mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 23:28:25 +00:00
Add default role support for RolePage
This commit is contained in:
@@ -53,7 +53,6 @@ export const registerOrgRoleRouter = async (server: FastifyZodProvider) => {
|
|||||||
});
|
});
|
||||||
|
|
||||||
server.route({
|
server.route({
|
||||||
// new: note that doesn't work for default roles
|
|
||||||
method: "GET",
|
method: "GET",
|
||||||
url: "/:organizationId/roles/:roleId",
|
url: "/:organizationId/roles/:roleId",
|
||||||
config: {
|
config: {
|
||||||
|
|||||||
@@ -51,9 +51,50 @@ export const orgRoleServiceFactory = ({ orgRoleDAL, permissionService }: TOrgRol
|
|||||||
) => {
|
) => {
|
||||||
const { permission } = await permissionService.getUserOrgPermission(userId, orgId, actorAuthMethod, actorOrgId);
|
const { permission } = await permissionService.getUserOrgPermission(userId, orgId, actorAuthMethod, actorOrgId);
|
||||||
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Read, OrgPermissionSubjects.Role);
|
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Read, OrgPermissionSubjects.Role);
|
||||||
const role = await orgRoleDAL.findOne({ id: roleId, orgId });
|
|
||||||
if (!role) throw new BadRequestError({ message: "Role not found", name: "Get role" });
|
switch (roleId) {
|
||||||
return role;
|
case "b11b49a9-09a9-4443-916a-4246f9ff2c69": {
|
||||||
|
return {
|
||||||
|
id: roleId,
|
||||||
|
orgId,
|
||||||
|
name: "Admin",
|
||||||
|
slug: "admin",
|
||||||
|
description: "Complete administration access over the organization",
|
||||||
|
permissions: packRules(orgAdminPermissions.rules),
|
||||||
|
createdAt: new Date(),
|
||||||
|
updatedAt: new Date()
|
||||||
|
};
|
||||||
|
}
|
||||||
|
case "b11b49a9-09a9-4443-916a-4246f9ff2c70": {
|
||||||
|
return {
|
||||||
|
id: roleId,
|
||||||
|
orgId,
|
||||||
|
name: "Member",
|
||||||
|
slug: "member",
|
||||||
|
description: "Non-administrative role in an organization",
|
||||||
|
permissions: packRules(orgMemberPermissions.rules),
|
||||||
|
createdAt: new Date(),
|
||||||
|
updatedAt: new Date()
|
||||||
|
};
|
||||||
|
}
|
||||||
|
case "b10d49a9-09a9-4443-916a-4246f9ff2c72": {
|
||||||
|
return {
|
||||||
|
id: "b10d49a9-09a9-4443-916a-4246f9ff2c72", // dummy user for zod validation in response
|
||||||
|
orgId,
|
||||||
|
name: "No Access",
|
||||||
|
slug: "no-access",
|
||||||
|
description: "No access to any resources in the organization",
|
||||||
|
permissions: packRules(orgNoAccessPermissions.rules),
|
||||||
|
createdAt: new Date(),
|
||||||
|
updatedAt: new Date()
|
||||||
|
};
|
||||||
|
}
|
||||||
|
default: {
|
||||||
|
const role = await orgRoleDAL.findOne({ id: roleId, orgId });
|
||||||
|
if (!role) throw new BadRequestError({ message: "Role not found", name: "Get role" });
|
||||||
|
return role;
|
||||||
|
}
|
||||||
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
const updateRole = async (
|
const updateRole = async (
|
||||||
|
|||||||
@@ -21,32 +21,35 @@ export const RoleDetailsSection = ({ roleId, handlePopUpOpen }: Props) => {
|
|||||||
const { currentOrg } = useOrganization();
|
const { currentOrg } = useOrganization();
|
||||||
const orgId = currentOrg?.id || "";
|
const orgId = currentOrg?.id || "";
|
||||||
const { data } = useGetOrgRole(orgId, roleId);
|
const { data } = useGetOrgRole(orgId, roleId);
|
||||||
|
const isCustomRole = !["admin", "member", "no-access"].includes(data?.slug ?? "");
