mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-03 23:26:09 +00:00
Merge pull request #2162 from Infisical/role-concept
Organization Role Page
This commit is contained in:
@@ -52,6 +52,36 @@ export const registerOrgRoleRouter = async (server: FastifyZodProvider) => {
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
server.route({
|
||||||
|
method: "GET",
|
||||||
|
url: "/:organizationId/roles/:roleId",
|
||||||
|
config: {
|
||||||
|
rateLimit: readLimit
|
||||||
|
},
|
||||||
|
schema: {
|
||||||
|
params: z.object({
|
||||||
|
organizationId: z.string().trim(),
|
||||||
|
roleId: z.string().trim()
|
||||||
|
}),
|
||||||
|
response: {
|
||||||
|
200: z.object({
|
||||||
|
role: OrgRolesSchema
|
||||||
|
})
|
||||||
|
}
|
||||||
|
},
|
||||||
|
onRequest: verifyAuth([AuthMode.JWT]),
|
||||||
|
handler: async (req) => {
|
||||||
|
const role = await server.services.orgRole.getRole(
|
||||||
|
req.permission.id,
|
||||||
|
req.params.organizationId,
|
||||||
|
req.params.roleId,
|
||||||
|
req.permission.authMethod,
|
||||||
|
req.permission.orgId
|
||||||
|
);
|
||||||
|
return { role };
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
server.route({
|
server.route({
|
||||||
method: "PATCH",
|
method: "PATCH",
|
||||||
url: "/:organizationId/roles/:roleId",
|
url: "/:organizationId/roles/:roleId",
|
||||||
@@ -69,7 +99,7 @@ export const registerOrgRoleRouter = async (server: FastifyZodProvider) => {
|
|||||||
.trim()
|
.trim()
|
||||||
.optional()
|
.optional()
|
||||||
.refine(
|
.refine(
|
||||||
(val) => typeof val === "undefined" || Object.keys(OrgMembershipRole).includes(val),
|
(val) => typeof val !== "undefined" && !Object.keys(OrgMembershipRole).includes(val),
|
||||||
"Please choose a different slug, the slug you have entered is reserved."
|
"Please choose a different slug, the slug you have entered is reserved."
|
||||||
)
|
)
|
||||||
.refine((val) => typeof val === "undefined" || slugify(val) === val, {
|
.refine((val) => typeof val === "undefined" || slugify(val) === val, {
|
||||||
|
|||||||
@@ -42,6 +42,61 @@ export const orgRoleServiceFactory = ({ orgRoleDAL, permissionService }: TOrgRol
|
|||||||
return role;
|
return role;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const getRole = async (
|
||||||
|
userId: string,
|
||||||
|
orgId: string,
|
||||||
|
roleId: string,
|
||||||
|
actorAuthMethod: ActorAuthMethod,
|
||||||
|
actorOrgId: string | undefined
|
||||||
|
) => {
|
||||||
|
const { permission } = await permissionService.getUserOrgPermission(userId, orgId, actorAuthMethod, actorOrgId);
|
||||||
|
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Read, OrgPermissionSubjects.Role);
|
||||||
|
|
||||||
|
switch (roleId) {
|
||||||
|
case "b11b49a9-09a9-4443-916a-4246f9ff2c69": {
|
||||||
|
return {
|
||||||
|
id: roleId,
|
||||||
|
orgId,
|
||||||
|
name: "Admin",
|
||||||
|
slug: "admin",
|
||||||
|
description: "Complete administration access over the organization",
|
||||||
|
permissions: packRules(orgAdminPermissions.rules),
|
||||||
|
createdAt: new Date(),
|
||||||
|
updatedAt: new Date()
|
||||||
|
};
|
||||||
|
}
|
||||||
|
case "b11b49a9-09a9-4443-916a-4246f9ff2c70": {
|
||||||
|
return {
|
||||||
|
id: roleId,
|
||||||
|
orgId,
|
||||||
|
name: "Member",
|
||||||
|
slug: "member",
|
||||||
|
description: "Non-administrative role in an organization",
|
||||||
|
permissions: packRules(orgMemberPermissions.rules),
|
||||||
|
createdAt: new Date(),
|
||||||
|
updatedAt: new Date()
|
||||||
|
};
|
||||||
|
}
|
||||||
|
case "b10d49a9-09a9-4443-916a-4246f9ff2c72": {
|
||||||
|
return {
|
||||||
|
id: "b10d49a9-09a9-4443-916a-4246f9ff2c72", // dummy user for zod validation in response
|
||||||
|
orgId,
|
||||||
|
name: "No Access",
|
||||||
|
slug: "no-access",
|
||||||
|
description: "No access to any resources in the organization",
|
||||||
|
permissions: packRules(orgNoAccessPermissions.rules),
|
||||||
|
createdAt: new Date(),
|
||||||
|
updatedAt: new Date()
|
||||||
|
};
|
||||||
|
}
|
||||||
|
default: {
|
||||||
|
const role = await orgRoleDAL.findOne({ id: roleId, orgId });
|
||||||
|
if (!role) throw new BadRequestError({ message: "Role not found", name: "Get role" });
|
||||||
|
return role;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
const updateRole = async (
|
const updateRole = async (
|
||||||
userId: string,
|
userId: string,
|
||||||
orgId: string,
|
orgId: string,
|
||||||
@@ -144,5 +199,5 @@ export const orgRoleServiceFactory = ({ orgRoleDAL, permissionService }: TOrgRol
|
|||||||
return { permissions: packRules(permission.rules), membership };
|
return { permissions: packRules(permission.rules), membership };
|
||||||
};
|
};
|
||||||
|
|
||||||
return { createRole, updateRole, deleteRole, listRoles, getUserPermission };
|
return { createRole, getRole, updateRole, deleteRole, listRoles, getUserPermission };
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -7,6 +7,7 @@ export {
|
|||||||
useUpdateProjectRole
|
useUpdateProjectRole
|
||||||
} from "./mutation";
|
} from "./mutation";
|
||||||
export {
|
export {
|
||||||
|
useGetOrgRole,
|
||||||
useGetOrgRoles,
|
useGetOrgRoles,
|
||||||
useGetProjectRoleBySlug,
|
useGetProjectRoleBySlug,
|
||||||
useGetProjectRoles,
|
useGetProjectRoles,
|
||||||
|
|||||||
@@ -9,6 +9,7 @@ import {
|
|||||||
TCreateProjectRoleDTO,
|
TCreateProjectRoleDTO,
|
||||||
TDeleteOrgRoleDTO,
|
TDeleteOrgRoleDTO,
|
||||||
TDeleteProjectRoleDTO,
|
TDeleteProjectRoleDTO,
|
||||||
|
TOrgRole,
|
||||||
TUpdateOrgRoleDTO,
|
TUpdateOrgRoleDTO,
|
||||||
TUpdateProjectRoleDTO
|
TUpdateProjectRoleDTO
|
||||||
} from "./types";
|
} from "./types";
|
||||||
@@ -52,12 +53,17 @@ export const useDeleteProjectRole = () => {
|
|||||||
export const useCreateOrgRole = () => {
|
export const useCreateOrgRole = () => {
|
||||||
const queryClient = useQueryClient();
|
const queryClient = useQueryClient();
|
||||||
|
|
||||||
return useMutation({
|
return useMutation<TOrgRole, {}, TCreateOrgRoleDTO>({
|
||||||
mutationFn: ({ orgId, permissions, ...dto }: TCreateOrgRoleDTO) =>
|
mutationFn: async ({ orgId, permissions, ...dto }: TCreateOrgRoleDTO) => {
|
||||||
apiRequest.post(`/api/v1/organization/${orgId}/roles`, {
|
const {
|
||||||
|
data: { role }
|
||||||
|
} = await apiRequest.post(`/api/v1/organization/${orgId}/roles`, {
|
||||||
...dto,
|
...dto,
|
||||||
permissions: permissions.length ? packRules(permissions) : []
|
permissions: permissions.length ? packRules(permissions) : []
|
||||||
}),
|
});
|
||||||
|
|
||||||
|
return role;
|
||||||
|
},
|
||||||
onSuccess: (_, { orgId }) => {
|
