feat(rust): the permission manager — the site owns the whole store (D160-D163, D188-D198) #25

Merged
whitlocktech merged 1 commits from feat/perm-manager into edge 2026-09-28 16:39:13 +00:00
Member

What & why

Step 3's first redesign, PLAN_REDESIGNS.md §1. The site now owns every permission and group on every server: what was there before it, what an admin makes, and what is changed in the game (D160). Companion PRs: Rust-Plugins (perm.inventory), Rust-Link (the route), and docs (PROTOCOL §19.9 + PLAN_REDESIGNS §1.9). Tracking: #21.

The sync is now read → reconcile → push (permSync.js, reconcile.js, permissions.apply.js):

  • It reads the whole store in pages. It then compares what's in the game, what the site pushed, and what the site wants, and settles each in-game change by the server's policy (D161): auto-adopt (default), adopt (wait for a person), or revoke.
  • The first read of a server imports everything it finds (D198). Removals at import are pushed back, not deleted.
  • An in-game change affects that server only (D190): a grant that reaches further gains an exception, and a shared group is split.
  • Never judged: permissions the server doesn't register right now (an unloaded plugin is not a revocation), and pairs an event lease holds.
  • The reconcile step runs under one fleet-wide lock.

Data (schema.sql, below the existing tables, ALTERs only on shipped ones):

  • Groups are id-keyed, per server unless shared (D189): rust_permgroups plus _servers, _permissions, _members, _steam_members and _chat.
  • New tables: Steam-account holders (rust_perm_steam_grants, D188) and rust_perm_exceptions.
  • New columns: the per-server policy, imported_at, the catalogue's owner, and the drift row's direction.
  • The old group tables are copied once at boot and left unread. The schema applies and replays cleanly on MariaDB 11.8, and purge removes it all.

API + screen:

  • New admin routes: a server view, grant/revoke with everywhere-or-here, groups by id, share/split, members, and drift answers (adopt/undo/accept/put back/dismiss). The swagger fragment and route manifest are regenerated.
  • Permissions.jsx is rebuilt on PermissionsManager's flow (D162). A server, then players ⇄ groups, then plugins by registering owner, then Granted/Revoked, Grant all and Revoke all.
  • Every toggle carries its own state (U-1). Subjects are named by account and in-game name (D163).
  • The announcement voice now stores a group id; old name settings still read.

How it was tested

  • Server 420/420 (15 new reconcile tests; the permission, style and player tests moved to the new shapes). Client 58/58. check:swagger, check:imports, check:externals and the frozen manifest (core f0e7d2a) are all current.
  • Walked on both rigs against the walk core (rustp16, backed up first):
    • the import on an existing install;
    • auto-adopt of an oxide.grant and an oxide.revoke within one tick;
    • a fleet grant revoked in game → an exception, and still landed on Carbon;
    • oxide.unload Kits → nothing deleted;
    • c.grant group walkvoice … on Carbon → split, Oxide untouched;
    • the adopt policy (held, then answered) and the revoke policy (undone).
  • Not yet walked: a parent group; share/unshare from the screen; Grant all / Revoke all; the screen in a browser (every endpoint behind it was called); the large-store timing. See PLAN_REDESIGNS §1.9.

Checklist

  • I have read CONTRIBUTING.md.
  • The change builds and existing tests/checks pass locally.
  • I have added or updated tests/docs where it makes sense.
  • My commits are reasonably scoped with clear messages.

AI-assisted contributions (required)

  • No AI tools were used to produce this contribution.
  • AI tools were used. Tool(s): Claude Code (Claude Opus 5.5). I have reviewed and understand
    every change, and take responsibility for it. AI-authored commits are
    marked with a Co-Authored-By / Assisted-By trailer.

License

  • I agree that my contribution is licensed under this project's license
    (GNU GPL v3.0 or later), and I have the right to contribute it.

