This repository has been archived on 2026-04-03. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Files
core/server/handlers/profile_permissions.go
Jeffrey Smith 66063b08ed Feat v0.2.7 user settings audit (#11)
Audit all 6 user settings sections. Remove dead chat-era code,
rename localStorage namespace, clean up stale backend policies.

- Remove BYOK nav section (empty BYOK_ITEMS, byokEnabled state,
  "BYOK Enabled" badge) and personas gate filter from settings nav
- Remove auth.permissions.changed listener (existed solely for
  dead BYOK + personas state)
- Remove Message Font Size slider, msgFont state, and --msg-font
  CSS variable application from appearance section and base template
- Rename localStorage key cs-appearance → sb-appearance with
  one-time migration preserving existing user preferences
- Remove allow_user_byok and allow_user_personas from PolicyDefaults,
  profile bootstrap, permissions handler, PublicSettings, and test seeds
- Remove orphaned .settings-nav-footer CSS class
- Replace stale policy-gating test assertions with allow_registration

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-27 15:38:42 +00:00

75 lines
1.7 KiB
Go

package handlers
import (
"net/http"
"sort"
"github.com/gin-gonic/gin"
"switchboard-core/auth"
"switchboard-core/store"
)
// ProfilePermissionsHandler exposes the current user's resolved permissions.
type ProfilePermissionsHandler struct {
stores store.Stores
}
func NewProfilePermissionsHandler(s store.Stores) *ProfilePermissionsHandler {
return &ProfilePermissionsHandler{stores: s}
}
// GetMyPermissions returns the current user's effective permission set.
// GET /api/v1/profile/permissions
func (h *ProfilePermissionsHandler) GetMyPermissions(c *gin.Context) {
userID := getUserID(c)
role, _ := c.Get("role")
ctx := c.Request.Context()
// Admin gets all permissions by definition.
var list []string
if role == "admin" {
list = make([]string, len(auth.AllPermissions))
copy(list, auth.AllPermissions)
} else {
perms, err := auth.ResolvePermissions(ctx, h.stores, userID)
if err != nil {
c.JSON(http.StatusInternalServerError, gin.H{"error": "failed to resolve permissions"})
return
}
list = make([]string, 0, len(perms))
for p := range perms {
list = append(list, p)
}
}
sort.Strings(list)
// Contributing groups
groupIDs, _ := h.stores.Groups.GetUserGroupIDs(ctx, userID)
if groupIDs == nil {
groupIDs = []string{}
}
groupIDs = append(groupIDs, auth.EveryoneGroupID)
// Teams
teams, _ := h.stores.Teams.ListForUser(ctx, userID)
teamData := make([]gin.H, 0, len(teams))
for _, t := range teams {
teamData = append(teamData, gin.H{
"id": t.ID,
"name": t.Name,
"my_role": t.MyRole,
})
}
// Policies that affect UI gating
policies := make(map[string]bool)
c.JSON(http.StatusOK, gin.H{
"permissions": list,
"groups": groupIDs,
"teams": teamData,
"policies": policies,
})
}