feat(rust): the permission manager — the site owns the whole store (D160-D163, D188-D198)
PLAN_REDESIGNS section 1. - Every sync reads the store (perm.inventory), reconciles it against the site's record and its ledger, and pushes. A change made in the game is settled by the server's policy (D161): auto-adopt (default), adopt, or revoke. The first read of a server imports everything (D198). - Groups belong to one server unless an admin shares them (D189), in new id-keyed tables; the old ones are copied once at boot and left unread. Holders may be a Steam account nobody linked (D188). - An in-game change affects that server only (D190): a grant that reaches further gains an exception, a shared group is split. - Never judged: a permission the server does not register right now (an unloaded plugin is not a revocation), and a pair an event lease holds. - A new admin API (server view, grant/revoke with everywhere-or-here, groups by id, share/split, members, drift answers) and a screen on PermissionsManager's flow with a state on every toggle (D162, D163, U-1). - The announcement voice names a group by id; old name settings still read. Walked on both rigs against the walk core: import on an existing install, auto-adopt of a grant and a revoke, a fleet grant's exception, Kits unloaded without loss, a shared group split, adopt and revoke policies. Server 420/420, client 58/58, swagger, imports and route manifest current. Refs #21 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E14m6SuuY6i1vASFeGDBeY
This commit is contained in:
@@ -45,11 +45,15 @@ const SERVERS = [
|
||||
/** One person: in a fleet group, holding one server-scoped grant. */
|
||||
function fixture({ pushed = [] } = {}) {
|
||||
return {
|
||||
listGroupsForUser: [{ name: 'vip', title: 'VIP', rank: 10, scope: '*', addedAt: '2026-09-01T00:00:00Z' }],
|
||||
// A group on every server (D189: `allServers`, where the old model said `scope: '*'`).
|
||||
listGroupsForUser: [{ id: 1, name: 'vip', title: 'VIP', rank: 10, allServers: true, addedAt: '2026-09-01T00:00:00Z' }],
|
||||
listGroupServers: [],
|
||||
listGroupPermissions: [
|
||||
{ groupName: 'vip', permission: 'Kits.VIP' },
|
||||
{ groupName: 'builder', permission: 'buildtools.use' },
|
||||
{ groupId: 1, permission: 'Kits.VIP' },
|
||||
{ groupId: 2, permission: 'buildtools.use' },
|
||||
],
|
||||
listSteamGrants: [],
|
||||
listExceptions: [],
|
||||
listGrants: [
|
||||
{ id: 7, userId: 4, permission: 'zonemanager.admin', scope: 'creative', source: 'admin', note: null, grantedAt: '2026-09-02T00:00:00Z', steamId: '7656119', playerName: 'Wanderer' },
|
||||
],
|
||||
@@ -110,8 +114,11 @@ test('a grant and a membership are different rows about the same person', async
|
||||
// direct grant named `vip` would otherwise be one entry in the map, and the
|
||||
// wrong one would light up.
|
||||
const { model, restore } = modelWith({
|
||||
listGroupsForUser: [{ name: 'vip', title: 'VIP', rank: 0, scope: '*', addedAt: null }],
|
||||
listGroupsForUser: [{ id: 1, name: 'vip', title: 'VIP', rank: 0, allServers: true, addedAt: null }],
|
||||
listGroupServers: [],
|
||||
listGroupPermissions: [],
|
||||
listSteamGrants: [],
|
||||
listExceptions: [],
|
||||
listGrants: [{ id: 1, userId: 4, permission: 'vip', scope: '*', source: 'admin', note: null, grantedAt: null, steamId: '7656119' }],
|
||||
listPushedForSteamIds: [{ serverId: 'main', kind: 'grant', subject: '7656119', object: 'vip' }],
|
||||
})
|
||||
|
||||
Reference in New Issue
Block a user