onSuccess: (_, { orgId }) => {
|
||||||
queryClient.invalidateQueries(roleQueryKeys.getOrgRoles(orgId));
|
queryClient.invalidateQueries(roleQueryKeys.getOrgRoles(orgId));
|
||||||
}
|
}
|
||||||
@@ -67,14 +73,20 @@ export const useCreateOrgRole = () => {
|
|||||||
export const useUpdateOrgRole = () => {
|
export const useUpdateOrgRole = () => {
|
||||||
const queryClient = useQueryClient();
|
const queryClient = useQueryClient();
|
||||||
|
|
||||||
return useMutation({
|
return useMutation<TOrgRole, {}, TUpdateOrgRoleDTO>({
|
||||||
mutationFn: ({ id, orgId, permissions, ...dto }: TUpdateOrgRoleDTO) =>
|
mutationFn: async ({ id, orgId, permissions, ...dto }: TUpdateOrgRoleDTO) => {
|
||||||
apiRequest.patch(`/api/v1/organization/${orgId}/roles/${id}`, {
|
const {
|
||||||
|
data: { role }
|
||||||
|
} = await apiRequest.patch(`/api/v1/organization/${orgId}/roles/${id}`, {
|
||||||
...dto,
|
...dto,
|
||||||
permissions: permissions?.length ? packRules(permissions) : []
|
permissions: permissions?.length ? packRules(permissions) : []
|
||||||
}),
|
});
|
||||||
onSuccess: (_, { orgId }) => {
|
|
||||||
|
return role;
|
||||||
|
},
|
||||||
|
onSuccess: (_, { id, orgId }) => {
|
||||||
queryClient.invalidateQueries(roleQueryKeys.getOrgRoles(orgId));
|
queryClient.invalidateQueries(roleQueryKeys.getOrgRoles(orgId));
|
||||||
|
queryClient.invalidateQueries(roleQueryKeys.getOrgRole(orgId, id));
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
};
|
};
|
||||||
@@ -82,13 +94,19 @@ export const useUpdateOrgRole = () => {
|
|||||||
export const useDeleteOrgRole = () => {
|
export const useDeleteOrgRole = () => {
|
||||||
const queryClient = useQueryClient();
|
const queryClient = useQueryClient();
|
||||||
|
|
||||||
return useMutation({
|
return useMutation<TOrgRole, {}, TDeleteOrgRoleDTO>({
|
||||||
mutationFn: ({ orgId, id }: TDeleteOrgRoleDTO) =>
|
mutationFn: async ({ orgId, id }: TDeleteOrgRoleDTO) => {
|
||||||
apiRequest.delete(`/api/v1/organization/${orgId}/roles/${id}`, {
|
const {
|
||||||
|
data: { role }
|
||||||
|
} = await apiRequest.delete(`/api/v1/organization/${orgId}/roles/${id}`, {
|
||||||
data: { orgId }
|
data: { orgId }
|
||||||
}),
|
});
|
||||||
onSuccess: (_, { orgId }) => {
|
|
||||||
|
return role;
|
||||||
|
},
|
||||||
|
onSuccess: (_, { id, orgId }) => {
|
||||||
queryClient.invalidateQueries(roleQueryKeys.getOrgRoles(orgId));
|
queryClient.invalidateQueries(roleQueryKeys.getOrgRoles(orgId));
|
||||||
|
queryClient.invalidateQueries(roleQueryKeys.getOrgRole(orgId, id));
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -40,6 +40,7 @@ export const roleQueryKeys = {
|
|||||||
getProjectRoleBySlug: (projectSlug: string, roleSlug: string) =>
|
getProjectRoleBySlug: (projectSlug: string, roleSlug: string) =>
|
||||||
["roles", { projectSlug, roleSlug }] as const,
|
["roles", { projectSlug, roleSlug }] as const,
|
||||||
getOrgRoles: (orgId: string) => ["org-roles", { orgId }] as const,
|
getOrgRoles: (orgId: string) => ["org-roles", { orgId }] as const,
|
||||||
|
getOrgRole: (orgId: string, roleId: string) => [{ orgId, roleId }, "org-role"] as const,
|
||||||
getUserOrgPermissions: ({ orgId }: TGetUserOrgPermissionsDTO) =>
|
getUserOrgPermissions: ({ orgId }: TGetUserOrgPermissionsDTO) =>
|
||||||
["user-permissions", { orgId }] as const,
|
["user-permissions", { orgId }] as const,
|
||||||
getUserProjectPermissions: ({ workspaceId }: TGetUserProjectPermissionDTO) =>
|
getUserProjectPermissions: ({ workspaceId }: TGetUserProjectPermissionDTO) =>
|
||||||
@@ -89,6 +90,21 @@ export const useGetOrgRoles = (orgId: string, enable = true) =>
|
|||||||
enabled: Boolean(orgId) && enable
|
enabled: Boolean(orgId) && enable
|
||||||
});
|
});
|
||||||
|
|
||||||
|
export const useGetOrgRole = (orgId: string, roleId: string) =>
|
||||||
|
useQuery({
|
||||||
|
queryKey: roleQueryKeys.getOrgRole(orgId, roleId),
|
||||||
|
queryFn: async () => {
|
||||||
|
const { data } = await apiRequest.get<{
|
||||||
|
role: Omit<TOrgRole, "permissions"> & { permissions: unknown };
|
||||||
|
}>(`/api/v1/organization/${orgId}/roles/${roleId}`);
|
||||||
|
return {
|
||||||
|
...data.role,
|
||||||
|
permissions: unpackRules(data.role.permissions as PackRule<TPermission>[])
|
||||||
|
};
|
||||||
|
},
|
||||||
|
enabled: Boolean(orgId && roleId)
|
||||||
|
});
|
||||||
|
|
||||||
const getUserOrgPermissions = async ({ orgId }: TGetUserOrgPermissionsDTO) => {
|
const getUserOrgPermissions = async ({ orgId }: TGetUserOrgPermissionsDTO) => {
|
||||||
if (orgId === "") return { permissions: [], membership: null };
|
if (orgId === "") return { permissions: [], membership: null };
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,20 @@
|
|||||||
|
/* eslint-disable @typescript-eslint/no-unused-vars */
|
||||||
|
import { useTranslation } from "react-i18next";
|
||||||
|
import Head from "next/head";
|
||||||
|
|
||||||
|
import { RolePage } from "@app/views/Org/RolePage";
|
||||||
|
|
||||||
|
export default function Role() {
|
||||||
|
const { t } = useTranslation();
|
||||||
|
return (
|
||||||
|
<>
|
||||||
|
<Head>
|
||||||
|
<title>{t("common.head-title", { title: t("settings.org.title") })}</title>
|
||||||
|
<link rel="icon" href="/infisical.ico" />
|
||||||
|
</Head>
|
||||||
|
<RolePage />
|
||||||
|
</>
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
Role.requireAuth = true;
|
||||||
+1
-1
@@ -68,7 +68,7 @@ export const IdentitySection = withPermission(
|
|||||||
};
|
};
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<div className="mb-6 rounded-lg border border-mineshaft-600 bg-mineshaft-900 p-4">
|
<div className="rounded-lg border border-mineshaft-600 bg-mineshaft-900 p-4">
|
||||||
<div className="mb-4 flex justify-between">
|
<div className="mb-4 flex justify-between">
|
||||||
<p className="text-xl font-semibold text-mineshaft-100">Identities</p>
|
<p className="text-xl font-semibold text-mineshaft-100">Identities</p>
|
||||||
<div className="flex w-full justify-end pr-4">
|
<div className="flex w-full justify-end pr-4">
|
||||||
|
|||||||
-2
@@ -106,8 +106,6 @@ const SIMPLE_PERMISSION_OPTIONS = [
|
|||||||
export const OrgRoleModifySection = ({ role, onGoBack }: Props) => {
|
export const OrgRoleModifySection = ({ role, onGoBack }: Props) => {
|
||||||
const isNonEditable = ["owner", "admin", "member", "no-access"].includes(role?.slug || "");
|
const isNonEditable = ["owner", "admin", "member", "no-access"].includes(role?.slug || "");
|
||||||
const isNewRole = !role?.slug;
|
const isNewRole = !role?.slug;
|
||||||
|
|
||||||
|
|
||||||
const { currentOrg } = useOrganization();
