: z.string().datetime()
})
])
)
.optional()
})
.refine((data) => data.role || data.roles, {
message: "Either role or roles must be present",
path: ["role", "roles"]
}),
response: { response: {
200: z.object({ 200: z.object({
groupMembership: GroupProjectMembershipsSchema groupMembership: GroupProjectMembershipsSchema
@@ -48,17 +74,18 @@ export const registerGroupProjectRouter = async (server: FastifyZodProvider) =>
actorId: req.permission.id, actorId: req.permission.id,
actorAuthMethod: req.permission.authMethod, actorAuthMethod: req.permission.authMethod,
actorOrgId: req.permission.orgId, actorOrgId: req.permission.orgId,
groupSlug: req.params.groupSlug, roles: req.body.roles || [{ role: req.body.role }],
projectSlug: req.params.projectSlug, projectId: req.params.projectId,
role: req.body.role groupId: req.params.groupId
}); });
return { groupMembership }; return { groupMembership };
} }
}); });
server.route({ server.route({
method: "PATCH", method: "PATCH",
url: "/:projectSlug/groups/:groupSlug", url: "/:projectId/groups/:groupId",
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]), onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
schema: { schema: {
description: "Update group in project", description: "Update group in project",
@@ -68,8 +95,8 @@ export const registerGroupProjectRouter = async (server: FastifyZodProvider) =>
} }
], ],
params: z.object({ params: z.object({
projectSlug: z.string().trim().describe(PROJECTS.UPDATE_GROUP_IN_PROJECT.projectSlug), projectId: z.string().trim().describe(PROJECTS.UPDATE_GROUP_IN_PROJECT.projectId),
groupSlug: z.string().trim().describe(PROJECTS.UPDATE_GROUP_IN_PROJECT.groupSlug) groupId: z.string().trim().describe(PROJECTS.UPDATE_GROUP_IN_PROJECT.groupId)
}), }),
body: z.object({ body: z.object({
roles: z roles: z
@@ -103,18 +130,22 @@ export const registerGroupProjectRouter = async (server: FastifyZodProvider) =>
actorId: req.permission.id, actorId: req.permission.id,
actorAuthMethod: req.permission.authMethod, actorAuthMethod: req.permission.authMethod,
actorOrgId: req.permission.orgId, actorOrgId: req.permission.orgId,
groupSlug: req.params.groupSlug, projectId: req.params.projectId,
projectSlug: req.params.projectSlug, groupId: req.params.groupId,
roles: req.body.roles roles: req.body.roles
}); });
return { roles }; return { roles };
} }
}); });
server.route({ server.route({
method: "DELETE", method: "DELETE",
url: "/:projectSlug/groups/:groupSlug", url: "/:projectId/groups/:groupId",
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]), onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
config: {
rateLimit: writeLimit
},
schema: { schema: {
description: "Remove group from project", description: "Remove group from project",
security: [ security: [
@@ -123,8 +154,8 @@ export const registerGroupProjectRouter = async (server: FastifyZodProvider) =>
} }
], ],
params: z.object({ params: z.object({
projectSlug: z.string().trim().describe(PROJECTS.REMOVE_GROUP_FROM_PROJECT.projectSlug), projectId: z.string().trim().describe(PROJECTS.REMOVE_GROUP_FROM_PROJECT.projectId),
groupSlug: z.string().trim().describe(PROJECTS.REMOVE_GROUP_FROM_PROJECT.groupSlug) groupId: z.string().trim().describe(PROJECTS.REMOVE_GROUP_FROM_PROJECT.groupId)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -138,17 +169,21 @@ export const registerGroupProjectRouter = async (server: FastifyZodProvider) =>
actorId: req.permission.id, actorId: req.permission.id,
actorAuthMethod: req.permission.authMethod, actorAuthMethod: req.permission.authMethod,
actorOrgId: req.permission.orgId, actorOrgId: req.permission.orgId,
groupSlug: req.params.groupSlug, groupId: req.params.groupId,
projectSlug: req.params.projectSlug projectId: req.params.projectId
}); });
return { groupMembership }; return { groupMembership };
} }
}); });
server.route({ server.route({
method: "GET", method: "GET",
url: "/:projectSlug/groups", url: "/:projectId/groups",
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]), onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
config: {
rateLimit: readLimit
},
schema: { schema: {
description: "Return list of groups in project", description: "Return list of groups in project",
security: [ security: [
@@ -157,7 +192,7 @@ export const registerGroupProjectRouter = async (server: FastifyZodProvider) =>
} }
], ],
params: z.object({ params: z.object({
projectSlug: z.string().trim().describe(PROJECTS.LIST_GROUPS_IN_PROJECT.projectSlug) projectId: z.string().trim().describe(PROJECTS.LIST_GROUPS_IN_PROJECT.projectId)
}), }),
response: { response: {
200: z.object({ 200: z.object({
@@ -193,9 +228,67 @@ export const registerGroupProjectRouter = async (server: FastifyZodProvider) =>
actorId: req.permission.id, actorId: req.permission.id,
actorAuthMethod: req.permission.authMethod, actorAuthMethod: req.permission.authMethod,
actorOrgId: req.permission.orgId, actorOrgId: req.permission.orgId,
projectSlug: req.params.projectSlug projectId: req.params.projectId
}); });
return { groupMemberships }; return { groupMemberships };
} }
}); });
server.route({
method: "GET",
url: "/:projectId/groups/:groupId",
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
config: {
rateLimit: readLimit
},
schema: {
description: "Return project group",
security: [
{
bearerAuth: []
}
],
params: z.object({
projectId: z.string().trim(),
groupId: z.string().trim()
}),
response: {
200: z.object({
groupMembership: z.object({
id: z.string(),
groupId: z.string(),
createdAt: z.date(),
updatedAt: z.date(),
roles: z.array(
z.object({
id: z.string(),
role: z.string(),
customRoleId: z.string().optional().nullable(),
customRoleName: z.string().optional().nullable(),
customRoleSlug: z.string().optional().nullable(),
isTemporary: z.boolean(),
