feat(teams): the Team read API, the moderation routes, and Admin -> Teams
The eighteen routes of docs/website/TEAMS.md §2.11, their OpenAPI annotations,
and the staff screen that drives them.
Two rules shape the read model. Hidden means absent from every public surface --
the index, the lookup and the roster alike, and a hidden Team 404s
indistinguishably from one that does not exist, because "absent" includes not
confirming it is there. And staleness is surfaced rather than silent: every
public payload carries { configured, stale, lastSyncAt }, so a page can say how
recently the projection was confirmed instead of presenting stale data as
current.
The public roster withholds both the member key and the user id -- one is a
game-internal identifier, the other names a site account. `linked` answers the
only question a public page has without publishing which account. The module's
per-audience field projection is phase 3's; this is a conservative core one.
The §2.9 gate is enforced per REQUEST, not per route. A moderator may call all
eighteen; three of them mean something different when they do, and the server
decides from the role it re-validates on every request rather than from a token
claim. The client has no "file as request" argument to get wrong.
Found by booting the real server against the real database, and not by any test:
**the index and the by-slug lookup disagreed about what exists.** listPublic was
keyed on a registered team provider while findBySlug is not, so with no module
installed `/teams` returned an empty list while `/teams/:slug/members` served a
full roster -- the index denying a Team that direct URLs answered for in full.
The rows are core's and they outlive the module that filled them: an uninstalled
module leaves a projection that is unmaintained, not one that stopped existing,
and `configured: false` is how a client learns that. The read side no longer
takes the provider into account at all. There is now a test named for the
property.
Also verified live: the public routes answer anonymously, an unknown and a hidden
slug both 404, the player and admin tiers 401 an anonymous caller, a seeded
roster projects correctly, and the reconciler logs that it is staying idle with
no provider registered rather than failing a boot.
Process obligations, all done: #swagger.* annotations on every route, `npm run
swagger` regenerated (18 paths in the spec, no dangling $refs, and the schemas
they reference added), `npm run routes:manifest` regenerated -- additions only,
184 public routes -- and BACKEND_DESIGN.md updated across the schema section and
all three tier tables.
Admin -> Teams follows the ModulesAdmin precedent: everything that decides what a
row SAYS lives in lib/teamAdmin.js, which is plain JS with tests, and the view
renders it. That split earns itself here specifically -- the screen's job is to
make "the shard has no Teams" and "core has not been able to ask for two hours"
impossible to confuse, and those two produce the same empty table. The four
freshness states are named and tested for exactly that reason, and the last
provider error is shown verbatim rather than paraphrased.
The button labels follow the caller's role: a moderator sees "Request publish",
so the pending result is not a surprise. Hiding is offered to everyone with no
gate, matching the server.
Server 894 passed, client 206 passed, client build clean. 17 route tests, 20
client display tests.
Refs docs/website/TEAMS.md §2.11, Part 12 phase 2
Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
211
server/src/router/v1/admin/teams.controller.js
Normal file
211
server/src/router/v1/admin/teams.controller.js
Normal file
@@ -0,0 +1,211 @@
|
||||
// Admin · Teams — the staff surface (TEAMS.md §2.11).
|
||||
//
|
||||
// The role split inside this file is the §2.9 gate, and it is enforced HERE
|
||||
// rather than in the router, because it is not a matter of which routes a role
|
||||
// may call: a moderator may call all of them, and three of them mean something
|
||||
// different when they do. `requestOrApply` is what decides, from the caller's
|
||||
// live role, whether an action applies or is filed for approval.
