Feat admin rbac migration (#1)
Co-authored-by: Jeffrey Smith <jasafpro@gmail.com> Co-committed-by: Jeffrey Smith <jasafpro@gmail.com>
This commit was merged in pull request #1.
This commit is contained in:
@@ -43,17 +43,14 @@ func (s *GroupStore) GetByID(ctx context.Context, id string) (*models.Group, err
|
||||
g.created_at, g.updated_at,
|
||||
(SELECT COUNT(*) FROM group_members WHERE group_id = g.id) AS member_count,
|
||||
COALESCE(g.source, 'manual'),
|
||||
COALESCE(g.permissions, '[]'::jsonb),
|
||||
g.token_budget_daily,
|
||||
g.token_budget_monthly,
|
||||
g.allowed_models
|
||||
COALESCE(g.permissions, '[]'::jsonb)
|
||||
FROM groups g WHERE g.id = $1`, id)
|
||||
return scanGroup(row)
|
||||
}
|
||||
|
||||
// Update applies a patch to a group.
|
||||
// The Everyone group (source=system) allows permission/budget edits but not
|
||||
// name, description, or structural changes — those fields are silently ignored.
|
||||
// System groups (source=system) allow permission edits but not name,
|
||||
// description, or structural changes — those fields are silently ignored.
|
||||
func (s *GroupStore) Update(ctx context.Context, id string, patch models.GroupPatch) error {
|
||||
var source string
|
||||
if err := DB.QueryRowContext(ctx, "SELECT source FROM groups WHERE id = $1", id).Scan(&source); err != nil {
|
||||
@@ -76,25 +73,6 @@ func (s *GroupStore) Update(ctx context.Context, id string, patch models.GroupPa
|
||||
}
|
||||
b.Set("permissions", permsJSON)
|
||||
}
|
||||
if patch.ClearBudgetDaily {
|
||||
b.SetNull("token_budget_daily")
|
||||
} else if patch.TokenBudgetDaily != nil {
|
||||
b.Set("token_budget_daily", *patch.TokenBudgetDaily)
|
||||
}
|
||||
if patch.ClearBudgetMonthly {
|
||||
b.SetNull("token_budget_monthly")
|
||||
} else if patch.TokenBudgetMonthly != nil {
|
||||
b.Set("token_budget_monthly", *patch.TokenBudgetMonthly)
|
||||
}
|
||||
if patch.ClearAllowedModels {
|
||||
b.SetNull("allowed_models")
|
||||
} else if patch.AllowedModels != nil {
|
||||
modelsJSON, err := json.Marshal(*patch.AllowedModels)
|
||||
if err != nil {
|
||||
return fmt.Errorf("marshal allowed_models: %w", err)
|
||||
}
|
||||
b.Set("allowed_models", modelsJSON)
|
||||
}
|
||||
if !b.HasSets() {
|
||||
return nil
|
||||
}
|
||||
@@ -138,10 +116,7 @@ const groupSelectCols = `
|
||||
g.created_at, g.updated_at,
|
||||
(SELECT COUNT(*) FROM group_members WHERE group_id = g.id) AS member_count,
|
||||
COALESCE(g.source, 'manual'),
|
||||
COALESCE(g.permissions, '[]'::jsonb),
|
||||
g.token_budget_daily,
|
||||
g.token_budget_monthly,
|
||||
g.allowed_models`
|
||||
COALESCE(g.permissions, '[]'::jsonb)`
|
||||
|
||||
func (s *GroupStore) ListAll(ctx context.Context) ([]models.Group, error) {
|
||||
return queryGroups(ctx, `SELECT`+groupSelectCols+`
|
||||
@@ -250,28 +225,17 @@ func scanGroup(row groupScanner) (*models.Group, error) {
|
||||
var teamID sql.NullString
|
||||
var createdBy sql.NullString
|
||||
var permsJSON []byte
|
||||
var budgetDaily, budgetMonthly sql.NullInt64
|
||||
var allowedJSON []byte
|
||||
|
||||
if err := row.Scan(
|
||||
&g.ID, &g.Name, &g.Description, &g.Scope, &teamID, &createdBy,
|
||||
&g.CreatedAt, &g.UpdatedAt, &g.MemberCount, &g.Source,
|
||||
&permsJSON, &budgetDaily, &budgetMonthly, &allowedJSON,
|
||||
&permsJSON,
|
||||
); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
g.TeamID = NullableStringPtr(teamID)
|
||||
g.CreatedBy = NullableStringPtr(createdBy)
|
||||
g.Permissions = unmarshalStringSlice(permsJSON)
|
||||
if budgetDaily.Valid {
|
||||
g.TokenBudgetDaily = &budgetDaily.Int64
|
||||
}
|
||||
if budgetMonthly.Valid {
|
||||
g.TokenBudgetMonthly = &budgetMonthly.Int64
|
||||
}
|
||||
if len(allowedJSON) > 0 && string(allowedJSON) != "null" {
|
||||
g.AllowedModels = unmarshalStringSlice(allowedJSON)
|
||||
}
|
||||
return &g, nil
|
||||
}
|
||||
|
||||
@@ -288,28 +252,17 @@ func queryGroups(ctx context.Context, q string, args ...interface{}) ([]models.G
|
||||
var teamID sql.NullString
|
||||
var createdBy sql.NullString
|
||||
var permsJSON []byte
|
||||
var budgetDaily, budgetMonthly sql.NullInt64
|
||||
var allowedJSON []byte
|
||||
|
||||
if err := rows.Scan(
|
||||
&g.ID, &g.Name, &g.Description, &g.Scope, &teamID, &createdBy,
|
||||
&g.CreatedAt, &g.UpdatedAt, &g.MemberCount, &g.Source,
|
||||
&permsJSON, &budgetDaily, &budgetMonthly, &allowedJSON,
|
||||
&permsJSON,
|
||||
); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
g.TeamID = NullableStringPtr(teamID)
|
||||
g.CreatedBy = NullableStringPtr(createdBy)
|
||||
g.Permissions = unmarshalStringSlice(permsJSON)
|
||||
if budgetDaily.Valid {
|
||||
g.TokenBudgetDaily = &budgetDaily.Int64
|
||||
}
|
||||
if budgetMonthly.Valid {
|
||||
g.TokenBudgetMonthly = &budgetMonthly.Int64
|
||||
}
|
||||
if len(allowedJSON) > 0 && string(allowedJSON) != "null" {
|
||||
g.AllowedModels = unmarshalStringSlice(allowedJSON)
|
||||
}
|
||||
result = append(result, g)
|
||||
}
|
||||
return result, rows.Err()
|
||||
|
||||
Reference in New Issue
Block a user