temporaryMode: z.string().optional().nullable(),
temporaryRange: z.string().nullable().optional(),
temporaryAccessStartTime: z.date().nullable().optional(),
temporaryAccessEndTime: z.date().nullable().optional()
})
),
group: GroupsSchema.pick({ name: true, id: true, slug: true })
})
})
}
},
handler: async (req) => {
const groupMembership = await server.services.groupProject.getGroupInProject({
actor: req.permission.type,
actorId: req.permission.id,
actorAuthMethod: req.permission.authMethod,
actorOrgId: req.permission.orgId,
...req.params
});
return { groupMembership };
}
});
}; };
@@ -10,10 +10,15 @@ export type TGroupProjectDALFactory = ReturnType<typeof groupProjectDALFactory>;
export const groupProjectDALFactory = (db: TDbClient) => { export const groupProjectDALFactory = (db: TDbClient) => {
const groupProjectOrm = ormify(db, TableName.GroupProjectMembership); const groupProjectOrm = ormify(db, TableName.GroupProjectMembership);
const findByProjectId = async (projectId: string, tx?: Knex) => { const findByProjectId = async (projectId: string, filter?: { groupId?: string }, tx?: Knex) => {
try { try {
const docs = await (tx || db.replicaNode())(TableName.GroupProjectMembership) const docs = await (tx || db.replicaNode())(TableName.GroupProjectMembership)
.where(`${TableName.GroupProjectMembership}.projectId`, projectId) .where(`${TableName.GroupProjectMembership}.projectId`, projectId)
.where((qb) => {
if (filter?.groupId) {
void qb.where(`${TableName.Groups}.id`, "=", filter.groupId);
}
})
.join(TableName.Groups, `${TableName.GroupProjectMembership}.groupId`, `${TableName.Groups}.id`) .join(TableName.Groups, `${TableName.GroupProjectMembership}.groupId`, `${TableName.Groups}.id`)
.join( .join(
TableName.GroupProjectMembershipRole, TableName.GroupProjectMembershipRole,
@@ -7,7 +7,7 @@ import { ProjectPermissionActions, ProjectPermissionSub } from "@app/ee/services
import { isAtLeastAsPrivileged } from "@app/lib/casl"; import { isAtLeastAsPrivileged } from "@app/lib/casl";
import { decryptAsymmetric, encryptAsymmetric } from "@app/lib/crypto"; import { decryptAsymmetric, encryptAsymmetric } from "@app/lib/crypto";
import { infisicalSymmetricDecrypt } from "@app/lib/crypto/encryption"; import { infisicalSymmetricDecrypt } from "@app/lib/crypto/encryption";
import { BadRequestError, ForbiddenRequestError } from "@app/lib/errors"; import { BadRequestError, ForbiddenRequestError, NotFoundError } from "@app/lib/errors";
import { groupBy } from "@app/lib/fn"; import { groupBy } from "@app/lib/fn";
import { TGroupDALFactory } from "../../ee/services/group/group-dal"; import { TGroupDALFactory } from "../../ee/services/group/group-dal";
@@ -22,6 +22,7 @@ import { TGroupProjectMembershipRoleDALFactory } from "./group-project-membershi
import { import {
TCreateProjectGroupDTO, TCreateProjectGroupDTO,
TDeleteProjectGroupDTO, TDeleteProjectGroupDTO,
TGetGroupInProjectDTO,
TListProjectGroupDTO, TListProjectGroupDTO,
TUpdateProjectGroupDTO TUpdateProjectGroupDTO
} from "./group-project-types"; } from "./group-project-types";
@@ -33,7 +34,7 @@ type TGroupProjectServiceFactoryDep = {
"create" | "transaction" | "insertMany" | "delete" "create" | "transaction" | "insertMany" | "delete"
>; >;
userGroupMembershipDAL: Pick<TUserGroupMembershipDALFactory, "findGroupMembersNotInProject">; userGroupMembershipDAL: Pick<TUserGroupMembershipDALFactory, "findGroupMembersNotInProject">;
projectDAL: Pick<TProjectDALFactory, "findOne" | "findProjectGhostUser">; projectDAL: Pick<TProjectDALFactory, "findOne" | "findProjectGhostUser" | "findById">;
projectKeyDAL: Pick<TProjectKeyDALFactory, "findLatestProjectKey" | "delete" | "insertMany" | "transaction">; projectKeyDAL: Pick<TProjectKeyDALFactory, "findLatestProjectKey" | "delete" | "insertMany" | "transaction">;
projectRoleDAL: Pick<TProjectRoleDALFactory, "find">; projectRoleDAL: Pick<TProjectRoleDALFactory, "find">;
projectBotDAL: TProjectBotDALFactory; projectBotDAL: TProjectBotDALFactory;
@@ -55,19 +56,17 @@ export const groupProjectServiceFactory = ({
permissionService permissionService
}: TGroupProjectServiceFactoryDep) => { }: TGroupProjectServiceFactoryDep) => {
const addGroupToProject = async ({ const addGroupToProject = async ({
groupSlug,
actor, actor,
actorId, actorId,
actorOrgId, actorOrgId,
actorAuthMethod, actorAuthMethod,
projectSlug, roles,
role projectId,
groupId
}: TCreateProjectGroupDTO) => { }: TCreateProjectGroupDTO) => {
const project = await projectDAL.findOne({ const project = await projectDAL.findById(projectId);
slug: projectSlug
});
if (!project) throw new BadRequestError({ message: `Failed to find project with slug ${projectSlug}` }); if (!project) throw new BadRequestError({ message: `Failed to find project with ID ${projectId}` });
if (project.version < 2) throw new BadRequestError({ message: `Failed to add group to E2EE project` }); if (project.version < 2) throw new BadRequestError({ message: `Failed to add group to E2EE project` });
const { permission } = await permissionService.getProjectPermission( const { permission } = await permissionService.getProjectPermission(
@@ -79,25 +78,51 @@ export const groupProjectServiceFactory = ({
); );
ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionActions.Create, ProjectPermissionSub.Groups); ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionActions.Create, ProjectPermissionSub.Groups);
const group = await groupDAL.findOne({ orgId: actorOrgId, slug: groupSlug }); const group = await groupDAL.findOne({ orgId: actorOrgId, id: groupId });
if (!group) throw new BadRequestError({ message: `Failed to find group with slug ${groupSlug}` }); if (!group) throw new BadRequestError({ message: `Failed to find group with ID ${groupId}` });
