Remove role and roleId from group project membership

This commit is contained in:
Tuan Dang
2024-04-03 20:30:14 -07:00
parent 457edef5fe
commit e1d9f779b2
7 changed files with 6 additions and 36 deletions
@@ -37,9 +37,6 @@ export async function up(knex: Knex): Promise<void> {
if (!(await knex.schema.hasTable(TableName.GroupProjectMembership))) { if (!(await knex.schema.hasTable(TableName.GroupProjectMembership))) {
await knex.schema.createTable(TableName.GroupProjectMembership, (t) => { await knex.schema.createTable(TableName.GroupProjectMembership, (t) => {
t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid()); t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid());
t.string("role").notNullable();
t.uuid("roleId");
t.foreign("roleId").references("id").inTable(TableName.ProjectRoles);
t.string("projectId").notNullable(); t.string("projectId").notNullable();
t.foreign("projectId").references("id").inTable(TableName.Project).onDelete("CASCADE"); t.foreign("projectId").references("id").inTable(TableName.Project).onDelete("CASCADE");
t.uuid("groupId").notNullable(); t.uuid("groupId").notNullable();
@@ -9,8 +9,6 @@ import { TImmutableDBKeys } from "./models";
export const GroupProjectMembershipsSchema = z.object({ export const GroupProjectMembershipsSchema = z.object({
id: z.string().uuid(), id: z.string().uuid(),
role: z.string(),
roleId: z.string().uuid().nullable().optional(),
projectId: z.string(), projectId: z.string(),
groupId: z.string().uuid(), groupId: z.string().uuid(),
createdAt: z.date(), createdAt: z.date(),
@@ -12,7 +12,7 @@ export const getDefaultOnPremFeatures = () => {
secretVersioning: true, secretVersioning: true,
pitRecovery: false, pitRecovery: false,
ipAllowlisting: true, ipAllowlisting: true,
rbac: false, rbac: true,
customRateLimits: false, customRateLimits: false,
customAlerts: false, customAlerts: false,
auditLogs: false, auditLogs: false,
@@ -19,7 +19,7 @@ export const getDefaultOnPremFeatures = (): TFeatureSet => ({
secretVersioning: true, secretVersioning: true,
pitRecovery: false, pitRecovery: false,
ipAllowlisting: false, ipAllowlisting: false,
rbac: false, rbac: true,
customRateLimits: false, customRateLimits: false,
customAlerts: false, customAlerts: false,
auditLogs: false, auditLogs: false,
@@ -35,7 +35,7 @@ export type TFeatureSet = {
secretVersioning: true; secretVersioning: true;
pitRecovery: false; pitRecovery: false;
ipAllowlisting: false; ipAllowlisting: false;
rbac: false; rbac: true;
customRateLimits: false; customRateLimits: false;
customAlerts: false; customAlerts: false;
auditLogs: false; auditLogs: false;
@@ -73,7 +73,6 @@ export const permissionDALFactory = (db: TDbClient) => {
.select( .select(
db.ref("id").withSchema(TableName.GroupProjectMembership).as("membershipId"), db.ref("id").withSchema(TableName.GroupProjectMembership).as("membershipId"),
// TODO(roll-forward-migration): remove this field when we drop this in next migration after a week // TODO(roll-forward-migration): remove this field when we drop this in next migration after a week
db.ref("role").withSchema(TableName.GroupProjectMembership).as("oldRoleField"),
db.ref("createdAt").withSchema(TableName.GroupProjectMembership).as("membershipCreatedAt"), db.ref("createdAt").withSchema(TableName.GroupProjectMembership).as("membershipCreatedAt"),
db.ref("updatedAt").withSchema(TableName.GroupProjectMembership).as("membershipUpdatedAt"), db.ref("updatedAt").withSchema(TableName.GroupProjectMembership).as("membershipUpdatedAt"),
db.ref("projectId").withSchema(TableName.GroupProjectMembership), db.ref("projectId").withSchema(TableName.GroupProjectMembership),
@@ -102,7 +101,6 @@ export const permissionDALFactory = (db: TDbClient) => {
.select( .select(
db.ref("id").withSchema(TableName.ProjectMembership).as("membershipId"), db.ref("id").withSchema(TableName.ProjectMembership).as("membershipId"),