|
const { currentOrg } = useOrganization();
|
||||||
const orgId = currentOrg?.id || "";
|
const orgId = currentOrg?.id || "";
|
||||||
const {
|
const {
|
||||||
|
|||||||
+2
-2
@@ -7,7 +7,7 @@ import { OrgRoleModifySection } from "./OrgRoleModifySection";
|
|||||||
import { OrgRoleTable } from "./OrgRoleTable";
|
import { OrgRoleTable } from "./OrgRoleTable";
|
||||||
|
|
||||||
export const OrgRoleTabSection = () => {
|
export const OrgRoleTabSection = () => {
|
||||||
const { popUp, handlePopUpOpen, handlePopUpClose } = usePopUp(["editRole"] as const);
|
const { popUp, handlePopUpClose } = usePopUp(["editRole"] as const);
|
||||||
return popUp.editRole.isOpen ? (
|
return popUp.editRole.isOpen ? (
|
||||||
<motion.div
|
<motion.div
|
||||||
key="role-modify"
|
key="role-modify"
|
||||||
@@ -29,7 +29,7 @@ export const OrgRoleTabSection = () => {
|
|||||||
animate={{ opacity: 1, translateX: 0 }}
|
animate={{ opacity: 1, translateX: 0 }}
|
||||||
exit={{ opacity: 0, translateX: -30 }}
|
exit={{ opacity: 0, translateX: -30 }}
|
||||||
>
|
>
|
||||||
<OrgRoleTable onSelectRole={(role) => handlePopUpOpen("editRole", role)} />
|
<OrgRoleTable />
|
||||||
</motion.div>
|
</motion.div>
|
||||||
);
|
);
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -1,14 +1,17 @@
|
|||||||
import { useState } from "react";
|
import { useRouter } from "next/router";
|
||||||
import { faEdit, faMagnifyingGlass, faPlus, faTrash } from "@fortawesome/free-solid-svg-icons";
|
import { faEllipsis, faPlus } from "@fortawesome/free-solid-svg-icons";
|
||||||
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
||||||
|
import { twMerge } from "tailwind-merge";
|
||||||
|
|
||||||
import { createNotification } from "@app/components/notifications";
|
import { createNotification } from "@app/components/notifications";
|
||||||
import { OrgPermissionCan } from "@app/components/permissions";
|
import { OrgPermissionCan } from "@app/components/permissions";
|
||||||
import {
|
import {
|
||||||
Button,
|
Button,
|
||||||
DeleteActionModal,
|
DeleteActionModal,
|
||||||
IconButton,
|
DropdownMenu,
|
||||||
Input,
|
DropdownMenuContent,
|
||||||
|
DropdownMenuItem,
|
||||||
|
DropdownMenuTrigger,
|
||||||
Table,
|
Table,
|
||||||
TableContainer,
|
TableContainer,
|
||||||
TableSkeleton,
|
TableSkeleton,
|
||||||
@@ -22,17 +25,17 @@ import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@a
|
|||||||
import { usePopUp } from "@app/hooks";
|
import { usePopUp } from "@app/hooks";
|
||||||
import { useDeleteOrgRole, useGetOrgRoles } from "@app/hooks/api";
|
import { useDeleteOrgRole, useGetOrgRoles } from "@app/hooks/api";
|
||||||
import { TOrgRole } from "@app/hooks/api/roles/types";
|
import { TOrgRole } from "@app/hooks/api/roles/types";
|
||||||
|
import { RoleModal } from "@app/views/Org/RolePage/components";
|
||||||
|
|
||||||
type Props = {
|
export const OrgRoleTable = () => {
|
||||||
onSelectRole: (role?: TOrgRole) => void;
|
const router = useRouter();
|
||||||
};
|
|
||||||
|
|
||||||
export const OrgRoleTable = ({ onSelectRole }: Props) => {
|
|
||||||
const [searchRoles, setSearchRoles] = useState("");
|
|
||||||
const { currentOrg } = useOrganization();
|
const { currentOrg } = useOrganization();
|
||||||
const orgId = currentOrg?.id || "";
|
const orgId = currentOrg?.id || "";
|
||||||
|
|
||||||
const { popUp, handlePopUpOpen, handlePopUpClose } = usePopUp(["deleteRole"] as const);
|
const { popUp, handlePopUpOpen, handlePopUpClose, handlePopUpToggle } = usePopUp([
|
||||||
|
"role",
|
||||||
|
"deleteRole"
|
||||||
|
] as const);
|
||||||
|
|
||||||
const { data: roles, isLoading: isRolesLoading } = useGetOrgRoles(orgId);
|
const { data: roles, isLoading: isRolesLoading } = useGetOrgRoles(orgId);
|
||||||
|
|
||||||
@@ -54,100 +57,113 @@ export const OrgRoleTable = ({ onSelectRole }: Props) => {
|
|||||||
};
|
};
|
||||||
|
|
||||||
return (
|
return (
|
||||||
<div className="w-full">
|
<div className="rounded-lg border border-mineshaft-600 bg-mineshaft-900 p-4">
|
||||||
<div className="mb-4 flex">
|
<div className="mb-4 flex justify-between">
|
||||||
<div className="mr-4 flex-1">
|
<p className="text-xl font-semibold text-mineshaft-100">Organization Roles</p>
|
||||||
<Input
|
|
||||||
value={searchRoles}
|
|
||||||
onChange={(e) => setSearchRoles(e.target.value)}
|
|
||||||
leftIcon={<FontAwesomeIcon icon={faMagnifyingGlass} />}
|
|
||||||
placeholder="Search roles..."
|
|
||||||
/>
|
|
||||||
</div>
|
|
||||||
<OrgPermissionCan I={OrgPermissionActions.Create} a={OrgPermissionSubjects.Role}>
|
<OrgPermissionCan I={OrgPermissionActions.Create} a={OrgPermissionSubjects.Role}>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
<Button
|
<Button
|
||||||
isDisabled={!isAllowed}
|
colorSchema="primary"
|
||||||
|
type="submit"
|
||||||
leftIcon={<FontAwesomeIcon icon={faPlus} />}
|
leftIcon={<FontAwesomeIcon icon={faPlus} />}
|
||||||
onClick={() => onSelectRole()}
|
onClick={() => {
|
||||||
|
handlePopUpOpen("role");
|
||||||
|
}}
|
||||||
|
isDisabled={!isAllowed}
|
||||||
>
|
>
|
||||||
Add Role
|
Add Role
|
||||||
</Button>
|
</Button>
|
||||||
)}
|
)}
|
||||||
</OrgPermissionCan>
|
</OrgPermissionCan>
|
||||||
</div>
|
</div>
|
||||||
<div>
|
<TableContainer>
|
||||||
<TableContainer>
|
<Table>
|
||||||
<Table>
|
<THead>
|
||||||
<THead>
|
<Tr>
|
||||||
<Tr>
|
<Th>Name</Th>
|
||||||
<Th>Name</Th>
|
<Th>Slug</Th>
|
||||||
<Th>Slug</Th>
|
<Th aria-label="actions" className="w-5" />
|
||||||
<Th aria-label="actions" />
|
</Tr>
|
||||||
</Tr>
|
</THead>
|
||||||
</THead>
|
<TBody>
|
||||||
<TBody>
|
{isRolesLoading && <TableSkeleton columns={3} innerKey="org-roles" />}
|
||||||
{isRolesLoading && <TableSkeleton columns={4} innerKey="org-roles" />}
|
{roles?.map((role) => {
|
||||||
{roles?.map((role) => {
|
const { id, name, slug } = role;
|
||||||
const { id, name, slug } = role;
|
const isNonMutatable = ["owner", "admin", "member", "no-access"].includes(slug);
|
||||||
const isNonMutatable = ["owner", "admin", "member", "no-access"].includes(slug);
|
return (
|
||||||
|
<Tr
|
||||||
return (
|
key={`role-list-${id}`}
|
||||||
<Tr key={`role-list-${id}`}>
|
className="h-10 cursor-pointer transition-colors duration-300 hover:bg-mineshaft-700"
|
||||||
<Td>{name}</Td>
|
onClick={() => router.push(`/org/${orgId}/roles/${id}`)}
|
||||||
<Td>{slug}</Td>
|
>
|
||||||
<Td className="flex justify-end">
|
<Td>{name}</Td>
|
||||||
<div className="flex space-x-2">
|
<Td>{slug}</Td>
|
||||||
|
<Td>
|
||||||
|
<DropdownMenu>
|
||||||
|
<DropdownMenuTrigger asChild className="rounded-lg">
|
||||||
|