|
||||||
|
|
||||||
return data ? (
|
return data ? (
|
||||||
<div className="rounded-lg border border-mineshaft-600 bg-mineshaft-900 p-4">
|
<div className="rounded-lg border border-mineshaft-600 bg-mineshaft-900 p-4">
|
||||||
<div className="flex items-center justify-between border-b border-mineshaft-400 pb-4">
|
<div className="flex items-center justify-between border-b border-mineshaft-400 pb-4">
|
||||||
<h3 className="text-lg font-semibold text-mineshaft-100">Details</h3>
|
<h3 className="text-lg font-semibold text-mineshaft-100">Details</h3>
|
||||||
<OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Role}>
|
{isCustomRole && (
|
||||||
{(isAllowed) => {
|
<OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Role}>
|
||||||
return (
|
{(isAllowed) => {
|
||||||
<Tooltip content="Edit Role">
|
return (
|
||||||
<IconButton
|
<Tooltip content="Edit Role">
|
||||||
isDisabled={!isAllowed}
|
<IconButton
|
||||||
ariaLabel="copy icon"
|
isDisabled={!isAllowed}
|
||||||
variant="plain"
|
ariaLabel="copy icon"
|
||||||
className="group relative"
|
variant="plain"
|
||||||
onClick={() =>
|
className="group relative"
|
||||||
handlePopUpOpen("role", {
|
onClick={() =>
|
||||||
roleId
|
handlePopUpOpen("role", {
|
||||||
})
|
roleId
|
||||||
}
|
})
|
||||||
>
|
}
|
||||||
<FontAwesomeIcon icon={faPencil} />
|
>
|
||||||
</IconButton>
|
<FontAwesomeIcon icon={faPencil} />
|
||||||
</Tooltip>
|
</IconButton>
|
||||||
);
|
</Tooltip>
|
||||||
}}
|
);
|
||||||
</OrgPermissionCan>
|
}}
|
||||||
|
</OrgPermissionCan>
|
||||||
|
)}
|
||||||
</div>
|
</div>
|
||||||
<div className="pt-4">
|
<div className="pt-4">
|
||||||
<div className="mb-4">
|
<div className="mb-4">
|
||||||
|
|||||||
+20
-10
@@ -3,7 +3,8 @@ import { Control, Controller, UseFormSetValue, useWatch } from "react-hook-form"
|
|||||||
import { faChevronDown, faChevronRight } from "@fortawesome/free-solid-svg-icons";
|
import { faChevronDown, faChevronRight } from "@fortawesome/free-solid-svg-icons";
|
||||||
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
||||||
|
|
||||||
import { Checkbox, IconButton, Select, SelectItem, Td, Tr } from "@app/components/v2";
|
import { createNotification } from "@app/components/notifications";
|
||||||
|
import { Checkbox, Select, SelectItem, Td, Tr } from "@app/components/v2";
|
||||||
import { useToggle } from "@app/hooks";
|
import { useToggle } from "@app/hooks";
|
||||||
import { TFormSchema } from "@app/views/Org/MembersPage/components/OrgRoleTabSection/OrgRoleModifySection/OrgRoleModifySection.utils";
|
import { TFormSchema } from "@app/views/Org/MembersPage/components/OrgRoleTabSection/OrgRoleModifySection/OrgRoleModifySection.utils";
|
||||||
|
|
||||||
@@ -58,6 +59,7 @@ const getPermissionList = (option: string) => {
|
|||||||
};
|
};
|
||||||
|
|
||||||
type Props = {
|
type Props = {
|
||||||
|
isEditable: boolean;
|
||||||
title: string;
|
title: string;
|
||||||
formName: keyof Omit<Exclude<TFormSchema["permissions"], undefined>, "workspace">;
|
formName: keyof Omit<Exclude<TFormSchema["permissions"], undefined>, "workspace">;
|
||||||
setValue: UseFormSetValue<TFormSchema>;
|
setValue: UseFormSetValue<TFormSchema>;
|
||||||
@@ -76,7 +78,14 @@ enum Permission {
|
|||||||
|
|
||||||
// TODO: support for default roles
|
// TODO: support for default roles
|
||||||
|
|
||||||
export const RolePermissionRow = ({ title, formName, handleSubmit, control, setValue }: Props) => {
