feat(rust): the permission manager — the site owns the whole store (D160-D163, D188-D198)
PLAN_REDESIGNS section 1. - Every sync reads the store (perm.inventory), reconciles it against the site's record and its ledger, and pushes. A change made in the game is settled by the server's policy (D161): auto-adopt (default), adopt, or revoke. The first read of a server imports everything (D198). - Groups belong to one server unless an admin shares them (D189), in new id-keyed tables; the old ones are copied once at boot and left unread. Holders may be a Steam account nobody linked (D188). - An in-game change affects that server only (D190): a grant that reaches further gains an exception, a shared group is split. - Never judged: a permission the server does not register right now (an unloaded plugin is not a revocation), and a pair an event lease holds. - A new admin API (server view, grant/revoke with everywhere-or-here, groups by id, share/split, members, drift answers) and a screen on PermissionsManager's flow with a state on every toggle (D162, D163, U-1). - The announcement voice names a group by id; old name settings still read. Walked on both rigs against the walk core: import on an existing install, auto-adopt of a grant and a revoke, a fleet grant's exception, Kits unloaded without loss, a shared group split, adopt and revoke policies. Server 420/420, client 58/58, swagger, imports and route manifest current. Refs #21 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E14m6SuuY6i1vASFeGDBeY
This commit is contained in:
@@ -150,37 +150,48 @@ export const admin = {
|
||||
// A write is followed by a re-read rather than a local edit of the model: what
|
||||
// the screen is showing is partly the game's answer, and the honest way to learn
|
||||
// the new one is to ask.
|
||||
const P = '/admin/rust/permissions'
|
||||
const enc = encodeURIComponent
|
||||
|
||||
export const adminPermissions = {
|
||||
overview: () => req('/admin/rust/permissions'),
|
||||
catalogue: () => req('/admin/rust/permissions/catalogue'),
|
||||
overview: () => req(P),
|
||||
catalogue: () => req(`${P}/catalogue`),
|
||||
|
||||
saveGroup: (name, body) =>
|
||||
req(`/admin/rust/permissions/groups/${encodeURIComponent(name)}`, { method: 'PUT', body }),
|
||||
deleteGroup: (name) =>
|
||||
req(`/admin/rust/permissions/groups/${encodeURIComponent(name)}`, { method: 'DELETE' }),
|
||||
// One server, as PermissionsManager shows one (D162).
|
||||
server: (serverId) => req(`${P}/servers/${enc(serverId)}`),
|
||||
players: (serverId, q) => req(`${P}/servers/${enc(serverId)}/players?q=${enc(q || '')}`),
|
||||
setPolicy: (serverId, policy) => req(`${P}/servers/${enc(serverId)}/policy`, { method: 'PUT', body: { policy } }),
|
||||
|
||||
addMember: (name, username) =>
|
||||
req(`/admin/rust/permissions/groups/${encodeURIComponent(name)}/members`, {
|
||||
method: 'POST',
|
||||
body: { username },
|
||||
}),
|
||||
removeMember: (name, userId) =>
|
||||
req(
|
||||
`/admin/rust/permissions/groups/${encodeURIComponent(name)}/members/${encodeURIComponent(userId)}`,
|
||||
{ method: 'DELETE' },
|
||||
),
|
||||
// A subject is `{ steamId }` or `{ userId }`; `everywhere` reaches every server.
|
||||
grant: (serverId, subject, permissions, everywhere = false) =>
|
||||
req(`${P}/servers/${enc(serverId)}/grant`, { method: 'POST', body: { ...subject, permissions, everywhere } }),
|
||||
revoke: (serverId, subject, permissions, everywhere = false) =>
|
||||
req(`${P}/servers/${enc(serverId)}/revoke`, { method: 'POST', body: { ...subject, permissions, everywhere } }),
|
||||
removeException: (id) => req(`${P}/exceptions/${enc(id)}`, { method: 'DELETE' }),
|
||||
|
||||
grant: (body) => req('/admin/rust/permissions/grants', { method: 'POST', body }),
|
||||
revoke: (id) =>
|
||||
req(`/admin/rust/permissions/grants/${encodeURIComponent(id)}`, { method: 'DELETE' }),
|
||||
// Groups by id (D189). `here` is `{ onlyHere: true, serverId }` to split a
|
||||
// shared group's copy off first (D190), or null to change it everywhere.
