feat(rust): the permission manager — the site owns the whole store (D160-D163, D188-D198)
All checks were successful
PR Checks / client-build (pull_request) Successful in 21s
PR Checks / frozen-manifest (pull_request) Successful in 43s
PR Checks / server-tests (pull_request) Successful in 7m58s

PLAN_REDESIGNS section 1.

- Every sync reads the store (perm.inventory), reconciles it against the
  site's record and its ledger, and pushes. A change made in the game is
  settled by the server's policy (D161): auto-adopt (default), adopt, or
  revoke. The first read of a server imports everything (D198).
- Groups belong to one server unless an admin shares them (D189), in new
  id-keyed tables; the old ones are copied once at boot and left unread.
  Holders may be a Steam account nobody linked (D188).
- An in-game change affects that server only (D190): a grant that reaches
  further gains an exception, a shared group is split.
- Never judged: a permission the server does not register right now (an
  unloaded plugin is not a revocation), and a pair an event lease holds.
- A new admin API (server view, grant/revoke with everywhere-or-here,
  groups by id, share/split, members, drift answers) and a screen on
  PermissionsManager's flow with a state on every toggle (D162, D163, U-1).
- The announcement voice names a group by id; old name settings still read.

Walked on both rigs against the walk core: import on an existing install,
auto-adopt of a grant and a revoke, a fleet grant's exception, Kits
unloaded without loss, a shared group split, adopt and revoke policies.
Server 420/420, client 58/58, swagger, imports and route manifest current.

Refs #21

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E14m6SuuY6i1vASFeGDBeY
This commit is contained in:
2026-09-28 06:58:59 -05:00
parent 77c90db338
commit e0d13e73db
24 changed files with 5873 additions and 2589 deletions

View File

@@ -18,53 +18,89 @@ const model = require('./permissions.model')
const VOICE_KEY = 'announce.voice'
/** The chosen group's name, or '' for plain chat. */
/**
* The chosen group's id as a string, or '' for plain chat.
*
* Since groups became per server (D189) a name can belong to several groups, so
* the setting holds a group's id. A setting written before that holds a NAME,
* and is read as the first styled group of that name until somebody chooses again.
*/
async function chosen() {
return (await settingsDb.getSetting(VOICE_KEY)) || ''
}
/** The chosen group's style fields, or null. */
async function chosenFields() {
const value = await chosen()
if (!value) return { value, fields: null }
if (/^\d+$/.test(value)) return { value, fields: await db.getGroupChat(Number(value)) }
const groups = await db.listGroups()
for (const group of groups.filter((g) => g.name === model.normaliseName(value))) {
// eslint-disable-next-line no-await-in-loop
const fields = await db.getGroupChat(group.id)
if (fields) return { value: String(group.id), fields }
}
return { value, fields: null }
}
/**
* The format a line is said in right now, or null for plain chat — which is
* also the answer when the chosen group has since lost its style or gone.
*/
async function currentFormat() {
const group = await chosen()
if (!group) return null
const fields = await db.getGroupChat(group)
const { fields } = await chosenFields()
return fields ? chatStyle.voiceFormat(fields) : null
}
/** The setting, and every group that could be a voice, for the admin page. */
async function describe() {
const [voice, rows] = await Promise.all([chosen(), db.listGroupChat()])
const [{ value }, rows, groups, groupServers] = await Promise.all([
chosenFields(),
db.listGroupChat(),
db.listGroups(),
db.listGroupServers(),
])
const byId = new Map(groups.map((g) => [g.id, g]))
const options = []
for (const [group, fields] of model.chatByGroup(rows)) {
const format = chatStyle.voiceFormat(fields)
if (format) options.push({ group, title: fields.Title || group, format })
// Which servers each group is on, so two groups of one name can be told apart.
const where = (group) => {
if (group.allServers) return 'all servers'
const ids = groupServers.filter((r) => r.groupId === group.id && r.included).map((r) => r.serverId)
return ids.length ? ids.join(', ') : 'no server'
}
return { voice, options: options.sort((a, b) => a.group.localeCompare(b.group)) }
}
/**
* Choose the voice. A group is accepted only when it has a style a voice can be
* made from; '' goes back to plain chat. Resolves `{ ok }` or
* `{ ok: false, message }`.
*/
async function choose(group, userId = null) {
const name = model.normaliseName(group)
if (name) {
const fields = await db.getGroupChat(name)
if (!fields || !chatStyle.voiceFormat(fields)) {
return { ok: false, message: `The group "${name}" has no chat style, so it cannot be a voice. Give it one under Permissions first.` }
for (const [groupId, fields] of model.chatByGroup(rows)) {
const format = chatStyle.voiceFormat(fields)
const group = byId.get(groupId)
if (format && group) {
options.push({ group: String(groupId), name: group.name, where: where(group), title: fields.Title || group.name, format })
}
}
await settingsDb.setSetting(VOICE_KEY, name, userId)
return { ok: true, voice: name }
return { voice: value, options: options.sort((a, b) => a.name.localeCompare(b.name) || a.group.localeCompare(b.group)) }
}
/**
* Choose the voice by group id. A group is accepted only when it has a style a
* voice can be made from; '' goes back to plain chat. Resolves `{ ok }` or
* `{ ok: false, message }`.
*/
async function choose(group, userId = null) {
const value = String(group || '').trim()
if (value) {
const fields = /^\d+$/.test(value) ? await db.getGroupChat(Number(value)) : null
if (!fields || !chatStyle.voiceFormat(fields)) {
return { ok: false, message: 'That group has no chat style, so it cannot be a voice. Give it one under Permissions first.' }
}
}
await settingsDb.setSetting(VOICE_KEY, value, userId)
return { ok: true, voice: value }
}
module.exports = { VOICE_KEY, chosen, currentFormat, describe, choose }