🤖 Generated with Claude Code

https://claude.ai/code/session_01E14m6SuuY6i1vASFeGDBeY

## What & why Step 3's first redesign, `PLAN_REDESIGNS.md` §1. The site now owns **every** permission and group on every server: what was there before it, what an admin makes, and what is changed in the game (D160). Companion PRs: Rust-Plugins (`perm.inventory`), Rust-Link (the route), and docs (PROTOCOL §19.9 + PLAN_REDESIGNS §1.9). Tracking: #21. **The sync is now read → reconcile → push** (`permSync.js`, `reconcile.js`, `permissions.apply.js`): - It reads the whole store in pages. It then compares what's in the game, what the site pushed, and what the site wants, and settles each in-game change by the server's **policy** (D161): `auto-adopt` (default), `adopt` (wait for a person), or `revoke`. - The first read of a server **imports everything** it finds (D198). Removals at import are pushed back, not deleted. - An in-game change affects **that server only** (D190): a grant that reaches further gains an **exception**, and a shared group is **split**. - **Never judged:** permissions the server doesn't register right now (an unloaded plugin is not a revocation), and pairs an event lease holds. - The reconcile step runs under one fleet-wide lock. **Data** (`schema.sql`, below the existing tables, ALTERs only on shipped ones): - Groups are id-keyed, **per server unless shared** (D189): `rust_permgroups` plus `_servers`, `_permissions`, `_members`, `_steam_members` and `_chat`. - New tables: Steam-account holders (`rust_perm_steam_grants`, D188) and `rust_perm_exceptions`. - New columns: the per-server policy, `imported_at`, the catalogue's `owner`, and the drift row's `direction`. - The old group tables are copied once at boot and left unread. The schema applies and replays cleanly on MariaDB 11.8, and purge removes it all. **API + screen:** - New admin routes: a server view, grant/revoke with everywhere-or-here, groups by id, share/split, members, and drift answers (adopt/undo/accept/put back/dismiss). The swagger fragment and route manifest are regenerated. - `Permissions.jsx` is rebuilt on PermissionsManager's flow (D162). A server, then players ⇄ groups, then plugins **by registering owner**, then Granted/Revoked, Grant all and Revoke all. - Every toggle carries its own state (U-1). Subjects are named by account and in-game name (D163). - The announcement voice now stores a group id; old name settings still read. ## How it was tested - Server **420/420** (15 new reconcile tests; the permission, style and player tests moved to the new shapes). Client **58/58**. `check:swagger`, `check:imports`, `check:externals` and the frozen manifest (core `f0e7d2a`) are all current. - **Walked** on both rigs against the walk core (`rustp16`, backed up first): - the import on an existing install; - auto-adopt of an `oxide.grant` and an `oxide.revoke` within one tick; - a fleet grant revoked in game → an exception, and still landed on Carbon; - `oxide.unload Kits` → nothing deleted; - `c.grant group walkvoice …` on Carbon → split, Oxide untouched; - the `adopt` policy (held, then answered) and the `revoke` policy (undone). - **Not yet walked:** a parent group; share/unshare from the screen; Grant all / Revoke all; the screen in a browser (every endpoint behind it was called); the large-store timing. See PLAN_REDESIGNS §1.9. ## Checklist - [x] I have read [CONTRIBUTING.md](CONTRIBUTING.md). - [x] The change builds and existing tests/checks pass locally. - [x] I have added or updated tests/docs where it makes sense. - [x] My commits are reasonably scoped with clear messages. ## AI-assisted contributions (required) - [ ] No AI tools were used to produce this contribution. - [x] AI tools were used. Tool(s): `Claude Code (Claude Opus 5.5)`. I have reviewed and understand every change, and take responsibility for it. AI-authored commits are marked with a `Co-Authored-By` / `Assisted-By` trailer. ## License - [x] I agree that my contribution is licensed under this project's license (**GNU GPL v3.0 or later**), and I have the right to contribute it. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01E14m6SuuY6i1vASFeGDBeY
wtclaude added 1 commit 2026-09-28 16:26:53 +00:00
feat(rust): the permission manager — the site owns the whole store (D160-D163, D188-D198)
All checks were successful
PR Checks / client-build (pull_request) Successful in 21s
PR Checks / frozen-manifest (pull_request) Successful in 43s
PR Checks / server-tests (pull_request) Successful in 7m58s
e0d13e73db
PLAN_REDESIGNS section 1.

- Every sync reads the store (perm.inventory), reconciles it against the
  site's record and its ledger, and pushes. A change made in the game is
  settled by the server's policy (D161): auto-adopt (default), adopt, or
  revoke. The first read of a server imports everything (D198).
- Groups belong to one server unless an admin shares them (D189), in new
  id-keyed tables; the old ones are copied once at boot and left unread.
  Holders may be a Steam account nobody linked (D188).
- An in-game change affects that server only (D190): a grant that reaches
  further gains an exception, a shared group is split.
- Never judged: a permission the server does not register right now (an
  unloaded plugin is not a revocation), and a pair an event lease holds.
- A new admin API (server view, grant/revoke with everywhere-or-here,
  groups by id, share/split, members, drift answers) and a screen on
  PermissionsManager's flow with a state on every toggle (D162, D163, U-1).
- The announcement voice names a group by id; old name settings still read.

Walked on both rigs against the walk core: import on an existing install,
auto-adopt of a grant and a revoke, a fleet grant's exception, Kits
unloaded without loss, a shared group split, adopt and revoke policies.
Server 420/420, client 58/58, swagger, imports and route manifest current.

Refs #21

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E14m6SuuY6i1vASFeGDBeY
whitlocktech merged commit afb16112b0 into edge 2026-09-28 16:39:13 +00:00
whitlocktech deleted branch feat/perm-manager 2026-09-28 16:39:14 +00:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: RunicGateway/Module-Rust#25
No description provided.