const existingGroup = await groupProjectDAL.findOne({ groupId: group.id, projectId: project.id }); const existingGroup = await groupProjectDAL.findOne({ groupId: group.id, projectId: project.id });
if (existingGroup) if (existingGroup)
throw new BadRequestError({ throw new BadRequestError({
message: `Group with slug ${groupSlug} already exists in project with id ${project.id}` message: `Group with ID ${groupId} already exists in project with id ${project.id}`
}); });
const { permission: rolePermission, role: customRole } = await permissionService.getProjectPermissionByRole( for await (const { role: requestedRoleChange } of roles) {
role, const { permission: rolePermission } = await permissionService.getProjectPermissionByRole(
project.id requestedRoleChange,
project.id
);
const hasRequiredPrivileges = isAtLeastAsPrivileged(permission, rolePermission);
if (!hasRequiredPrivileges) {
throw new ForbiddenRequestError({ message: "Failed to assign group to a more privileged role" });
}
}
// validate custom roles input
const customInputRoles = roles.filter(
({ role }) => !Object.values(ProjectMembershipRole).includes(role as ProjectMembershipRole)
); );
const hasPrivilege = isAtLeastAsPrivileged(permission, rolePermission); const hasCustomRole = Boolean(customInputRoles.length);
if (!hasPrivilege) const customRoles = hasCustomRole
throw new ForbiddenRequestError({ ? await projectRoleDAL.find({
message: "Failed to add group to project with more privileged role" projectId: project.id,
$in: { slug: customInputRoles.map(({ role }) => role) }
})
: [];
if (customRoles.length !== customInputRoles.length) {
const customRoleSlugs = customRoles.map((customRole) => customRole.slug);
const missingInputRoles = customInputRoles
.filter((inputRole) => !customRoleSlugs.includes(inputRole.role))
.map((role) => role.role);
throw new NotFoundError({
message: `Custom role/s not found: ${missingInputRoles.join(", ")}`
}); });
const isCustomRole = Boolean(customRole); }
const customRolesGroupBySlug = groupBy(customRoles, ({ slug }) => slug);
const projectGroup = await groupProjectDAL.transaction(async (tx) => { const projectGroup = await groupProjectDAL.transaction(async (tx) => {
const groupProjectMembership = await groupProjectDAL.create( const groupProjectMembership = await groupProjectDAL.create(
@@ -108,14 +133,31 @@ export const groupProjectServiceFactory = ({
tx tx
); );
await groupProjectMembershipRoleDAL.create( const sanitizedProjectMembershipRoles = roles.map((inputRole) => {
{ const isCustomRole = Boolean(customRolesGroupBySlug?.[inputRole.role]?.[0]);
if (!inputRole.isTemporary) {
return {
projectMembershipId: groupProjectMembership.id,
role: isCustomRole ? ProjectMembershipRole.Custom : inputRole.role,
customRoleId: customRolesGroupBySlug[inputRole.role] ? customRolesGroupBySlug[inputRole.role][0].id : null
};
}
// check cron or relative here later for now its just relative
const relativeTimeInMs = ms(inputRole.temporaryRange);
return {
projectMembershipId: groupProjectMembership.id, projectMembershipId: groupProjectMembership.id,
role: isCustomRole ? ProjectMembershipRole.Custom : role, role: isCustomRole ? ProjectMembershipRole.Custom : inputRole.role,
customRoleId: customRole?.id customRoleId: customRolesGroupBySlug[inputRole.role] ? customRolesGroupBySlug[inputRole.role][0].id : null,
}, isTemporary: true,
tx temporaryMode: ProjectUserMembershipTemporaryMode.Relative,
); temporaryRange: inputRole.temporaryRange,
temporaryAccessStartTime: new Date(inputRole.temporaryAccessStartTime),
temporaryAccessEndTime: new Date(new Date(inputRole.temporaryAccessStartTime).getTime() + relativeTimeInMs)
};
});
await groupProjectMembershipRoleDAL.insertMany(sanitizedProjectMembershipRoles, tx);
// share project key with users in group that have not // share project key with users in group that have not
// individually been added to the project and that are not part of // individually been added to the project and that are not part of
@@ -183,19 +225,17 @@ export const groupProjectServiceFactory = ({
}; };
const updateGroupInProject = async ({ const updateGroupInProject = async ({
projectSlug, projectId,
groupSlug, groupId,
roles, roles,
actor, actor,
actorId, actorId,
actorAuthMethod, actorAuthMethod,
actorOrgId actorOrgId
}: TUpdateProjectGroupDTO) => { }: TUpdateProjectGroupDTO) => {
const project = await projectDAL.findOne({ const project = await projectDAL.findById(projectId);
slug: projectSlug
});
if (!project) throw new BadRequestError({ message: `Failed to find project with slug ${projectSlug}` }); if (!project) throw new BadRequestError({ message: `Failed to find project with ID ${projectId}` });
const { permission } = await permissionService.getProjectPermission( const { permission } = await permissionService.getProjectPermission(
actor, actor,
@@ -206,11 +246,24 @@ export const groupProjectServiceFactory = ({
); );
ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionActions.Edit, ProjectPermissionSub.Groups); ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionActions.Edit, ProjectPermissionSub.Groups);
const group = await groupDAL.findOne({ orgId: actorOrgId, slug: groupSlug }); const group = await groupDAL.findOne({ orgId: actorOrgId, id: groupId });
if (!group) throw new BadRequestError({ message: `Failed to find group with slug ${groupSlug}` }); if (!group) throw new BadRequestError({ message: `Failed to find group with ID ${groupId}` });
const projectGroup = await groupProjectDAL.findOne({ groupId: group.id, projectId: project.id }); const projectGroup = await groupProjectDAL.findOne({ groupId: group.id, projectId: project.id });
if (!projectGroup) throw new BadRequestError({ message: `Failed to find group with slug ${groupSlug}` }); if (!projectGroup) throw new BadRequestError({ message: `Failed to find group with ID ${groupId}` });