<div className="hover:text-primary-400 data-[state=open]:text-primary-400">
|
||||||
|
<FontAwesomeIcon size="sm" icon={faEllipsis} />
|
||||||
|
</div>
|
||||||
|
</DropdownMenuTrigger>
|
||||||
|
<DropdownMenuContent align="start" className="p-1">
|
||||||
<OrgPermissionCan
|
<OrgPermissionCan
|
||||||
I={OrgPermissionActions.Edit}
|
I={OrgPermissionActions.Edit}
|
||||||
a={OrgPermissionSubjects.Role}
|
a={OrgPermissionSubjects.Role}
|
||||||
renderTooltip
|
|
||||||
allowedLabel="Edit"
|
|
||||||
>
|
>
|
||||||
{(isAllowed) => (
|
{(isAllowed) => (
|
||||||
<IconButton
|
<DropdownMenuItem
|
||||||
isDisabled={!isAllowed}
|
className={twMerge(
|
||||||
ariaLabel="edit"
|
!isAllowed && "pointer-events-none cursor-not-allowed opacity-50"
|
||||||
onClick={() => onSelectRole(role)}
|
)}
|
||||||
variant="plain"
|
onClick={(e) => {
|
||||||
|
e.stopPropagation();
|
||||||
|
router.push(`/org/${orgId}/roles/${id}`);
|
||||||
|
}}
|
||||||
|
disabled={!isAllowed}
|
||||||
>
|
>
|
||||||
<FontAwesomeIcon icon={faEdit} />
|
{`${isNonMutatable ? "View" : "Edit"} Role`}
|
||||||
</IconButton>
|
</DropdownMenuItem>
|
||||||
)}
|
)}
|
||||||
</OrgPermissionCan>
|
</OrgPermissionCan>
|
||||||
<OrgPermissionCan
|
{!isNonMutatable && (
|
||||||
I={OrgPermissionActions.Delete}
|
<OrgPermissionCan
|
||||||
a={OrgPermissionSubjects.Role}
|
I={OrgPermissionActions.Delete}
|
||||||
renderTooltip
|
a={OrgPermissionSubjects.Role}
|
||||||
allowedLabel={
|
>
|
||||||
isNonMutatable ? "Reserved roles are non-removable" : "Delete"
|
{(isAllowed) => (
|
||||||
}
|
<DropdownMenuItem
|
||||||
>
|
className={twMerge(
|
||||||
{(isAllowed) => (
|
isAllowed
|
||||||
<IconButton
|
? "hover:!bg-red-500 hover:!text-white"
|
||||||
ariaLabel="delete"
|
: "pointer-events-none cursor-not-allowed opacity-50"
|
||||||
onClick={() => handlePopUpOpen("deleteRole", role)}
|
)}
|
||||||
variant="plain"
|
onClick={(e) => {
|
||||||
isDisabled={isNonMutatable || !isAllowed}
|
e.stopPropagation();
|
||||||
>
|
handlePopUpOpen("deleteRole", role);
|
||||||
<FontAwesomeIcon icon={faTrash} />
|
}}
|
||||||
</IconButton>
|
disabled={!isAllowed}
|
||||||
)}
|
>
|
||||||
</OrgPermissionCan>
|
Delete Role
|
||||||
</div>
|
</DropdownMenuItem>
|
||||||
</Td>
|
)}
|
||||||
</Tr>
|
</OrgPermissionCan>
|
||||||
);
|
)}
|
||||||
})}
|
</DropdownMenuContent>
|
||||||
</TBody>
|
</DropdownMenu>
|
||||||
</Table>
|
</Td>
|
||||||
</TableContainer>
|
</Tr>
|
||||||
</div>
|
);
|
||||||
|
})}
|
||||||
|
</TBody>
|
||||||
|
</Table>
|
||||||
|
</TableContainer>
|
||||||
|
<RoleModal popUp={popUp} handlePopUpToggle={handlePopUpToggle} />
|
||||||
<DeleteActionModal
|
<DeleteActionModal
|
||||||
isOpen={popUp.deleteRole.isOpen}
|
isOpen={popUp.deleteRole.isOpen}
|
||||||
title={`Are you sure want to delete ${
|
title={`Are you sure want to delete ${
|
||||||
(popUp?.deleteRole?.data as TOrgRole)?.name || " "
|
(popUp?.deleteRole?.data as TOrgRole)?.name || " "
|
||||||
} role?`}
|
} role?`}
|
||||||
|
onChange={(isOpen) => handlePopUpToggle("deleteRole", isOpen)}
|
||||||
deleteKey={(popUp?.deleteRole?.data as TOrgRole)?.slug || ""}
|
deleteKey={(popUp?.deleteRole?.data as TOrgRole)?.slug || ""}
|
||||||
onClose={() => handlePopUpClose("deleteRole")}
|
onClose={() => handlePopUpClose("deleteRole")}
|
||||||
onDeleteApproved={handleRoleDelete}
|
onDeleteApproved={handleRoleDelete}
|
||||||
|
|||||||
@@ -0,0 +1,157 @@
|
|||||||
|
/* eslint-disable @typescript-eslint/no-unused-vars */
|
||||||
|
import { useRouter } from "next/router";
|
||||||
|
import { faChevronLeft, faEllipsis } from "@fortawesome/free-solid-svg-icons";
|
||||||
|
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
||||||
|
import { twMerge } from "tailwind-merge";
|
||||||
|
|
||||||
|
import { createNotification } from "@app/components/notifications";
|
||||||
|
import { OrgPermissionCan } from "@app/components/permissions";
|
||||||
|
import {
|
||||||
|
Button,
|
||||||
|
DeleteActionModal,
|
||||||
|
DropdownMenu,
|
||||||
|
DropdownMenuContent,
|
||||||
|
DropdownMenuItem,
|
||||||
|
DropdownMenuTrigger,
|
||||||
|
Tooltip
|
||||||
|
} from "@app/components/v2";
|
||||||
|
import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
||||||
|
import { withPermission } from "@app/hoc";
|
||||||
|
import { useDeleteOrgRole, useGetOrgRole } from "@app/hooks/api";
|
||||||
|
import { usePopUp } from "@app/hooks/usePopUp";
|
||||||
|
|
||||||
|
import { RoleDetailsSection, RoleModal, RolePermissionsSection } from "./components";
|
||||||
|
|
||||||
|
export const RolePage = withPermission(
|
||||||
|
() => {
|
||||||
|
const router = useRouter();
|
||||||
|
const roleId = router.query.roleId as string;
|
||||||
|
const { currentOrg } = useOrganization();
|
||||||
|
const orgId = currentOrg?.id || "";
|
||||||
|
const { data } = useGetOrgRole(orgId, roleId);
|
||||||
|
const { mutateAsync: deleteOrgRole } = useDeleteOrgRole();
|
||||||
|
|
||||||
|
const { popUp, handlePopUpOpen, handlePopUpClose, handlePopUpToggle } = usePopUp([
|
||||||
|
"role",
|
||||||
|
"deleteOrgRole"
|
||||||
|
] as const);
|
||||||
|
|
||||||
|
const onDeleteOrgRoleSubmit = async () => {
|
||||||
|
try {
|
||||||
|
if (!orgId || !roleId) return;
|
||||||
|
|
||||||
|
await deleteOrgRole({
|
||||||
|
orgId,
|
||||||
|
id: roleId
|
||||||
|
});
|
||||||
|
|
||||||
|
createNotification({
|
||||||
|
text: "Successfully deleted organization role",
|
||||||
|
type: "success"
|
||||||
|
});
|
||||||
|
|
||||||
|
handlePopUpClose("deleteOrgRole");
|
||||||
|
router.push(`/org/${orgId}/members`);
|
||||||
|
} catch (err) {
|
||||||
|
console.error(err);
|
||||||
|
const error = err as any;
|
||||||
|
const text = error?.response?.data?.message ?? "Failed to delete organization role";
|
||||||
|
|
||||||
|
createNotification({
|
||||||
|
text,
|
||||||
|
type: "error"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
const isCustomRole = !["admin", "member", "no-access"].includes(data?.slug ?? "");
|
||||||
|
|
||||||
|
return (
|
||||||
|
<div className="container mx-auto flex flex-col justify-between bg-bunker-800 text-white">
|
||||||
|
{data && (
|
||||||
|
<div className="mx-auto mb-6 w-full max-w-7xl py-6 px-6">
|
||||||
|
<Button
|
||||||
|
variant="link"
|
||||||
|
type="submit"
|
||||||
|
leftIcon={<FontAwesomeIcon icon={faChevronLeft} />}
|
||||||
|
onClick={() => {
|
||||||
|
router.push(`/org/${orgId}/members`);
|
||||||
|
}}
|
||||||
|
className="mb-4"
|
||||||
|
>
|
||||||
|
Roles
|
||||||
|
</Button>
|
||||||
|
<div className="mb-4 flex items-center justify-between">
|
||||||
|
<p className="text-3xl font-semibold text-white">{data.name}</p>
