feat: more patchy patch

This commit is contained in:
=
2025-10-10 00:09:48 +05:30
parent 97135d9cfa
commit 26543b6374
4 changed files with 33 additions and 23 deletions
@@ -372,14 +372,12 @@ export const githubOrgSyncServiceFactory = ({
tx tx
); );
const memberships = await membershipGroupDAL.insertMany( const memberships = await membershipGroupDAL.insertMany(
newGroups.map( newGroups.map((el) => ({
(el) => ({ actorGroupId: el.id,
actorGroupId: el.id, scope: AccessScope.Organization,
scope: AccessScope.Organization, scopeOrgId: orgId
scopeOrgId: orgId })),
}), tx
tx
)
); );
await membershipRoleDAL.insertMany( await membershipRoleDAL.insertMany(
@@ -717,14 +715,12 @@ export const githubOrgSyncServiceFactory = ({
); );
const memberships = await membershipGroupDAL.insertMany( const memberships = await membershipGroupDAL.insertMany(
newGroups.map( newGroups.map((el) => ({
(el) => ({ actorGroupId: el.id,
actorGroupId: el.id, scope: AccessScope.Organization,
scope: AccessScope.Organization, scopeOrgId: orgPermission.orgId
scopeOrgId: orgPermission.orgId })),
}), tx
tx
)
); );
await membershipRoleDAL.insertMany( await membershipRoleDAL.insertMany(
@@ -467,7 +467,7 @@ export const ldapConfigServiceFactory = ({
const [orgMembership] = await orgDAL.findMembership( const [orgMembership] = await orgDAL.findMembership(
{ {
[`${TableName.Membership}.actorUserId` as "actorUserId"]: userAlias.userId, [`${TableName.Membership}.actorUserId` as "actorUserId"]: newUserAlias.userId,
[`${TableName.Membership}.scopeOrgId` as "scopeOrgId"]: orgId, [`${TableName.Membership}.scopeOrgId` as "scopeOrgId"]: orgId,
[`${TableName.Membership}.scope` as "scope"]: AccessScope.Organization [`${TableName.Membership}.scope` as "scope"]: AccessScope.Organization
}, },
@@ -229,7 +229,9 @@ export const OrgPermissionSchema = z.discriminatedUnion("subject", [
}), }),
z.object({ z.object({
subject: z.literal(OrgPermissionSubjects.Billing).describe("The entity this permission pertains to."), subject: z.literal(OrgPermissionSubjects.Billing).describe("The entity this permission pertains to."),
action: CASL_ACTION_SCHEMA_NATIVE_ENUM(OrgPermissionActions).describe("Describe what action an entity can take.") action: CASL_ACTION_SCHEMA_NATIVE_ENUM(OrgPermissionBillingActions).describe(
"Describe what action an entity can take."
)
}), }),
z.object({ z.object({
subject: z.literal(OrgPermissionSubjects.Identity).describe("The entity this permission pertains to."), subject: z.literal(OrgPermissionSubjects.Identity).describe("The entity this permission pertains to."),
@@ -52,10 +52,14 @@ export const newProjectAdditionalPrivilegesFactory = ({
async (dto) => { async (dto) => {
const scope = getScopeField(dto.scopeData); const scope = getScopeField(dto.scopeData);
const { permission } = await $getPermission(dto.permission, scope.value);
ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionMemberActions.Edit, ProjectPermissionSub.Member);
const { actorType } = dto.data; const { actorType } = dto.data;
const { permission } = await $getPermission(dto.permission, scope.value);
const permissionSet =
actorType === ActorType.USER
? ([ProjectPermissionMemberActions.Edit, ProjectPermissionSub.Member] as const)
: ([ProjectPermissionIdentityActions.Edit, ProjectPermissionSub.Identity] as const);
ForbiddenError.from(permission).throwUnlessCan(...permissionSet);
const { shouldUseNewPrivilegeSystem } = await orgDAL.findById(dto.permission.orgId); const { shouldUseNewPrivilegeSystem } = await orgDAL.findById(dto.permission.orgId);
const { permission: targetUserPermission, memberships } = await $getPermission( const { permission: targetUserPermission, memberships } = await $getPermission(
{ ...dto.permission, type: actorType, id: dto.data.actorId }, { ...dto.permission, type: actorType, id: dto.data.actorId },
@@ -98,7 +102,11 @@ export const newProjectAdditionalPrivilegesFactory = ({
const { actorType } = dto.selector; const { actorType } = dto.selector;
const { permission } = await $getPermission(dto.permission, scope.value); const { permission } = await $getPermission(dto.permission, scope.value);
ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionMemberActions.Edit, ProjectPermissionSub.Member); const permissionSet =
actorType === ActorType.USER
? ([ProjectPermissionMemberActions.Edit, ProjectPermissionSub.Member] as const)
: ([ProjectPermissionIdentityActions.Edit, ProjectPermissionSub.Identity] as const);
ForbiddenError.from(permission).throwUnlessCan(...permissionSet);
const { shouldUseNewPrivilegeSystem } = await orgDAL.findById(dto.permission.orgId); const { shouldUseNewPrivilegeSystem } = await orgDAL.findById(dto.permission.orgId);
const { permission: targetUserPermission, memberships } = await $getPermission( const { permission: targetUserPermission, memberships } = await $getPermission(
@@ -142,7 +150,11 @@ export const newProjectAdditionalPrivilegesFactory = ({
const { actorType } = dto.selector; const { actorType } = dto.selector;
const { permission } = await $getPermission(dto.permission, scope.value); const { permission } = await $getPermission(dto.permission, scope.value);
ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionMemberActions.Edit, ProjectPermissionSub.Member); const permissionSet =
actorType === ActorType.USER
? ([ProjectPermissionMemberActions.Edit, ProjectPermissionSub.Member] as const)
: ([ProjectPermissionIdentityActions.Edit, ProjectPermissionSub.Identity] as const);
ForbiddenError.from(permission).throwUnlessCan(...permissionSet);
const membership = await membershipDAL.findOne({ const membership = await membershipDAL.findOne({
scopeOrgId: dto.permission.orgId, scopeOrgId: dto.permission.orgId,