for await (const { role: requestedRoleChange } of roles) {
const { permission: rolePermission } = await permissionService.getProjectPermissionByRole(
requestedRoleChange,
project.id
);
const hasRequiredPrivileges = isAtLeastAsPrivileged(permission, rolePermission);
if (!hasRequiredPrivileges) {
throw new ForbiddenRequestError({ message: "Failed to assign group to a more privileged role" });
}
}
// validate custom roles input // validate custom roles input
const customInputRoles = roles.filter( const customInputRoles = roles.filter(
@@ -223,7 +276,16 @@ export const groupProjectServiceFactory = ({
$in: { slug: customInputRoles.map(({ role }) => role) } $in: { slug: customInputRoles.map(({ role }) => role) }
}) })
: []; : [];
if (customRoles.length !== customInputRoles.length) throw new BadRequestError({ message: "Custom role not found" }); if (customRoles.length !== customInputRoles.length) {
const customRoleSlugs = customRoles.map((customRole) => customRole.slug);
const missingInputRoles = customInputRoles
.filter((inputRole) => !customRoleSlugs.includes(inputRole.role))
.map((role) => role.role);
throw new NotFoundError({
message: `Custom role/s not found: ${missingInputRoles.join(", ")}`
});
}
const customRolesGroupBySlug = groupBy(customRoles, ({ slug }) => slug); const customRolesGroupBySlug = groupBy(customRoles, ({ slug }) => slug);
@@ -260,24 +322,22 @@ export const groupProjectServiceFactory = ({
}; };
const removeGroupFromProject = async ({ const removeGroupFromProject = async ({
projectSlug, projectId,
groupSlug, groupId,
actorId, actorId,
actor, actor,
actorOrgId, actorOrgId,
actorAuthMethod actorAuthMethod
}: TDeleteProjectGroupDTO) => { }: TDeleteProjectGroupDTO) => {
const project = await projectDAL.findOne({ const project = await projectDAL.findById(projectId);
slug: projectSlug
});
if (!project) throw new BadRequestError({ message: `Failed to find project with slug ${projectSlug}` }); if (!project) throw new BadRequestError({ message: `Failed to find project with ID ${projectId}` });
const group = await groupDAL.findOne({ orgId: actorOrgId, slug: groupSlug }); const group = await groupDAL.findOne({ orgId: actorOrgId, id: groupId });
if (!group) throw new BadRequestError({ message: `Failed to find group with slug ${groupSlug}` }); if (!group) throw new BadRequestError({ message: `Failed to find group with ID ${groupId}` });
const groupProjectMembership = await groupProjectDAL.findOne({ groupId: group.id, projectId: project.id }); const groupProjectMembership = await groupProjectDAL.findOne({ groupId: group.id, projectId: project.id });
if (!groupProjectMembership) throw new BadRequestError({ message: `Failed to find group with slug ${groupSlug}` }); if (!groupProjectMembership) throw new BadRequestError({ message: `Failed to find group with ID ${groupId}` });
const { permission } = await permissionService.getProjectPermission( const { permission } = await permissionService.getProjectPermission(
actor, actor,
@@ -311,17 +371,17 @@ export const groupProjectServiceFactory = ({
}; };
const listGroupsInProject = async ({ const listGroupsInProject = async ({
projectSlug, projectId,
actor, actor,
actorId, actorId,
actorAuthMethod, actorAuthMethod,
actorOrgId actorOrgId
}: TListProjectGroupDTO) => { }: TListProjectGroupDTO) => {
const project = await projectDAL.findOne({ const project = await projectDAL.findById(projectId);
slug: projectSlug
});
if (!project) throw new BadRequestError({ message: `Failed to find project with slug ${projectSlug}` }); if (!project) {
throw new BadRequestError({ message: `Failed to find project with ID ${projectId}` });
}
const { permission } = await permissionService.getProjectPermission( const { permission } = await permissionService.getProjectPermission(
actor, actor,
@@ -336,10 +396,47 @@ export const groupProjectServiceFactory = ({
return groupMemberships; return groupMemberships;
}; };
const getGroupInProject = async ({
actor,
actorId,
actorAuthMethod,
actorOrgId,
groupId,
projectId
}: TGetGroupInProjectDTO) => {
const project = await projectDAL.findById(projectId);
if (!project) {
throw new NotFoundError({ message: `Failed to find project with ID ${projectId}` });
}
const { permission } = await permissionService.getProjectPermission(
actor,
actorId,
project.id,
actorAuthMethod,
actorOrgId
);
ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionActions.Read, ProjectPermissionSub.Groups);
const [groupMembership] = await groupProjectDAL.findByProjectId(project.id, {
groupId
});
if (!groupMembership) {
throw new NotFoundError({
message: "Cannot find group membership"
});
}
return groupMembership;
};
return { return {
addGroupToProject, addGroupToProject,
updateGroupInProject, updateGroupInProject,
removeGroupFromProject, removeGroupFromProject,
listGroupsInProject listGroupsInProject,
getGroupInProject
}; };
}; };
@@ -1,11 +1,23 @@
import { TProjectSlugPermission } from "@app/lib/types"; import { TProjectPermission } from "@app/lib/types";
import { ProjectUserMembershipTemporaryMode } from "../project-membership/project-membership-types"; import { ProjectUserMembershipTemporaryMode } from "../project-membership/project-membership-types";
export type TCreateProjectGroupDTO = { export type TCreateProjectGroupDTO = {
groupSlug: string; groupId: string;
role: string; roles: (
} & TProjectSlugPermission; | {
role: string;
isTemporary?: false;
}
| {
role: string;
isTemporary: true;
temporaryMode: ProjectUserMembershipTemporaryMode.Relative;
temporaryRange: string;
temporaryAccessStartTime: string;
}
)[];
} & TProjectPermission;
export type TUpdateProjectGroupDTO = { export type TUpdateProjectGroupDTO = {