|
||||||
|
{isCustomRole && (
|
||||||
|
<DropdownMenu>
|
||||||
|
<DropdownMenuTrigger asChild className="rounded-lg">
|
||||||
|
<div className="hover:text-primary-400 data-[state=open]:text-primary-400">
|
||||||
|
<Tooltip content="More options">
|
||||||
|
<FontAwesomeIcon size="sm" icon={faEllipsis} />
|
||||||
|
</Tooltip>
|
||||||
|
</div>
|
||||||
|
</DropdownMenuTrigger>
|
||||||
|
<DropdownMenuContent align="start" className="p-1">
|
||||||
|
<OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Role}>
|
||||||
|
{(isAllowed) => (
|
||||||
|
<DropdownMenuItem
|
||||||
|
className={twMerge(
|
||||||
|
!isAllowed && "pointer-events-none cursor-not-allowed opacity-50"
|
||||||
|
)}
|
||||||
|
onClick={async () => {
|
||||||
|
handlePopUpOpen("role", {
|
||||||
|
roleId
|
||||||
|
});
|
||||||
|
}}
|
||||||
|
disabled={!isAllowed}
|
||||||
|
>
|
||||||
|
Edit Role
|
||||||
|
</DropdownMenuItem>
|
||||||
|
)}
|
||||||
|
</OrgPermissionCan>
|
||||||
|
<OrgPermissionCan
|
||||||
|
I={OrgPermissionActions.Delete}
|
||||||
|
a={OrgPermissionSubjects.Role}
|
||||||
|
>
|
||||||
|
{(isAllowed) => (
|
||||||
|
<DropdownMenuItem
|
||||||
|
className={twMerge(
|
||||||
|
isAllowed
|
||||||
|
? "hover:!bg-red-500 hover:!text-white"
|
||||||
|
: "pointer-events-none cursor-not-allowed opacity-50"
|
||||||
|
)}
|
||||||
|
onClick={async () => {
|
||||||
|
handlePopUpOpen("deleteOrgRole");
|
||||||
|
}}
|
||||||
|
disabled={!isAllowed}
|
||||||
|
>
|
||||||
|
Delete Role
|
||||||
|
</DropdownMenuItem>
|
||||||
|
)}
|
||||||
|
</OrgPermissionCan>
|
||||||
|
</DropdownMenuContent>
|
||||||
|
</DropdownMenu>
|
||||||
|
)}
|
||||||
|
</div>
|
||||||
|
<div className="flex">
|
||||||
|
<div className="mr-4 w-96">
|
||||||
|
<RoleDetailsSection roleId={roleId} handlePopUpOpen={handlePopUpOpen} />
|
||||||
|
</div>
|
||||||
|
<RolePermissionsSection roleId={roleId} />
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
|
<RoleModal popUp={popUp} handlePopUpToggle={handlePopUpToggle} />
|
||||||
|
<DeleteActionModal
|
||||||
|
isOpen={popUp.deleteOrgRole.isOpen}
|
||||||
|
title={`Are you sure want to delete the organization role ${data?.name ?? ""}?`}
|
||||||
|
onChange={(isOpen) => handlePopUpToggle("deleteOrgRole", isOpen)}
|
||||||
|
deleteKey="confirm"
|
||||||
|
onDeleteApproved={() => onDeleteOrgRoleSubmit()}
|
||||||
|
/>
|
||||||
|
</div>
|
||||||
|
);
|
||||||
|
},
|
||||||
|
{ action: OrgPermissionActions.Read, subject: OrgPermissionSubjects.Role }
|
||||||
|
);
|
||||||
@@ -0,0 +1,95 @@
|
|||||||
|
import { faCheck, faCopy, faPencil } from "@fortawesome/free-solid-svg-icons";
|
||||||
|
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
||||||
|
|
||||||
|
import { OrgPermissionCan } from "@app/components/permissions";
|
||||||
|
import { IconButton, Tooltip } from "@app/components/v2";
|
||||||
|
import { OrgPermissionActions, OrgPermissionSubjects, useOrganization } from "@app/context";
|
||||||
|
import { useTimedReset } from "@app/hooks";
|
||||||
|
import { useGetOrgRole } from "@app/hooks/api";
|
||||||
|
import { UsePopUpState } from "@app/hooks/usePopUp";
|
||||||
|
|
||||||
|
type Props = {
|
||||||
|
roleId: string;
|
||||||
|
handlePopUpOpen: (popUpName: keyof UsePopUpState<["role"]>, data?: {}) => void;
|
||||||
|
};
|
||||||
|
|
||||||
|
export const RoleDetailsSection = ({ roleId, handlePopUpOpen }: Props) => {
|
||||||
|
const [copyTextId, isCopyingId, setCopyTextId] = useTimedReset<string>({
|
||||||
|
initialState: "Copy ID to clipboard"
|
||||||
|
});
|
||||||
|
|
||||||
|
const { currentOrg } = useOrganization();
|
||||||
|
const orgId = currentOrg?.id || "";
|
||||||
|
const { data } = useGetOrgRole(orgId, roleId);
|
||||||
|
const isCustomRole = !["admin", "member", "no-access"].includes(data?.slug ?? "");
|
||||||
|
|
||||||
|
return data ? (
|
||||||
|
<div className="rounded-lg border border-mineshaft-600 bg-mineshaft-900 p-4">
|
||||||
|
<div className="flex items-center justify-between border-b border-mineshaft-400 pb-4">
|
||||||
|
<h3 className="text-lg font-semibold text-mineshaft-100">Details</h3>
|
||||||
|
{isCustomRole && (
|
||||||
|
<OrgPermissionCan I={OrgPermissionActions.Edit} a={OrgPermissionSubjects.Role}>
|
||||||
|
{(isAllowed) => {
|
||||||
|
return (
|
||||||
|
<Tooltip content="Edit Role">
|
||||||
|
<IconButton
|
||||||
|
isDisabled={!isAllowed}
|
||||||
|
ariaLabel="copy icon"
|
||||||
|
variant="plain"
|
||||||
|
className="group relative"
|
||||||
|
onClick={() =>
|
||||||
|
handlePopUpOpen("role", {
|
||||||
|
roleId
|
||||||
|
})
|
||||||
|
}
|
||||||
|
>
|
||||||
|
<FontAwesomeIcon icon={faPencil} />
|
||||||
|
</IconButton>
|
||||||
|
</Tooltip>
|
||||||
|
);
|
||||||
|
}}
|
||||||
|
</OrgPermissionCan>
|
||||||
|
)}
|
||||||
|
</div>
|
||||||
|
<div className="pt-4">
|
||||||
|
<div className="mb-4">
|
||||||
|
<p className="text-sm font-semibold text-mineshaft-300">Role ID</p>
|
||||||
|
<div className="group flex align-top">
|
||||||
|
<p className="text-sm text-mineshaft-300">{roleId}</p>
|
||||||
|
<div className="opacity-0 transition-opacity duration-300 group-hover:opacity-100">
|
||||||
|
<Tooltip content={copyTextId}>
|
||||||
|
<IconButton
|
||||||
|
ariaLabel="copy icon"
|
||||||
|
variant="plain"
|
||||||
|
className="group relative ml-2"
|
||||||
|
onClick={() => {
|
||||||
|
navigator.clipboard.writeText(roleId);
|
||||||
|
setCopyTextId("Copied");
|
||||||
|
}}
|
||||||
|
>
|
||||||
|
<FontAwesomeIcon icon={isCopyingId ? faCheck : faCopy} />
|
||||||
|
</IconButton>
|
||||||
|
</Tooltip>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
<div className="mb-4">
|
||||||
|
<p className="text-sm font-semibold text-mineshaft-300">Name</p>
|
||||||
|
<p className="text-sm text-mineshaft-300">{data.name}</p>
|
||||||
|
</div>
|
||||||
|
<div className="mb-4">
|
||||||
|
<p className="text-sm font-semibold text-mineshaft-300">Slug</p>
|
||||||
|
<p className="text-sm text-mineshaft-300">{data.slug}</p>
|
||||||
|
</div>
|
||||||
|
<div className="mb-4">
|
||||||
|
<p className="text-sm font-semibold text-mineshaft-300">Description</p>
|
||||||
|
<p className="text-sm text-mineshaft-300">
|
||||||
|
{data.description?.length ? data.description : "-"}
|
||||||
|
</p>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
) : (
|
||||||
|
<div />
|
||||||
|
);
|
||||||
|
};
|
||||||
@@ -0,0 +1,200 @@
|
|||||||
|
import { useEffect } from "react";
|
||||||
|
import { Controller, useForm } from "react-hook-form";
|
||||||
|
import { useRouter } from "next/router";
|
||||||
|
import { zodResolver } from "@hookform/resolvers/zod";
