feat(rust): the permission manager — the site owns the whole store (D160-D163, D188-D198)
PLAN_REDESIGNS section 1. - Every sync reads the store (perm.inventory), reconciles it against the site's record and its ledger, and pushes. A change made in the game is settled by the server's policy (D161): auto-adopt (default), adopt, or revoke. The first read of a server imports everything (D198). - Groups belong to one server unless an admin shares them (D189), in new id-keyed tables; the old ones are copied once at boot and left unread. Holders may be a Steam account nobody linked (D188). - An in-game change affects that server only (D190): a grant that reaches further gains an exception, a shared group is split. - Never judged: a permission the server does not register right now (an unloaded plugin is not a revocation), and a pair an event lease holds. - A new admin API (server view, grant/revoke with everywhere-or-here, groups by id, share/split, members, drift answers) and a screen on PermissionsManager's flow with a state on every toggle (D162, D163, U-1). - The announcement voice names a group by id; old name settings still read. Walked on both rigs against the walk core: import on an existing install, auto-adopt of a grant and a revoke, a fleet grant's exception, Kits unloaded without loss, a shared group split, adopt and revoke policies. Server 420/420, client 58/58, swagger, imports and route manifest current. Refs #21 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E14m6SuuY6i1vASFeGDBeY
This commit is contained in:
@@ -46,23 +46,29 @@ function withCore(overrides = {}) {
|
||||
/** One authored set: a fleet group, a server-scoped group, and two grants. */
|
||||
function authored() {
|
||||
return {
|
||||
// A group on every server, and one on `creative` alone (D189).
|
||||
groups: [
|
||||
{ name: 'vip', title: 'VIP', rank: 10, scope: '*' },
|
||||
{ name: 'builder', title: 'Builder', rank: 0, scope: 'creative' },
|
||||
{ id: 1, name: 'vip', title: 'VIP', rank: 10, parent: '', allServers: true },
|
||||
{ id: 2, name: 'builder', title: 'Builder', rank: 0, parent: '', allServers: false },
|
||||
],
|
||||
groupServers: [{ groupId: 2, serverId: 'creative', included: true }],
|
||||
groupPermissions: [
|
||||
{ groupName: 'vip', permission: 'kits.vip' },
|
||||
{ groupName: 'builder', permission: 'buildtools.use' },
|
||||
{ groupId: 1, permission: 'kits.vip' },
|
||||
{ groupId: 2, permission: 'buildtools.use' },
|
||||
],
|
||||
members: [
|
||||
{ groupName: 'vip', userId: 1 },
|
||||
{ groupName: 'builder', userId: 2 },
|
||||
{ groupId: 1, userId: 1 },
|
||||
{ groupId: 2, userId: 2 },
|
||||
],
|
||||
steamMembers: [],
|
||||
grants: [
|
||||
{ id: 1, userId: 1, permission: 'kits.gold', scope: '*', steamId: '7656001' },
|
||||
{ id: 2, userId: 3, permission: 'kits.gold', scope: '*', steamId: null },
|
||||
{ id: 3, userId: 2, permission: 'zonemanager.admin', scope: 'creative', steamId: '7656002' },
|
||||
],
|
||||
steamGrants: [],
|
||||
exceptions: [],
|
||||
groupChat: [],
|
||||
// One person with TWO Steam accounts, one with one, one with none.
|
||||
steamIdsByUser: new Map([
|
||||
[1, ['7656001', '7656099']],
|
||||
@@ -83,17 +89,18 @@ test('a grant reaches every Steam account its holder has linked (D28)', () => {
|
||||
for (const row of payload.grants) assert.deepEqual(row.permissions, ['kits.gold'])
|
||||
})
|
||||
|
||||
test('a holder who has linked nothing contributes to the namespace but reaches nobody', () => {
|
||||
test('a holder who has linked nothing reaches nobody, and is not an error', () => {
|
||||
withCore()
|
||||
const model = require('../model/permissions/permissions.model')
|
||||
|
||||
const { payload, rows } = model.buildDesired('main', authored())
|
||||
|
||||
// User 3 holds `kits.gold` and has no account. Nothing is pushed for them…
|
||||
// User 3 holds `kits.gold` and has no account. Nothing is pushed for them, and
|
||||
// the grant is still the site's: it reaches them the day they link.
|
||||
assert.ok(!rows.some((row) => row.kind === 'grant' && row.subject === null))
|
||||
// …and the permission is still MANAGED, which is what makes a hand grant of it
|
||||
// to somebody else show up as drift rather than as nothing at all.
|
||||
assert.ok(payload.managed.includes('kits.gold'))
|
||||
assert.deepEqual(payload.grants.map((g) => g.steamId).sort(), ['7656001', '7656099'])
|
||||
// Protocol 13 sends no `managed` namespace: the inventory reads the whole store.
|
||||
assert.equal(payload.managed, undefined)
|
||||
})
|
||||
|
||||
test('scope decides what a server is sent at all (D29)', () => {
|
||||
@@ -107,8 +114,9 @@ test('scope decides what a server is sent at all (D29)', () => {
|
||||
assert.deepEqual(creative.payload.groups.map((g) => g.name).sort(), ['builder', 'vip'])
|
||||
|
||||
// The server-scoped grant is on `creative` and nowhere else.
|
||||
assert.ok(!main.payload.managed.includes('zonemanager.admin'))
|
||||
assert.ok(creative.payload.managed.includes('zonemanager.admin'))
|
||||
const holds = (desired, permission) => desired.payload.grants.some((g) => g.permissions.includes(permission))
|
||||
assert.ok(!holds(main, 'zonemanager.admin'))
|
||||
assert.ok(holds(creative, 'zonemanager.admin'))
|
||||
})
|
||||
|
||||
test('a group travels as a group: its members and its permissions are separate facts (D30)', () => {
|
||||
@@ -349,7 +357,7 @@ test('an event grant is unioned with the admin grants, reaches only its server,
|
||||
|
||||
assert.deepEqual(grantsFor('7656001'), ['kits.event', 'kits.gold'])
|
||||
assert.deepEqual(grantsFor('7656099'), ['kits.event', 'kits.gold'])
|
||||
assert.ok(!payload.managed.includes('kits.creative'))
|
||||
assert.ok(!payload.grants.some((g) => g.permissions.includes('kits.creative')))
|
||||
assert.strictEqual(rows.filter((r) => r.kind === 'grant' && r.object === 'kits.gold').length, 2)
|
||||
|
||||
assert.deepEqual(payload.credits, [
|
||||
|
||||
Reference in New Issue
Block a user