roles: ( roles: (
@@ -21,11 +33,13 @@ export type TUpdateProjectGroupDTO = {
temporaryAccessStartTime: string; temporaryAccessStartTime: string;
} }
)[]; )[];
groupSlug: string; groupId: string;
} & TProjectSlugPermission; } & TProjectPermission;
export type TDeleteProjectGroupDTO = { export type TDeleteProjectGroupDTO = {
groupSlug: string; groupId: string;
} & TProjectSlugPermission; } & TProjectPermission;
export type TListProjectGroupDTO = TProjectSlugPermission; export type TListProjectGroupDTO = TProjectPermission;
export type TGetGroupInProjectDTO = TProjectPermission & { groupId: string };
+25 -9
View File
@@ -38,17 +38,17 @@ export const useUpdateGroup = () => {
const queryClient = useQueryClient(); const queryClient = useQueryClient();
return useMutation({ return useMutation({
mutationFn: async ({ mutationFn: async ({
currentSlug, id,
name, name,
slug, slug,
role role
}: { }: {
currentSlug: string; id: string;
name?: string; name?: string;
slug?: string; slug?: string;
role?: string; role?: string;
}) => { }) => {
const { data: group } = await apiRequest.patch<TGroup>(`/api/v1/groups/${currentSlug}`, { const { data: group } = await apiRequest.patch<TGroup>(`/api/v1/groups/${id}`, {
name, name,
slug, slug,
role role
@@ -65,8 +65,8 @@ export const useUpdateGroup = () => {
export const useDeleteGroup = () => { export const useDeleteGroup = () => {
const queryClient = useQueryClient(); const queryClient = useQueryClient();
return useMutation({ return useMutation({
mutationFn: async ({ slug }: { slug: string }) => { mutationFn: async ({ id }: { id: string }) => {
const { data: group } = await apiRequest.delete<TGroup>(`/api/v1/groups/${slug}`); const { data: group } = await apiRequest.delete<TGroup>(`/api/v1/groups/${id}`);
return group; return group;
}, },
@@ -79,8 +79,15 @@ export const useDeleteGroup = () => {
export const useAddUserToGroup = () => { export const useAddUserToGroup = () => {
const queryClient = useQueryClient(); const queryClient = useQueryClient();
return useMutation({ return useMutation({
mutationFn: async ({ slug, username }: { slug: string; username: string }) => { mutationFn: async ({
const { data } = await apiRequest.post<TGroup>(`/api/v1/groups/${slug}/users/${username}`); groupId,
username
}: {
groupId: string;
username: string;
slug: string;
}) => {
const { data } = await apiRequest.post<TGroup>(`/api/v1/groups/${groupId}/users/${username}`);
return data; return data;
}, },
@@ -93,8 +100,17 @@ export const useAddUserToGroup = () => {
export const useRemoveUserFromGroup = () => { export const useRemoveUserFromGroup = () => {
const queryClient = useQueryClient(); const queryClient = useQueryClient();
return useMutation({ return useMutation({
mutationFn: async ({ slug, username }: { slug: string; username: string }) => { mutationFn: async ({
const { data } = await apiRequest.delete<TGroup>(`/api/v1/groups/${slug}/users/${username}`); username,
groupId
}: {
slug: string;
username: string;
groupId: string;
}) => {
const { data } = await apiRequest.delete<TGroup>(
`/api/v1/groups/${groupId}/users/${username}`
);
return data; return data;
}, },
+10 -6
View File
@@ -4,7 +4,8 @@ import { apiRequest } from "@app/config/request";
export const groupKeys = { export const groupKeys = {
allGroupUserMemberships: () => ["group-user-memberships"] as const, allGroupUserMemberships: () => ["group-user-memberships"] as const,
forGroupUserMemberships: (slug: string) => [...groupKeys.allGroupUserMemberships(), slug] as const, forGroupUserMemberships: (slug: string) =>
[...groupKeys.allGroupUserMemberships(), slug] as const,
specificGroupUserMemberships: ({ specificGroupUserMemberships: ({
slug, slug,
offset, offset,
@@ -28,11 +29,13 @@ type TUser = {
}; };
export const useListGroupUsers = ({ export const useListGroupUsers = ({
id,
groupSlug, groupSlug,
offset = 0, offset = 0,
limit = 10, limit = 10,
username username
}: { }: {
id: string;
groupSlug: string; groupSlug: string;
offset: number; offset: number;
limit: number; limit: number;
@@ -52,14 +55,15 @@ export const useListGroupUsers = ({
limit: String(limit), limit: String(limit),
username username
}); });
const { data } = await apiRequest.get<{ users: TUser[]; totalCount: number; }>( const { data } = await apiRequest.get<{ users: TUser[]; totalCount: number }>(
`/api/v1/groups/${groupSlug}/users`, { `/api/v1/groups/${id}/users`,
{
params params
} }
); );
return data; return data;
}, }
}); });
}; };
+19 -18
View File
@@ -10,23 +10,24 @@ export const useAddGroupToWorkspace = () => {
const queryClient = useQueryClient(); const queryClient = useQueryClient();
return useMutation({ return useMutation({
mutationFn: async ({ mutationFn: async ({
groupSlug, groupId,
projectSlug, projectId,
role role
}: { }: {
groupSlug: string; groupId: string;
projectSlug: string; projectId: string;
role?: string; role?: string;
}) => { }) => {
const { const {
data: { groupMembership } data: { groupMembership }
} = await apiRequest.post(`/api/v2/workspace/${projectSlug}/groups/${groupSlug}`, { } = await apiRequest.post(`/api/v2/workspace/${projectId}/groups/${groupId}`, {
role role
}); });
return groupMembership; return groupMembership;
}, },
onSuccess: (_, { projectSlug }) => { onSuccess: (_, { projectId }) => {
queryClient.invalidateQueries(workspaceKeys.getWorkspaceGroupMemberships(projectSlug)); queryClient.invalidateQueries(workspaceKeys.getWorkspaceGroupMemberships(projectId));
} }
}); });
}; };
@@ -34,17 +35,17 @@ export const useAddGroupToWorkspace = () => {
export const useUpdateGroupWorkspaceRole = () => { export const useUpdateGroupWorkspaceRole = () => {
const queryClient = useQueryClient(); const queryClient = useQueryClient();
return useMutation({ return useMutation({