|
export const RolePermissionRow = ({
|
||||||
|
isEditable,
|
||||||
|
title,
|
||||||
|
formName,
|
||||||
|
handleSubmit,
|
||||||
|
control,
|
||||||
|
setValue
|
||||||
|
}: Props) => {
|
||||||
const [isRowExpanded, setIsRowExpanded] = useToggle();
|
const [isRowExpanded, setIsRowExpanded] = useToggle();
|
||||||
const [isCustom, setIsCustom] = useToggle();
|
const [isCustom, setIsCustom] = useToggle();
|
||||||
|
|
||||||
@@ -159,14 +168,7 @@ export const RolePermissionRow = ({ title, formName, handleSubmit, control, setV
|
|||||||
onClick={() => setIsRowExpanded.toggle()}
|
onClick={() => setIsRowExpanded.toggle()}
|
||||||
>
|
>
|
||||||
<Td>
|
<Td>
|
||||||
<IconButton
|
<FontAwesomeIcon icon={isRowExpanded ? faChevronDown : faChevronRight} />
|
||||||
ariaLabel="copy icon"
|
|
||||||
variant="plain"
|
|
||||||
className="group relative ml-2"
|
|
||||||
onClick={() => setIsRowExpanded.toggle()}
|
|
||||||
>
|
|
||||||
<FontAwesomeIcon icon={isRowExpanded ? faChevronDown : faChevronRight} />
|
|
||||||
</IconButton>
|
|
||||||
</Td>
|
</Td>
|
||||||
<Td>{title}</Td>
|
<Td>{title}</Td>
|
||||||
<Td>
|
<Td>
|
||||||
@@ -175,6 +177,7 @@ export const RolePermissionRow = ({ title, formName, handleSubmit, control, setV
|
|||||||
className="w-40 bg-mineshaft-600"
|
className="w-40 bg-mineshaft-600"
|
||||||
dropdownContainerClassName="border border-mineshaft-600 bg-mineshaft-800"
|
dropdownContainerClassName="border border-mineshaft-600 bg-mineshaft-800"
|
||||||
onValueChange={handlePermissionChange}
|
onValueChange={handlePermissionChange}
|
||||||
|
isDisabled={!isEditable}
|
||||||
>
|
>
|
||||||
<SelectItem value={Permission.NoAccess}>No Access</SelectItem>
|
<SelectItem value={Permission.NoAccess}>No Access</SelectItem>
|
||||||
<SelectItem value={Permission.ReadOnly}>Read Only</SelectItem>
|
<SelectItem value={Permission.ReadOnly}>Read Only</SelectItem>
|
||||||
@@ -200,6 +203,13 @@ export const RolePermissionRow = ({ title, formName, handleSubmit, control, setV
|
|||||||
<Checkbox
|
<Checkbox
|
||||||
isChecked={field.value}
|
isChecked={field.value}
|
||||||
onCheckedChange={(e) => {
|
onCheckedChange={(e) => {
|
||||||
|
if (!isEditable) {
|
||||||
|
createNotification({
|
||||||
|
type: "error",
|
||||||
|
text: "Failed to update default role"
|
||||||
|
});
|
||||||
|
return;
|
||||||
|
}
|
||||||
field.onChange(e);
|
field.onChange(e);
|
||||||
handleSubmit();
|
handleSubmit();
|
||||||
}}
|
}}
|
||||||
|
|||||||
+3
@@ -93,6 +93,8 @@ export const RolePermissionsTable = ({ roleId }: Props) => {
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const isCustomRole = !["admin", "member", "no-access"].includes(role?.slug ?? "");
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<TableContainer>
|
<TableContainer>
|
||||||
<form onSubmit={handleSubmit(onSubmit)}>
|
<form onSubmit={handleSubmit(onSubmit)}>
|
||||||
@@ -114,6 +116,7 @@ export const RolePermissionsTable = ({ roleId }: Props) => {
|
|||||||
setValue={setValue}
|
setValue={setValue}
|
||||||
handleSubmit={handleSubmit(onSubmit)}
|
handleSubmit={handleSubmit(onSubmit)}
|
||||||
key={`org-role-${roleId}-permission-${permission.formName}`}
|
key={`org-role-${roleId}-permission-${permission.formName}`}
|
||||||
|
isEditable={isCustomRole}
|
||||||
/>
|
/>
|
||||||
);
|
);
|
||||||
})}
|
})}
|
||||||
|
|||||||
Reference in New Issue
Block a user