Feat v0.9.9 surface access via roles
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -206,6 +206,9 @@ type TeamStore interface {
|
||||
// HasRole checks whether a user holds a specific role (primary or additional).
|
||||
HasRole(ctx context.Context, teamID, userID, role string) (bool, error)
|
||||
|
||||
// HasRoleInAnyTeam checks whether a user holds a specific role in any team.
|
||||
HasRoleInAnyTeam(ctx context.Context, userID, role string) (bool, error)
|
||||
|
||||
// RemoveAllUserRoles deletes all additional roles for a member (cleanup on removal).
|
||||
RemoveAllUserRoles(ctx context.Context, teamID, userID string) error
|
||||
|
||||
|
||||
@@ -388,6 +388,17 @@ func (s *TeamStore) HasRole(ctx context.Context, teamID, userID, role string) (b
|
||||
return exists, err
|
||||
}
|
||||
|
||||
func (s *TeamStore) HasRoleInAnyTeam(ctx context.Context, userID, role string) (bool, error) {
|
||||
var exists bool
|
||||
err := DB.QueryRowContext(ctx, `
|
||||
SELECT EXISTS(
|
||||
SELECT 1 FROM team_members WHERE user_id = $1 AND role = $2
|
||||
UNION ALL
|
||||
SELECT 1 FROM team_user_roles WHERE user_id = $1 AND role = $2
|
||||
)`, userID, role).Scan(&exists)
|
||||
return exists, err
|
||||
}
|
||||
|
||||
func (s *TeamStore) RemoveAllUserRoles(ctx context.Context, teamID, userID string) error {
|
||||
_, err := DB.ExecContext(ctx,
|
||||
`DELETE FROM team_user_roles WHERE team_id = $1 AND user_id = $2`,
|
||||
|
||||
@@ -395,6 +395,17 @@ func (s *TeamStore) HasRole(ctx context.Context, teamID, userID, role string) (b
|
||||
return count > 0, err
|
||||
}
|
||||
|
||||
func (s *TeamStore) HasRoleInAnyTeam(ctx context.Context, userID, role string) (bool, error) {
|
||||
var count int
|
||||
err := DB.QueryRowContext(ctx, `
|
||||
SELECT COUNT(*) FROM (
|
||||
SELECT 1 FROM team_members WHERE user_id = ? AND role = ?
|
||||
UNION ALL
|
||||
SELECT 1 FROM team_user_roles WHERE user_id = ? AND role = ?
|
||||
) LIMIT 1`, userID, role, userID, role).Scan(&count)
|
||||
return count > 0, err
|
||||
}
|
||||
|
||||
func (s *TeamStore) RemoveAllUserRoles(ctx context.Context, teamID, userID string) error {
|
||||
_, err := DB.ExecContext(ctx,
|
||||
`DELETE FROM team_user_roles WHERE team_id = ? AND user_id = ?`,
|
||||
|
||||
Reference in New Issue
Block a user