mutationFn: async ({ groupSlug, projectSlug, roles }: TUpdateWorkspaceGroupRoleDTO) => { mutationFn: async ({ groupId, projectId, roles }: TUpdateWorkspaceGroupRoleDTO) => {
const { const {
data: { groupMembership } data: { groupMembership }
} = await apiRequest.patch(`/api/v2/workspace/${projectSlug}/groups/${groupSlug}`, { } = await apiRequest.patch(`/api/v2/workspace/${projectId}/groups/${groupId}`, {
roles roles
}); });
return groupMembership; return groupMembership;
}, },
onSuccess: (_, { projectSlug }) => { onSuccess: (_, { projectId }) => {
queryClient.invalidateQueries(workspaceKeys.getWorkspaceGroupMemberships(projectSlug)); queryClient.invalidateQueries(workspaceKeys.getWorkspaceGroupMemberships(projectId));
} }
}); });
}; };
@@ -53,20 +54,20 @@ export const useDeleteGroupFromWorkspace = () => {
const queryClient = useQueryClient(); const queryClient = useQueryClient();
return useMutation({ return useMutation({
mutationFn: async ({ mutationFn: async ({
groupSlug, groupId,
projectSlug projectId
}: { }: {
groupSlug: string; groupId: string;
projectSlug: string; projectId: string;
username?: string; username?: string;
}) => { }) => {
const { const {
data: { groupMembership } data: { groupMembership }
} = await apiRequest.delete(`/api/v2/workspace/${projectSlug}/groups/${groupSlug}`); } = await apiRequest.delete(`/api/v2/workspace/${projectId}/groups/${groupId}`);
return groupMembership; return groupMembership;
}, },
onSuccess: (_, { projectSlug, username }) => { onSuccess: (_, { projectId, username }) => {
queryClient.invalidateQueries(workspaceKeys.getWorkspaceGroupMemberships(projectSlug)); queryClient.invalidateQueries(workspaceKeys.getWorkspaceGroupMemberships(projectId));
if (username) { if (username) {
queryClient.invalidateQueries(userKeys.listUserGroupMemberships(username)); queryClient.invalidateQueries(userKeys.listUserGroupMemberships(username));
+3 -3
View File
@@ -535,14 +535,14 @@ export const useGetWorkspaceIdentityMemberships = (
}); });
}; };
export const useListWorkspaceGroups = (projectSlug: string) => { export const useListWorkspaceGroups = (projectId: string) => {
return useQuery({ return useQuery({
queryKey: workspaceKeys.getWorkspaceGroupMemberships(projectSlug), queryKey: workspaceKeys.getWorkspaceGroupMemberships(projectId),
queryFn: async () => { queryFn: async () => {
const { const {
data: { groupMemberships } data: { groupMemberships }
} = await apiRequest.get<{ groupMemberships: TGroupMembership[] }>( } = await apiRequest.get<{ groupMemberships: TGroupMembership[] }>(
`/api/v2/workspace/${projectSlug}/groups` `/api/v2/workspace/${projectId}/groups`
); );
return groupMemberships; return groupMemberships;
}, },
+2 -2
View File
@@ -127,8 +127,8 @@ export type TUpdateWorkspaceIdentityRoleDTO = {
}; };
export type TUpdateWorkspaceGroupRoleDTO = { export type TUpdateWorkspaceGroupRoleDTO = {
groupSlug: string; groupId: string;
projectSlug: string; projectId: string;
roles: ( roles: (
| { | {
role: string; role: string;
@@ -35,10 +35,12 @@ export const OrgGroupMembersModal = ({ popUp, handlePopUpToggle }: Props) => {
const [searchMemberFilter, setSearchMemberFilter] = useState(""); const [searchMemberFilter, setSearchMemberFilter] = useState("");
const popUpData = popUp?.groupMembers?.data as { const popUpData = popUp?.groupMembers?.data as {
groupId: string;
slug: string; slug: string;
}; };
const { data, isLoading } = useListGroupUsers({ const { data, isLoading } = useListGroupUsers({
id: popUpData?.groupId,
groupSlug: popUpData?.slug, groupSlug: popUpData?.slug,
offset: (page - 1) * perPage, offset: (page - 1) * perPage,
limit: perPage, limit: perPage,
@@ -54,11 +56,13 @@ export const OrgGroupMembersModal = ({ popUp, handlePopUpToggle }: Props) => {
if (assign) { if (assign) {
await assignMutateAsync({ await assignMutateAsync({
groupId: popUpData.groupId,
username, username,
slug: popUpData.slug slug: popUpData.slug
}); });
} else { } else {
await unassignMutateAsync({ await unassignMutateAsync({
groupId: popUpData.groupId,
username, username,
slug: popUpData.slug slug: popUpData.slug
}); });
@@ -85,7 +85,7 @@ export const OrgGroupModal = ({ popUp, handlePopUpClose, handlePopUpToggle }: Pr
if (group) { if (group) {
await updateMutateAsync({ await updateMutateAsync({
currentSlug: group.slug, id: group.groupId,
name, name,
slug, slug,
role: role || undefined role: role || undefined
@@ -34,10 +34,10 @@ export const OrgGroupsSection = () => {
} }
}; };
const onDeleteGroupSubmit = async ({ name, slug }: { name: string; slug: string }) => { const onDeleteGroupSubmit = async ({ name, groupId }: { name: string; groupId: string }) => {
try { try {
await deleteMutateAsync({ await deleteMutateAsync({
slug id: groupId
}); });
createNotification({ createNotification({
text: `Successfully deleted the group named ${name}`, text: `Successfully deleted the group named ${name}`,
@@ -87,7 +87,7 @@ export const OrgGroupsSection = () => {
onChange={(isOpen) => handlePopUpToggle("deleteGroup", isOpen)} onChange={(isOpen) => handlePopUpToggle("deleteGroup", isOpen)}
deleteKey="confirm" deleteKey="confirm"
onDeleteApproved={() => onDeleteApproved={() =>
onDeleteGroupSubmit(popUp?.deleteGroup?.data as { name: string; slug: string }) onDeleteGroupSubmit(popUp?.deleteGroup?.data as { name: string; groupId: string })
} }
/> />
<UpgradePlanModal <UpgradePlanModal
@@ -1,5 +1,5 @@
import { useState } from "react"; import { useState } from "react";
import { faEllipsis,faMagnifyingGlass, faUsers } from "@fortawesome/free-solid-svg-icons"; import { faEllipsis, faMagnifyingGlass, faUsers } from "@fortawesome/free-solid-svg-icons";
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
import { twMerge } from "tailwind-merge"; import { twMerge } from "tailwind-merge";