|
||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { createNotification } from "@app/components/notifications";
|
||||||
|
import { Button, FormControl, Input, Modal, ModalContent } from "@app/components/v2";
|
||||||
|
import { useOrganization } from "@app/context";
|
||||||
|
import { useCreateOrgRole, useGetOrgRole, useUpdateOrgRole } from "@app/hooks/api";
|
||||||
|
import { UsePopUpState } from "@app/hooks/usePopUp";
|
||||||
|
|
||||||
|
const schema = z
|
||||||
|
.object({
|
||||||
|
name: z.string(),
|
||||||
|
description: z.string(),
|
||||||
|
slug: z.string()
|
||||||
|
})
|
||||||
|
.required();
|
||||||
|
|
||||||
|
export type FormData = z.infer<typeof schema>;
|
||||||
|
|
||||||
|
type Props = {
|
||||||
|
popUp: UsePopUpState<["role"]>;
|
||||||
|
handlePopUpToggle: (popUpName: keyof UsePopUpState<["role"]>, state?: boolean) => void;
|
||||||
|
};
|
||||||
|
|
||||||
|
export const RoleModal = ({ popUp, handlePopUpToggle }: Props) => {
|
||||||
|
const router = useRouter();
|
||||||
|
const { currentOrg } = useOrganization();
|
||||||
|
const orgId = currentOrg?.id || "";
|
||||||
|
|
||||||
|
const popupData = popUp?.role?.data as {
|
||||||
|
roleId: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
const { data: role } = useGetOrgRole(orgId, popupData?.roleId ?? "");
|
||||||
|
|
||||||
|
const { mutateAsync: createOrgRole } = useCreateOrgRole();
|
||||||
|
const { mutateAsync: updateOrgRole } = useUpdateOrgRole();
|
||||||
|
|
||||||
|
const {
|
||||||
|
control,
|
||||||
|
handleSubmit,
|
||||||
|
reset,
|
||||||
|
formState: { isSubmitting }
|
||||||
|
} = useForm<FormData>({
|
||||||
|
resolver: zodResolver(schema),
|
||||||
|
defaultValues: {
|
||||||
|
name: "",
|
||||||
|
description: ""
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
useEffect(() => {
|
||||||
|
if (role) {
|
||||||
|
reset({
|
||||||
|
name: role.name,
|
||||||
|
description: role.description,
|
||||||
|
slug: role.slug
|
||||||
|
});
|
||||||
|
} else {
|
||||||
|
reset({
|
||||||
|
name: "",
|
||||||
|
description: "",
|
||||||
|
slug: ""
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}, [role]);
|
||||||
|
|
||||||
|
const onFormSubmit = async ({ name, description, slug }: FormData) => {
|
||||||
|
try {
|
||||||
|
console.log("onFormSubmit args: ", {
|
||||||
|
name,
|
||||||
|
description,
|
||||||
|
slug
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!orgId) return;
|
||||||
|
|
||||||
|
if (role) {
|
||||||
|
// update
|
||||||
|
|
||||||
|
await updateOrgRole({
|
||||||
|
orgId,
|
||||||
|
id: role.id,
|
||||||
|
name,
|
||||||
|
description,
|
||||||
|
slug
|
||||||
|
});
|
||||||
|
|
||||||
|
handlePopUpToggle("role", false);
|
||||||
|
} else {
|
||||||
|
// create
|
||||||
|
|
||||||
|
const newRole = await createOrgRole({
|
||||||
|
orgId,
|
||||||
|
name,
|
||||||
|
description,
|
||||||
|
slug,
|
||||||
|
permissions: []
|
||||||
|
});
|
||||||
|
|
||||||
|
handlePopUpToggle("role", false);
|
||||||
|
router.push(`/org/${orgId}/roles/${newRole.id}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
createNotification({
|
||||||
|
text: `Successfully ${popUp?.role?.data ? "updated" : "created"} role`,
|
||||||
|
type: "success"
|
||||||
|
});
|
||||||
|
|
||||||
|
reset();
|
||||||
|
} catch (err) {
|
||||||
|
console.error(err);
|
||||||
|
const error = err as any;
|
||||||
|
const text =
|
||||||
|
error?.response?.data?.message ??
|
||||||
|
`Failed to ${popUp?.role?.data ? "update" : "create"} role`;
|
||||||
|
|
||||||
|
createNotification({
|
||||||
|
text,
|
||||||
|
type: "error"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
return (
|
||||||
|
<Modal
|
||||||
|
isOpen={popUp?.role?.isOpen}
|
||||||
|
onOpenChange={(isOpen) => {
|
||||||
|
handlePopUpToggle("role", isOpen);
|
||||||
|
reset();
|
||||||
|
}}
|
||||||
|
>
|
||||||
|
<ModalContent title={`${popUp?.role?.data ? "Update" : "Create"} Role`}>
|
||||||
|
<form onSubmit={handleSubmit(onFormSubmit)}>
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
defaultValue=""
|
||||||
|
name="name"
|
||||||
|
render={({ field, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
label="Name"
|
||||||
|
isError={Boolean(error)}
|
||||||
|
errorText={error?.message}
|
||||||
|
isRequired
|
||||||
|
>
|
||||||
|
<Input {...field} placeholder="Billing Team" />
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
defaultValue=""
|
||||||
|
name="slug"
|
||||||
|
render={({ field, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
label="Slug"
|
||||||
|
isError={Boolean(error)}
|
||||||
|
errorText={error?.message}
|
||||||
|
isRequired
|
||||||
|
>
|
||||||
|
<Input {...field} placeholder="billing" />
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
defaultValue=""
|
||||||
|
name="description"
|
||||||
|
render={({ field, fieldState: { error } }) => (
|
||||||
|
<FormControl label="Description" isError={Boolean(error)} errorText={error?.message}>
|
||||||
|
<Input {...field} placeholder="To manage billing" />
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
<div className="flex items-center">
|
||||||
|
<Button
|
||||||
|
className="mr-4"
|
||||||
|
size="sm"
|
||||||
|
type="submit"
|
||||||
|
isLoading={isSubmitting}
|
||||||
|
isDisabled={isSubmitting}
|
||||||
|
>
|
||||||
|
{popUp?.role?.data ? "Update" : "Create"}
|
||||||
|
</Button>
|
||||||
|
<Button
|
||||||
|
colorSchema="secondary"
|
||||||
|
variant="plain"
|
||||||
|
onClick={() => handlePopUpToggle("role", false)}
|
||||||
|
>
|
||||||
|
Cancel
|
||||||
|
</Button>
|
||||||
|
</div>
|
||||||
|
</form>
|
||||||
|
</ModalContent>
|
||||||
|
</Modal>
|
||||||
|
);
|
||||||
|
};
|
||||||
+215
@@ -0,0 +1,215 @@
|
|||||||
|
import { useEffect, useMemo } from "react";
|
||||||
|
import { Control, Controller, UseFormSetValue, useWatch } from "react-hook-form";
|
||||||
|
import { faChevronDown, faChevronRight } from "@fortawesome/free-solid-svg-icons";
|
||||||
|
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
||||||
|
|
||||||
|
import { createNotification } from "@app/components/notifications";
|
||||||
|
import { Checkbox, Select, SelectItem, Td, Tr } from "@app/components/v2";
|
||||||
|
import { useToggle } from "@app/hooks";
|
||||||
|
import { TFormSchema } from "@app/views/Org/MembersPage/components/OrgRoleTabSection/OrgRoleModifySection/OrgRoleModifySection.utils";
|
||||||
|
|
||||||
|
const PERMISSIONS = [
|
||||||
|
{ action: "read", label: "View" },
|
||||||
|
{ action: "create", label: "Create" },
|
||||||
|
{ action: "edit", label: "Modify" },
|
||||||
|
{ action: "delete", label: "Remove" }