|
||||
|
||||
const teams = require('../../../model/teams/teams.model')
|
||||
const moderation = require('../../../model/teams/teamModeration.model')
|
||||
const access = require('../../../model/teams/teamAccess.model')
|
||||
const teamSync = require('../../../model/teams/teamSync.model')
|
||||
const teamsDb = require('../../../model/teams/teams.db')
|
||||
const activity = require('../../../model/activity/activity.model')
|
||||
|
||||
const log = require('../../../utils/logger')('teams')
|
||||
|
||||
const fail = (res, err, what) => {
|
||||
log.error(`admin teams: ${what} failed`, { message: err.message })
|
||||
return res.status(500).json({ message: 'Internal Server Error' })
|
||||
}
|
||||
|
||||
/** Translate a model result's { ok, status, error } into a response. */
|
||||
const send = (res, result, body = { ok: true }) =>
|
||||
(result.ok ? res.json({ ...body, ...result }) : res.status(result.status || 400).json({ message: result.error }))
|
||||
|
||||
async function listTeams(req, res) {
|
||||
try {
|
||||
return res.json(await teams.listAdmin({ includeArchived: req.query.archived === '1' }))
|
||||
} catch (err) {
|
||||
return fail(res, err, 'list')
|
||||
}
|
||||
}
|
||||
|
||||
async function getTeam(req, res) {
|
||||
try {
|
||||
const team = await teams.getAdmin(Number(req.params.id))
|
||||
if (!team) return res.status(404).json({ message: 'Team not found' })
|
||||
return res.json(team)
|
||||
} catch (err) {
|
||||
return fail(res, err, 'get')
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* The operator's escape hatch.
|
||||
*
|
||||
* Awaited rather than fire-and-forget: someone who pressed a button is owed the
|
||||
* outcome, including the provider's error when it refused. `ctx.teams.reconcile()`
|
||||
* is the debounced, unawaited path — this is not that.
|
||||
*/
|
||||
async function resync(req, res) {
|
||||
try {
|
||||
const result = await teamSync.reconcileNow('admin')
|
||||
await activity.log({ req, action: 'team.resync', detail: `${req.user.username} (#${req.user.id}) ran a Team resync` })
|
||||
return res.json(result)
|
||||
} catch (err) {
|
||||
return fail(res, err, 'resync')
|
||||
}
|
||||
}
|
||||
|
||||
async function archive(req, res) {
|
||||
try {
|
||||
const id = Number(req.params.id)
|
||||
const team = await teamsDb.findById(id)
|
||||
if (!team) return res.status(404).json({ message: 'Team not found' })
|
||||
await teamsDb.archiveTeam(id, 'staff')
|
||||
await activity.log({
|
||||
req,
|
||||
action: 'team.archive',
|
||||
detail: `${req.user.username} (#${req.user.id}) archived team "${team.name}" (#${id})`
|
||||
+ `${req.body.reason ? `: "${req.body.reason}"` : ''}`,
|
||||
})
|
||||
return res.json({ ok: true })
|
||||
} catch (err) {
|
||||
return fail(res, err, 'archive')
|
||||
}
|
||||
}
|
||||
|
||||
async function grants(req, res) {
|
||||
try {
|
||||
return res.json({ grants: await access.grantLedger(Number(req.params.id)) })
|
||||
} catch (err) {
|
||||
return fail(res, err, 'grants')
|
||||
}
|
||||
}
|
||||
|
||||
// ── Leadership overrides (§2.5.1) — NOT gated ─────────────────────────────
|
||||
|
||||
async function setLeaderOverride(req, res) {
|
||||
try {
|
||||
const id = Number(req.params.id)
|
||||
const team = await teamsDb.findById(id)
|
||||
if (!team) return res.status(404).json({ message: 'Team not found' })
|
||||
|
||||
const { memberKey, effect, reason } = req.body
|
||||
await access.setLeaderOverride({
|
||||
teamId: id,
|
||||
memberKey,
|
||||
effect,
|
||||
actorUserId: req.user.id,
|
||||
actorUsername: req.user.username,