@@ -52,10 +52,10 @@ export const OrgGroupsTable = ({ handlePopUpOpen }: Props) => {
const { data: roles } = useGetOrgRoles(orgId); const { data: roles } = useGetOrgRoles(orgId);
const handleChangeRole = async ({ currentSlug, role }: { currentSlug: string; role: string }) => { const handleChangeRole = async ({ id, role }: { id: string; role: string }) => {
try { try {
await updateMutateAsync({ await updateMutateAsync({
currentSlug, id,
role role
}); });
@@ -112,7 +112,7 @@ export const OrgGroupsTable = ({ handlePopUpOpen }: Props) => {
dropdownContainerClassName="border border-mineshaft-600 bg-mineshaft-800" dropdownContainerClassName="border border-mineshaft-600 bg-mineshaft-800"
onValueChange={(selectedRole) => onValueChange={(selectedRole) =>
handleChangeRole({ handleChangeRole({
currentSlug: slug, id,
role: selectedRole role: selectedRole
}) })
} }
@@ -135,6 +135,18 @@ export const OrgGroupsTable = ({ handlePopUpOpen }: Props) => {
</div> </div>
</DropdownMenuTrigger> </DropdownMenuTrigger>
<DropdownMenuContent align="start" className="p-1"> <DropdownMenuContent align="start" className="p-1">
<DropdownMenuItem
onClick={(e) => {
e.stopPropagation();
createNotification({
text: "Copied group ID to clipboard",
type: "info"
});
navigator.clipboard.writeText(id);
}}
>
Copy Group ID
</DropdownMenuItem>
<OrgPermissionCan <OrgPermissionCan
I={OrgPermissionActions.Edit} I={OrgPermissionActions.Edit}
a={OrgPermissionSubjects.Identity} a={OrgPermissionSubjects.Identity}
@@ -147,6 +159,7 @@ export const OrgGroupsTable = ({ handlePopUpOpen }: Props) => {
onClick={(e) => { onClick={(e) => {
e.stopPropagation(); e.stopPropagation();
handlePopUpOpen("groupMembers", { handlePopUpOpen("groupMembers", {
groupId: id,
slug slug
}); });
}} }}
@@ -195,7 +208,7 @@ export const OrgGroupsTable = ({ handlePopUpOpen }: Props) => {
onClick={(e) => { onClick={(e) => {
e.stopPropagation(); e.stopPropagation();
handlePopUpOpen("deleteGroup", { handlePopUpOpen("deleteGroup", {
slug, groupId: id,
name name
}); });
}} }}
@@ -30,6 +30,7 @@ export const UserGroupsRow = ({ group, handlePopUpOpen }: Props) => {
onClick={(e) => { onClick={(e) => {
e.stopPropagation(); e.stopPropagation();
handlePopUpOpen("removeUserFromGroup", { handlePopUpOpen("removeUserFromGroup", {
groupId: group.id,
groupSlug: group.slug groupSlug: group.slug
}); });
}} }}
@@ -19,9 +19,10 @@ export const UserGroupsSection = ({ orgMembership }: Props) => {
const { mutateAsync: removeUserFromGroup } = useRemoveUserFromGroup(); const { mutateAsync: removeUserFromGroup } = useRemoveUserFromGroup();
const handleRemoveUserFromGroup = useCallback(async (groupSlug: string) => { const handleRemoveUserFromGroup = useCallback(async (groupId: string, groupSlug: string) => {
try { try {
await removeUserFromGroup({ await removeUserFromGroup({
groupId,
slug: groupSlug, slug: groupSlug,
username: orgMembership.user.username username: orgMembership.user.username
}); });
@@ -57,10 +58,11 @@ export const UserGroupsSection = ({ orgMembership }: Props) => {
deleteKey="confirm" deleteKey="confirm"
onDeleteApproved={() => { onDeleteApproved={() => {
const popupData = popUp?.removeUserFromGroup?.data as { const popupData = popUp?.removeUserFromGroup?.data as {
groupId: string;
groupSlug: string; groupSlug: string;
}; };
return handleRemoveUserFromGroup(popupData.groupSlug); return handleRemoveUserFromGroup(popupData.groupId, popupData.groupSlug);
}} }}
/> />
</> </>
@@ -16,7 +16,7 @@ import {
import { UsePopUpState } from "@app/hooks/usePopUp"; import { UsePopUpState } from "@app/hooks/usePopUp";
const schema = z.object({ const schema = z.object({
slug: z.string(), id: z.string(),
role: z.string() role: z.string()
}); });
@@ -35,7 +35,7 @@ export const GroupModal = ({ popUp, handlePopUpToggle }: Props) => {
const projectSlug = currentWorkspace?.slug || ""; const projectSlug = currentWorkspace?.slug || "";
const { data: groups } = useGetOrganizationGroups(orgId); const { data: groups } = useGetOrganizationGroups(orgId);
const { data: groupMemberships } = useListWorkspaceGroups(currentWorkspace?.slug || ""); const { data: groupMemberships } = useListWorkspaceGroups(currentWorkspace?.id || "");
const { data: roles } = useGetProjectRoles(projectSlug); const { data: roles } = useGetProjectRoles(projectSlug);
@@ -60,11 +60,11 @@ export const GroupModal = ({ popUp, handlePopUpToggle }: Props) => {
resolver: zodResolver(schema) resolver: zodResolver(schema)
}); });
const onFormSubmit = async ({ slug, role }: FormData) => { const onFormSubmit = async ({ id, role }: FormData) => {
try { try {
await addGroupToWorkspaceMutateAsync({ await addGroupToWorkspaceMutateAsync({
projectSlug: currentWorkspace?.slug || "", projectId: currentWorkspace?.id || "",
groupSlug: slug, groupId: id,
role: role || undefined role: role || undefined
}); });
@@ -96,7 +96,7 @@ export const GroupModal = ({ popUp, handlePopUpToggle }: Props) => {
<form onSubmit={handleSubmit(onFormSubmit)}> <form onSubmit={handleSubmit(onFormSubmit)}>
<Controller <Controller
control={control} control={control}
name="slug" name="id"
defaultValue={filteredGroupMembershipOrgs?.[0]?.id} defaultValue={filteredGroupMembershipOrgs?.[0]?.id}
render={({ field: { onChange, ...field }, fieldState: { error } }) => ( render={({ field: { onChange, ...field }, fieldState: { error } }) => (
<FormControl label="Group" errorText={error?.message} isError={Boolean(error)}> <FormControl label="Group" errorText={error?.message} isError={Boolean(error)}>
@@ -107,8 +107,8 @@ export const GroupModal = ({ popUp, handlePopUpToggle }: Props) => {
className="w-full border border-mineshaft-600" className="w-full border border-mineshaft-600"
placeholder="Select group..." placeholder="Select group..."