// TODO(roll-forward-migration): remove this field when we drop this in next migration after a week // TODO(roll-forward-migration): remove this field when we drop this in next migration after a week
db.ref("role").withSchema(TableName.ProjectMembership).as("oldRoleField"),
db.ref("createdAt").withSchema(TableName.ProjectMembership).as("membershipCreatedAt"), db.ref("createdAt").withSchema(TableName.ProjectMembership).as("membershipCreatedAt"),
db.ref("updatedAt").withSchema(TableName.ProjectMembership).as("membershipUpdatedAt"), db.ref("updatedAt").withSchema(TableName.ProjectMembership).as("membershipUpdatedAt"),
db.ref("projectId").withSchema(TableName.ProjectMembership), db.ref("projectId").withSchema(TableName.ProjectMembership),
@@ -115,18 +113,11 @@ export const permissionDALFactory = (db: TDbClient) => {
const permission = sqlNestRelationships({ const permission = sqlNestRelationships({
data: docs.concat(groupDocs), data: docs.concat(groupDocs),
key: "projectId", key: "projectId",
parentMapper: ({ parentMapper: ({ orgId, orgAuthEnforced, membershipId, membershipCreatedAt, membershipUpdatedAt, role }) => ({
orgId,
orgAuthEnforced,
membershipId,
membershipCreatedAt,
membershipUpdatedAt,
oldRoleField
}) => ({
orgId, orgId,
orgAuthEnforced, orgAuthEnforced,
userId, userId,
role: oldRoleField, role,
id: membershipId, id: membershipId,
projectId, projectId,
createdAt: membershipCreatedAt, createdAt: membershipCreatedAt,
@@ -102,9 +102,7 @@ export const groupProjectServiceFactory = ({
const groupProjectMembership = await groupProjectDAL.create( const groupProjectMembership = await groupProjectDAL.create(
{ {
groupId: group.id, groupId: group.id,
projectId: project.id, projectId: project.id
role: isCustomRole ? ProjectMembershipRole.Custom : role,
roleId: customRole?.id
}, },
tx tx
); );
@@ -212,14 +210,6 @@ export const groupProjectServiceFactory = ({
const projectGroup = await groupProjectDAL.findOne({ groupId: group.id, projectId: project.id }); const projectGroup = await groupProjectDAL.findOne({ groupId: group.id, projectId: project.id });
if (!projectGroup) throw new BadRequestError({ message: `Failed to find group with slug ${groupSlug}` }); if (!projectGroup) throw new BadRequestError({ message: `Failed to find group with slug ${groupSlug}` });
const { permission: groupRolePermission } = await permissionService.getProjectPermissionByRole(
projectGroup.role,
project.id
);
const hasRequiredPriviledges = isAtLeastAsPrivileged(permission, groupRolePermission);
if (!hasRequiredPriviledges) throw new ForbiddenRequestError({ message: "Failed to delete more privileged group" });
// validate custom roles input // validate custom roles input
const customInputRoles = roles.filter( const customInputRoles = roles.filter(
({ role }) => !Object.values(ProjectMembershipRole).includes(role as ProjectMembershipRole) ({ role }) => !Object.values(ProjectMembershipRole).includes(role as ProjectMembershipRole)
@@ -295,12 +285,6 @@ export const groupProjectServiceFactory = ({
actorOrgId actorOrgId
); );
ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionActions.Delete, ProjectPermissionSub.Groups); ForbiddenError.from(permission).throwUnlessCan(ProjectPermissionActions.Delete, ProjectPermissionSub.Groups);
const { permission: groupRolePermission } = await permissionService.getProjectPermissionByRole(
groupProjectMembership.role,
project.id
);
const hasRequiredPriviledges = isAtLeastAsPrivileged(permission, groupRolePermission);
if (!hasRequiredPriviledges) throw new ForbiddenRequestError({ message: "Failed to delete more privileged group" });
const groupMembers = await userGroupMembershipDAL.findGroupMembersNotInProject(group.id, project.id); const groupMembers = await userGroupMembershipDAL.findGroupMembersNotInProject(group.id, project.id);