|
||||
reason: reason || null,
|
||||
})
|
||||
await activity.log({
|
||||
req,
|
||||
action: 'team.leader.override',
|
||||
detail: `${req.user.username} (#${req.user.id}) set a "${effect}" leadership override on `
|
||||
+ `${memberKey} in team "${team.name}" (#${id})${reason ? `: "${reason}"` : ''}`,
|
||||
})
|
||||
return res.json({ ok: true })
|
||||
} catch (err) {
|
||||
return fail(res, err, 'leader-override')
|
||||
}
|
||||
}
|
||||
|
||||
async function clearLeaderOverride(req, res) {
|
||||
try {
|
||||
const id = Number(req.params.id)
|
||||
const removed = await access.clearLeaderOverride(id, req.params.memberKey)
|
||||
if (!removed) return res.status(404).json({ message: 'No such override' })
|
||||
await activity.log({
|
||||
req,
|
||||
action: 'team.leader.override',
|
||||
detail: `${req.user.username} (#${req.user.id}) cleared the leadership override on `
|
||||
+ `${req.params.memberKey} in team #${id}`,
|
||||
})
|
||||
return res.json({ ok: true })
|
||||
} catch (err) {
|
||||
return fail(res, err, 'leader-override')
|
||||
}
|
||||
}
|
||||
|
||||
// ── The three gated actions, plus the ungated hide (§2.9) ─────────────────
|
||||
|
||||
async function unhide(req, res) {
|
||||
try {
|
||||
return send(res, await moderation.requestOrApply({
|
||||
req, actor: req.user, teamId: Number(req.params.id), action: 'unhide', reason: req.body.reason,
|
||||
}))
|
||||
} catch (err) {
|
||||
return fail(res, err, 'unhide')
|
||||
}
|
||||
}
|
||||
|
||||
async function hide(req, res) {
|
||||
try {
|
||||
return send(res, await moderation.hide({
|
||||
req, actor: req.user, teamId: Number(req.params.id), reason: req.body.reason,
|
||||
}))
|
||||
} catch (err) {
|
||||
return fail(res, err, 'hide')
|
||||
}
|
||||
}
|
||||
|
||||
async function displayName(req, res) {
|
||||
try {
|
||||
const { displayName: value, reason } = req.body
|
||||
// An empty string is how a UI says "clear it", and clearing is its own gated
|
||||
// action rather than an override set to nothing — otherwise the audit line
|
||||
// would read as though someone published a blank name.
|
||||
const action = value ? 'display_name_override' : 'clear_display_name_override'
|
||||
return send(res, await moderation.requestOrApply({
|
||||
req, actor: req.user, teamId: Number(req.params.id), action, payload: { displayName: value || null }, reason,
|
||||
}))
|
||||
} catch (err) {
|
||||
return fail(res, err, 'display-name')
|
||||
}
|
||||
}
|
||||
|
||||
async function reviewQueue(req, res) {
|
||||
try {
|
||||
return res.json({ teams: await moderation.reviewQueue() })
|
||||
} catch (err) {
|
||||
return fail(res, err, 'review queue')
|
||||
}
|
||||
}
|
||||
|
||||
async function listRequests(req, res) {
|
||||
try {
|
||||
return res.json({ requests: await moderation.listRequests({ status: req.query.status || 'pending' }) })
|
||||
} catch (err) {
|
||||
return fail(res, err, 'requests')
|
||||
}
|
||||
}
|
||||
|
||||
async function decideRequest(req, res) {
|
||||
try {
|
||||
return send(res, await moderation.decide({
|
||||
req, actor: req.user, requestId: Number(req.params.id), status: req.body.status, note: req.body.note,
|
||||
}))
|
||||
} catch (err) {
|
||||
return fail(res, err, 'decide')
|
||||
}
|
||||
}
|
||||
|
||||
module.exports = {
|
||||
listTeams,
|
||||
getTeam,
|
||||
resync,
|
||||
archive,
|
||||
grants,
|
||||
setLeaderOverride,
|
||||
clearLeaderOverride,
|
||||
unhide,
|
||||
hide,
|
||||
displayName,
|
||||
reviewQueue,
|
||||
listRequests,
|
||||
decideRequest,
|
||||
}
|
||||
Reference in New Issue
Block a user