> >
{filteredGroupMembershipOrgs.map(({ name, slug, id }) => ( {filteredGroupMembershipOrgs.map(({ name, id }) => (
<SelectItem value={slug} key={`org-group-${id}`} > <SelectItem value={id} key={`org-group-${id}`}>
{name} {name}
</SelectItem> </SelectItem>
))} ))}
@@ -143,7 +143,7 @@ export const GroupModal = ({ popUp, handlePopUpToggle }: Props) => {
</FormControl> </FormControl>
)} )}
/> />
<div className="flex items-center mt-6"> <div className="mt-6 flex items-center">
<Button <Button
className="mr-4" className="mr-4"
size="sm" size="sm"
@@ -153,13 +153,13 @@ export const GroupModal = ({ popUp, handlePopUpToggle }: Props) => {
> >
{popUp?.group?.data ? "Update" : "Create"} {popUp?.group?.data ? "Update" : "Create"}
</Button> </Button>
<Button <Button
colorSchema="secondary" colorSchema="secondary"
variant="plain" variant="plain"
onClick={() => handlePopUpToggle("group", false)} onClick={() => handlePopUpToggle("group", false)}
> >
Cancel Cancel
</Button> </Button>
</div> </div>
</form> </form>
) : ( ) : (
@@ -195,13 +195,13 @@ type TForm = z.infer<typeof formSchema>;
export type TMemberRolesProp = { export type TMemberRolesProp = {
disableEdit?: boolean; disableEdit?: boolean;
groupSlug: string; groupId: string;
roles: TGroupMembership["roles"]; roles: TGroupMembership["roles"];
}; };
const MAX_ROLES_TO_BE_SHOWN_IN_TABLE = 2; const MAX_ROLES_TO_BE_SHOWN_IN_TABLE = 2;
export const GroupRoles = ({ roles = [], disableEdit = false, groupSlug }: TMemberRolesProp) => { export const GroupRoles = ({ roles = [], disableEdit = false, groupId }: TMemberRolesProp) => {
const { currentWorkspace } = useWorkspace(); const { currentWorkspace } = useWorkspace();
const { popUp, handlePopUpToggle } = usePopUp(["editRole"] as const); const { popUp, handlePopUpToggle } = usePopUp(["editRole"] as const);
const [searchRoles, setSearchRoles] = useState(""); const [searchRoles, setSearchRoles] = useState("");
@@ -248,8 +248,8 @@ export const GroupRoles = ({ roles = [], disableEdit = false, groupSlug }: TMemb
try { try {
await updateGroupWorkspaceRole.mutateAsync({ await updateGroupWorkspaceRole.mutateAsync({
projectSlug: currentWorkspace?.slug || "", projectId: currentWorkspace?.id || "",
groupSlug, groupId,
roles: selectedRoles roles: selectedRoles
}); });
createNotification({ text: "Successfully updated group role", type: "success" }); createNotification({ text: "Successfully updated group role", type: "success" });
@@ -39,11 +39,11 @@ export const GroupsSection = () => {
} }
}; };
const onRemoveGroupSubmit = async (groupSlug: string) => { const onRemoveGroupSubmit = async (groupId: string) => {
try { try {
await deleteMutateAsync({ await deleteMutateAsync({
groupSlug, groupId,
projectSlug: currentWorkspace?.slug || "" projectId: currentWorkspace?.id || ""
}); });
createNotification({ createNotification({
@@ -92,7 +92,7 @@ export const GroupsSection = () => {
onChange={(isOpen) => handlePopUpToggle("deleteGroup", isOpen)} onChange={(isOpen) => handlePopUpToggle("deleteGroup", isOpen)}
deleteKey="confirm" deleteKey="confirm"
onDeleteApproved={() => onDeleteApproved={() =>
onRemoveGroupSubmit((popUp?.deleteGroup?.data as { slug: string })?.slug) onRemoveGroupSubmit((popUp?.deleteGroup?.data as { id: string })?.id)
} }
/> />
<UpgradePlanModal <UpgradePlanModal
@@ -26,7 +26,7 @@ type Props = {
handlePopUpOpen: ( handlePopUpOpen: (
popUpName: keyof UsePopUpState<["deleteGroup", "group"]>, popUpName: keyof UsePopUpState<["deleteGroup", "group"]>,
data?: { data?: {
slug?: string; id?: string;
name?: string; name?: string;
} }
) => void; ) => void;
@@ -34,7 +34,7 @@ type Props = {
export const GroupTable = ({ handlePopUpOpen }: Props) => { export const GroupTable = ({ handlePopUpOpen }: Props) => {
const { currentWorkspace } = useWorkspace(); const { currentWorkspace } = useWorkspace();
const { data, isLoading } = useListWorkspaceGroups(currentWorkspace?.slug || ""); const { data, isLoading } = useListWorkspaceGroups(currentWorkspace?.id || "");
return ( return (
<TableContainer> <TableContainer>
<Table> <Table>
@@ -51,7 +51,7 @@ export const GroupTable = ({ handlePopUpOpen }: Props) => {
{!isLoading && {!isLoading &&
data && data &&
data.length > 0 && data.length > 0 &&
data.map(({ group: { id, name, slug }, roles, createdAt }) => { data.map(({ group: { id, name }, roles, createdAt }) => {
return ( return (
<Tr className="group h-10" key={`st-v3-${id}`}> <Tr className="group h-10" key={`st-v3-${id}`}>
<Td>{name}</Td> <Td>{name}</Td>
@@ -61,7 +61,7 @@ export const GroupTable = ({ handlePopUpOpen }: Props) => {
a={ProjectPermissionSub.Groups} a={ProjectPermissionSub.Groups}
> >
{(isAllowed) => ( {(isAllowed) => (
<GroupRoles roles={roles} disableEdit={!isAllowed} groupSlug={slug} /> <GroupRoles roles={roles} disableEdit={!isAllowed} groupId={id} />
)} )}
</ProjectPermissionCan> </ProjectPermissionCan>
</Td> </Td>
@@ -77,7 +77,7 @@ export const GroupTable = ({ handlePopUpOpen }: Props) => {
<IconButton <IconButton
onClick={() => { onClick={() => {
handlePopUpOpen("deleteGroup", { handlePopUpOpen("deleteGroup", {
slug, id,
name name
}); });
}} }}