feat(rust): the permission manager — the site owns the whole store (D160-D163, D188-D198)
PLAN_REDESIGNS section 1. - Every sync reads the store (perm.inventory), reconciles it against the site's record and its ledger, and pushes. A change made in the game is settled by the server's policy (D161): auto-adopt (default), adopt, or revoke. The first read of a server imports everything (D198). - Groups belong to one server unless an admin shares them (D189), in new id-keyed tables; the old ones are copied once at boot and left unread. Holders may be a Steam account nobody linked (D188). - An in-game change affects that server only (D190): a grant that reaches further gains an exception, a shared group is split. - Never judged: a permission the server does not register right now (an unloaded plugin is not a revocation), and a pair an event lease holds. - A new admin API (server view, grant/revoke with everywhere-or-here, groups by id, share/split, members, drift answers) and a screen on PermissionsManager's flow with a state on every toggle (D162, D163, U-1). - The announcement voice names a group by id; old name settings still read. Walked on both rigs against the walk core: import on an existing install, auto-adopt of a grant and a revoke, a fleet grant's exception, Kits unloaded without loss, a shared group split, adopt and revoke policies. Server 420/420, client 58/58, swagger, imports and route manifest current. Refs #21 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E14m6SuuY6i1vASFeGDBeY
This commit is contained in:
@@ -83,32 +83,41 @@ async function listPermissions(req, res) {
|
||||
const userId = Number(req.params.id)
|
||||
|
||||
try {
|
||||
const [groups, groupPermissions, members, grants, allLinks] = await Promise.all([
|
||||
const [groups, groupServers, groupPermissions, members, grants, allLinks] = await Promise.all([
|
||||
permissionsDb.listGroups(),
|
||||
permissionsDb.listGroupServers(),
|
||||
permissionsDb.listGroupPermissions(),
|
||||
permissionsDb.listGroupMembers(),
|
||||
permissionsDb.listGrants({ userId }),
|
||||
permissionsDb.listLinks(),
|
||||
])
|
||||
|
||||
const theirs = new Set(
|
||||
members.filter((row) => row.userId === userId).map((row) => row.groupName),
|
||||
)
|
||||
const theirs = new Set(members.filter((row) => row.userId === userId).map((row) => row.groupId))
|
||||
|
||||
const carried = new Map()
|
||||
for (const row of groupPermissions) {
|
||||
if (!carried.has(row.groupName)) carried.set(row.groupName, [])
|
||||
carried.get(row.groupName).push(row.permission)
|
||||
if (!carried.has(row.groupId)) carried.set(row.groupId, [])
|
||||
carried.get(row.groupId).push(row.permission)
|
||||
}
|
||||
|
||||
// A group is on one server unless it is shared (D189): `scope` says `*`
|
||||
// for every server, or lists the servers it is on.
|
||||
const on = new Map()
|
||||
for (const row of groupServers) {
|
||||
if (!row.included) continue
|
||||
if (!on.has(row.groupId)) on.set(row.groupId, [])
|
||||
on.get(row.groupId).push(row.serverId)
|
||||
}
|
||||
|
||||
res.json({
|
||||
groups: groups
|
||||
.filter((group) => theirs.has(group.name))
|
||||
.filter((group) => theirs.has(group.id))
|
||||
.map((group) => ({
|
||||
id: group.id,
|
||||
name: group.name,
|
||||
title: group.title,
|
||||
scope: group.scope,
|
||||
permissions: carried.get(group.name) || [],
|
||||
scope: group.allServers ? permissions.FLEET : (on.get(group.id) || []).join(','),
|
||||
permissions: carried.get(group.id) || [],
|
||||
})),
|
||||
grants: permissions.collapseGrants(grants).map((grant) => ({
|
||||
id: grant.id,
|
||||
|
||||
Reference in New Issue
Block a user