|
||||||
|
] as const;
|
||||||
|
|
||||||
|
const SECRET_SCANNING_PERMISSIONS = [
|
||||||
|
{ action: "read", label: "View risks" },
|
||||||
|
{ action: "create", label: "Add integrations" },
|
||||||
|
{ action: "edit", label: "Edit risk status" },
|
||||||
|
{ action: "delete", label: "Remove integrations" }
|
||||||
|
] as const;
|
||||||
|
|
||||||
|
const INCIDENT_CONTACTS_PERMISSIONS = [
|
||||||
|
{ action: "read", label: "View contacts" },
|
||||||
|
{ action: "create", label: "Add new contacts" },
|
||||||
|
{ action: "edit", label: "Edit contacts" },
|
||||||
|
{ action: "delete", label: "Remove contacts" }
|
||||||
|
] as const;
|
||||||
|
|
||||||
|
const MEMBERS_PERMISSIONS = [
|
||||||
|
{ action: "read", label: "View all members" },
|
||||||
|
{ action: "create", label: "Invite members" },
|
||||||
|
{ action: "edit", label: "Edit members" },
|
||||||
|
{ action: "delete", label: "Remove members" }
|
||||||
|
] as const;
|
||||||
|
|
||||||
|
const BILLING_PERMISSIONS = [
|
||||||
|
{ action: "read", label: "View bills" },
|
||||||
|
{ action: "create", label: "Add payment methods" },
|
||||||
|
{ action: "edit", label: "Edit payments" },
|
||||||
|
{ action: "delete", label: "Remove payments" }
|
||||||
|
] as const;
|
||||||
|
|
||||||
|
const getPermissionList = (option: string) => {
|
||||||
|
switch (option) {
|
||||||
|
case "secret-scanning":
|
||||||
|
return SECRET_SCANNING_PERMISSIONS;
|
||||||
|
case "billing":
|
||||||
|
return BILLING_PERMISSIONS;
|
||||||
|
case "incident-contact":
|
||||||
|
return INCIDENT_CONTACTS_PERMISSIONS;
|
||||||
|
case "member":
|
||||||
|
return MEMBERS_PERMISSIONS;
|
||||||
|
default:
|
||||||
|
return PERMISSIONS;
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
type Props = {
|
||||||
|
isEditable: boolean;
|
||||||
|
title: string;
|
||||||
|
formName: keyof Omit<Exclude<TFormSchema["permissions"], undefined>, "workspace">;
|
||||||
|
setValue: UseFormSetValue<TFormSchema>;
|
||||||
|
control: Control<TFormSchema>;
|
||||||
|
};
|
||||||
|
|
||||||
|
enum Permission {
|
||||||
|
NoAccess = "no-access",
|
||||||
|
ReadOnly = "read-only",
|
||||||
|
FullAccess = "full-acess",
|
||||||
|
Custom = "custom"
|
||||||
|
}
|
||||||
|
|
||||||
|
export const RolePermissionRow = ({ isEditable, title, formName, control, setValue }: Props) => {
|
||||||
|
const [isRowExpanded, setIsRowExpanded] = useToggle();
|
||||||
|
const [isCustom, setIsCustom] = useToggle();
|
||||||
|
|
||||||
|
const rule = useWatch({
|
||||||
|
control,
|
||||||
|
name: `permissions.${formName}`
|
||||||
|
});
|
||||||
|
|
||||||
|
const selectedPermissionCategory = useMemo(() => {
|
||||||
|
const actions = Object.keys(rule || {}) as Array<keyof typeof rule>;
|
||||||
|
const totalActions = PERMISSIONS.length;
|
||||||
|
const score = actions.map((key) => (rule?.[key] ? 1 : 0)).reduce((a, b) => a + b, 0 as number);
|
||||||
|
|
||||||
|
if (isCustom) return Permission.Custom;
|
||||||
|
if (score === 0) return Permission.NoAccess;
|
||||||
|
if (score === totalActions) return Permission.FullAccess;
|
||||||
|
if (score === 1 && rule?.read) return Permission.ReadOnly;
|
||||||
|
|
||||||
|
return Permission.Custom;
|
||||||
|
}, [rule, isCustom]);
|
||||||
|
|
||||||
|
useEffect(() => {
|
||||||
|
if (selectedPermissionCategory === Permission.Custom) setIsCustom.on();
|
||||||
|
else setIsCustom.off();
|
||||||
|
}, [selectedPermissionCategory]);
|
||||||
|
|
||||||
|
useEffect(() => {
|
||||||
|
const isRowCustom = selectedPermissionCategory === Permission.Custom;
|
||||||
|
if (isRowCustom) {
|
||||||
|
setIsRowExpanded.on();
|
||||||
|
}
|
||||||
|
}, []);
|
||||||
|
|
||||||
|
const handlePermissionChange = (val: Permission) => {
|
||||||
|
if (val === Permission.Custom) {
|
||||||
|
setIsRowExpanded.on();
|
||||||
|
setIsCustom.on();
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
setIsCustom.off();
|
||||||
|
|
||||||
|
switch (val) {
|
||||||
|
case Permission.NoAccess:
|
||||||
|
setValue(
|
||||||
|
`permissions.${formName}`,
|
||||||
|
{ read: false, edit: false, create: false, delete: false },
|
||||||
|
{ shouldDirty: true }
|
||||||
|
);
|
||||||
|
break;
|
||||||
|
case Permission.FullAccess:
|
||||||
|
setValue(
|
||||||
|
`permissions.${formName}`,
|
||||||
|
{ read: true, edit: true, create: true, delete: true },
|
||||||
|
{ shouldDirty: true }
|
||||||
|
);
|
||||||
|
break;
|
||||||
|
case Permission.ReadOnly:
|
||||||
|
setValue(
|
||||||
|
`permissions.${formName}`,
|
||||||
|
{ read: true, edit: false, create: false, delete: false },
|
||||||
|
{ shouldDirty: true }
|
||||||
|
);
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
setValue(
|
||||||
|
`permissions.${formName}`,
|
||||||
|
{ read: false, edit: false, create: false, delete: false },
|
||||||
|
{ shouldDirty: true }
|
||||||
|
);
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
return (
|
||||||
|
<>
|
||||||
|
<Tr
|
||||||
|
className="h-10 cursor-pointer transition-colors duration-300 hover:bg-mineshaft-700"
|
||||||
|
onClick={() => setIsRowExpanded.toggle()}
|
||||||
|
>
|
||||||
|
<Td>
|
||||||
|
<FontAwesomeIcon icon={isRowExpanded ? faChevronDown : faChevronRight} />
|
||||||
|
</Td>
|
||||||
|
<Td>{title}</Td>
|
||||||
|
<Td>
|
||||||
|
<Select
|
||||||
|
value={selectedPermissionCategory}
|
||||||
|
className="w-40 bg-mineshaft-600"
|
||||||
|
dropdownContainerClassName="border border-mineshaft-600 bg-mineshaft-800"
|
||||||
|
onValueChange={handlePermissionChange}
|
||||||
|
isDisabled={!isEditable}
|
||||||
|
>
|
||||||
|
<SelectItem value={Permission.NoAccess}>No Access</SelectItem>
|
||||||
|
<SelectItem value={Permission.ReadOnly}>Read Only</SelectItem>
|
||||||
|
<SelectItem value={Permission.FullAccess}>Full Access</SelectItem>
|
||||||
|
<SelectItem value={Permission.Custom}>Custom</SelectItem>
|
||||||
|
</Select>
|
||||||
|
</Td>
|
||||||
|
</Tr>
|
||||||
|
{isRowExpanded && (
|
||||||
|
<Tr>
|
||||||
|
<Td
|
||||||
|
colSpan={3}
|
||||||
|
className={`bg-bunker-600 px-0 py-0 ${isRowExpanded && " border-mineshaft-500 p-8"}`}
|
||||||
|
>
|
||||||
|
<div className="grid grid-cols-3 gap-4">
|
||||||
|
{getPermissionList(formName).map(({ action, label }) => {
|
||||||
|
return (
|
||||||
|
<Controller
|
||||||
|
name={`permissions.${formName}.${action}`}
|
||||||
|
key={`permissions.${formName}.${action}`}
|
||||||
|
control={control}
|
||||||
|
render={({ field }) => (
|
||||||
|
<Checkbox
|
||||||
|
isChecked={field.value}
|
||||||
|
onCheckedChange={(e) => {
|
||||||
|
if (!isEditable) {
|
||||||
|
createNotification({
|
||||||