|
||||
createGroup: (serverId, body) => req(`${P}/servers/${enc(serverId)}/groups`, { method: 'POST', body }),
|
||||
updateGroup: (id, body, here = null) => req(`${P}/groups/${enc(id)}`, { method: 'PATCH', body: { ...body, ...(here || {}) } }),
|
||||
deleteGroup: (id) => req(`${P}/groups/${enc(id)}`, { method: 'DELETE' }),
|
||||
setGroupPermissions: (id, permissions, here = null) =>
|
||||
req(`${P}/groups/${enc(id)}/permissions`, { method: 'PUT', body: { permissions, ...(here || {}) } }),
|
||||
setGroupServers: (id, body) => req(`${P}/groups/${enc(id)}/servers`, { method: 'PUT', body }),
|
||||
splitGroup: (id, serverId) => req(`${P}/groups/${enc(id)}/split`, { method: 'POST', body: { serverId } }),
|
||||
addMember: (id, subject, here = null) =>
|
||||
req(`${P}/groups/${enc(id)}/members`, { method: 'POST', body: { ...subject, ...(here || {}) } }),
|
||||
removeMember: (id, subject, here = null) =>
|
||||
req(`${P}/groups/${enc(id)}/members/remove`, { method: 'POST', body: { ...subject, ...(here || {}) } }),
|
||||
clearMembers: (id, here = null) => req(`${P}/groups/${enc(id)}/members/clear`, { method: 'POST', body: { ...(here || {}) } }),
|
||||
|
||||
adoptDrift: (id) =>
|
||||
req(`/admin/rust/permissions/drift/${encodeURIComponent(id)}/adopt`, { method: 'POST' }),
|
||||
revokeDrift: (id) =>
|
||||
req(`/admin/rust/permissions/drift/${encodeURIComponent(id)}/revoke`, { method: 'POST' }),
|
||||
// What waits for a person (D161).
|
||||
adoptDrift: (id) => req(`${P}/drift/${enc(id)}/adopt`, { method: 'POST' }),
|
||||
revokeDrift: (id) => req(`${P}/drift/${enc(id)}/revoke`, { method: 'POST' }),
|
||||
acceptDrift: (id) => req(`${P}/drift/${enc(id)}/accept`, { method: 'POST' }),
|
||||
restoreDrift: (id) => req(`${P}/drift/${enc(id)}/restore`, { method: 'POST' }),
|
||||
dismissDrift: (id) => req(`${P}/drift/${enc(id)}/dismiss`, { method: 'POST' }),
|
||||
|
||||
sync: (serverId = null) =>
|
||||
req('/admin/rust/permissions/sync', { method: 'POST', body: serverId ? { serverId } : {} }),
|
||||
sync: (serverId = null) => req(`${P}/sync`, { method: 'POST', body: serverId ? { serverId } : {} }),
|
||||
}
|
||||
|
||||
// ── admin · visibility ────────────────────────────────────────────────────
|
||||
|
||||
@@ -196,13 +196,15 @@ export function VoiceCard() {
|
||||
Say them as
|
||||
<select value={data.voice} onChange={(e) => choose(e.target.value)} disabled={busy} style={inputStyle}>
|
||||
<option value="">Plain chat</option>
|
||||
{data.options.map((o) => <option key={o.group} value={o.group}>{o.group} — {o.title}</option>)}
|
||||
{data.options.map((o) => (
|
||||
<option key={o.group} value={o.group}>{o.name} — {o.title} ({o.where})</option>
|
||||
))}
|
||||
</select>
|
||||
</label>
|
||||
{data.voice && !current && (
|
||||
<p style={{ color: '#d08a2a', fontSize: '0.78rem', margin: '8px 0 0' }}>
|
||||
The group “{data.voice}” no longer has a chat style, so lines are said in plain chat until it has one again or
|
||||
another voice is chosen.
|
||||
The chosen group no longer has a chat style, so lines are said in plain chat until it has one again or another
|
||||
voice is chosen.
|
||||
</p>
|
||||
)}
|
||||
{current && <p className="dim" style={{ fontSize: '0.74rem', margin: '8px 0 0' }}>The line: <code>{current.format}</code></p>}
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user