|
type: "error",
|
||||||
|
text: "Failed to update default role"
|
||||||
|
});
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
field.onChange(e);
|
||||||
|
}}
|
||||||
|
id={`permissions.${formName}.${action}`}
|
||||||
|
>
|
||||||
|
{label}
|
||||||
|
</Checkbox>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
);
|
||||||
|
})}
|
||||||
|
</div>
|
||||||
|
</Td>
|
||||||
|
</Tr>
|
||||||
|
)}
|
||||||
|
</>
|
||||||
|
);
|
||||||
|
};
|
||||||
+162
@@ -0,0 +1,162 @@
|
|||||||
|
import { useForm } from "react-hook-form";
|
||||||
|
import { zodResolver } from "@hookform/resolvers/zod";
|
||||||
|
|
||||||
|
import { createNotification } from "@app/components/notifications";
|
||||||
|
import { Button , Table, TableContainer, TBody, Th, THead, Tr } from "@app/components/v2";
|
||||||
|
import { useOrganization } from "@app/context";
|
||||||
|
import { useGetOrgRole, useUpdateOrgRole } from "@app/hooks/api";
|
||||||
|
import {
|
||||||
|
formRolePermission2API,
|
||||||
|
formSchema,
|
||||||
|
rolePermission2Form,
|
||||||
|
TFormSchema
|
||||||
|
} from "@app/views/Org/MembersPage/components/OrgRoleTabSection/OrgRoleModifySection/OrgRoleModifySection.utils";
|
||||||
|
|
||||||
|
import { RolePermissionRow } from "./RolePermissionRow";
|
||||||
|
|
||||||
|
const SIMPLE_PERMISSION_OPTIONS = [
|
||||||
|
{
|
||||||
|
title: "User management",
|
||||||
|
formName: "member"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
title: "Group management",
|
||||||
|
formName: "groups"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
title: "Machine identity management",
|
||||||
|
formName: "identity"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
title: "Billing & usage",
|
||||||
|
formName: "billing"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
title: "Role management",
|
||||||
|
formName: "role"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
title: "Incident Contacts",
|
||||||
|
formName: "incident-contact"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
title: "Organization profile",
|
||||||
|
formName: "settings"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
title: "Secret Scanning",
|
||||||
|
formName: "secret-scanning"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
title: "SSO",
|
||||||
|
formName: "sso"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
title: "LDAP",
|
||||||
|
formName: "ldap"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
title: "SCIM",
|
||||||
|
formName: "scim"
|
||||||
|
}
|
||||||
|
] as const;
|
||||||
|
|
||||||
|
type Props = {
|
||||||
|
roleId: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
export const RolePermissionsSection = ({ roleId }: Props) => {
|
||||||
|
const { currentOrg } = useOrganization();
|
||||||
|
const orgId = currentOrg?.id || "";
|
||||||
|
|
||||||
|
const { data: role } = useGetOrgRole(orgId, roleId);
|
||||||
|
|
||||||
|
const {
|
||||||
|
setValue,
|
||||||
|
control,
|
||||||
|
handleSubmit,
|
||||||
|
formState: { isDirty, isSubmitting },
|
||||||
|
reset
|
||||||
|
} = useForm<TFormSchema>({
|
||||||
|
defaultValues: role ? { ...role, permissions: rolePermission2Form(role.permissions) } : {},
|
||||||
|
resolver: zodResolver(formSchema)
|
||||||
|
});
|
||||||
|
|
||||||
|
const { mutateAsync: updateRole } = useUpdateOrgRole();
|
||||||
|
|
||||||
|
const onSubmit = async (el: TFormSchema) => {
|
||||||
|
try {
|
||||||
|
await updateRole({
|
||||||
|
orgId,
|
||||||
|
id: roleId,
|
||||||
|
...el,
|
||||||
|
permissions: formRolePermission2API(el.permissions)
|
||||||
|
});
|
||||||
|
createNotification({ type: "success", text: "Successfully updated role" });
|
||||||
|
} catch (err) {
|
||||||
|
console.log(err);
|
||||||
|
createNotification({ type: "error", text: "Failed to update role" });
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
const isCustomRole = !["admin", "member", "no-access"].includes(role?.slug ?? "");
|
||||||
|
|
||||||
|
return (
|
||||||
|
<form
|
||||||
|
onSubmit={handleSubmit(onSubmit)}
|
||||||
|
className="w-full rounded-lg border border-mineshaft-600 bg-mineshaft-900 p-4"
|
||||||
|
>
|
||||||
|
<div className="flex items-center justify-between border-b border-mineshaft-400 pb-4">
|
||||||
|
<h3 className="text-lg font-semibold text-mineshaft-100">Permissions</h3>
|
||||||
|
{isCustomRole && (
|
||||||
|
<div className="flex items-center">
|
||||||
|
<Button
|
||||||
|
colorSchema="primary"
|
||||||
|
type="submit"
|
||||||
|
isDisabled={isSubmitting || !isDirty}
|
||||||
|
isLoading={isSubmitting}
|
||||||
|
>
|
||||||
|
Save
|
||||||
|
</Button>
|
||||||
|
<Button
|
||||||
|
className="ml-4 text-mineshaft-300"
|
||||||
|
variant="link"
|
||||||
|
isDisabled={isSubmitting || !isDirty}
|
||||||
|
isLoading={isSubmitting}
|
||||||
|
onClick={() => reset()}
|
||||||
|
>
|
||||||
|
Cancel
|
||||||
|
</Button>
|
||||||
|
</div>
|
||||||
|
)}
|
||||||
|
</div>
|
||||||
|
<div className="py-4">
|
||||||
|
<TableContainer>
|
||||||
|
<Table>
|
||||||
|
<THead>
|
||||||
|
<Tr>
|
||||||
|
<Th className="w-5" />
|
||||||
|
<Th>Resource</Th>
|
||||||
|
<Th>Permission</Th>
|
||||||
|
</Tr>
|
||||||
|
</THead>
|
||||||
|
<TBody>
|
||||||
|
{SIMPLE_PERMISSION_OPTIONS.map((permission) => {
|
||||||
|
return (
|
||||||
|
<RolePermissionRow
|
||||||
|
title={permission.title}
|
||||||
|
formName={permission.formName}
|
||||||
|
control={control}
|
||||||
|
setValue={setValue}
|
||||||
|
key={`org-role-${roleId}-permission-${permission.formName}`}
|
||||||
|
isEditable={isCustomRole}
|
||||||
|
/>
|
||||||
|
);
|
||||||
|
})}
|
||||||
|
</TBody>
|
||||||
|
</Table>
|
||||||
|
</TableContainer>
|
||||||
|
</div>
|
||||||
|
</form>
|
||||||
|
);
|
||||||
|
};
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
export { RolePermissionsSection } from "./RolePermissionsSection";
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
export { RoleDetailsSection } from "./RoleDetailsSection";
|
||||||
|
export { RoleModal } from "./RoleModal";
|
||||||
|
export { RolePermissionsSection } from "./RolePermissionsSection";
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
export { RolePage } from "./RolePage";
|
||||||
-1
@@ -161,7 +161,6 @@ export const SecretOverviewTableRow = ({
|
|||||||
secretPath={secretPath}
|
secretPath={secretPath}
|
||||||
getSecretByKey={getSecretByKey}
|
getSecretByKey={getSecretByKey}
|
||||||
/>
|
/>
|
||||||
|
|
||||||
<TableContainer>
|
<TableContainer>
|
||||||
<table className="secret-table">
|
<table className="secret-table">
|
||||||
<thead>
|
<thead>
|
||||||
|
|||||||
Reference in New Issue
Block a user