feat(groups): tree repos, hierarchy-aware RBAC, admin API
Server-side foundation for Phase-2 groups (no group-owned resources yet):
Shared types:
- GroupId, Group; App gains group_id; AppRole::{precedence,max} for
folding the highest effective role across the membership chain.
Repos:
- group_repo: tree CRUD with reparent (ancestor-walk cycle guard under a
coarse instance-wide structural advisory lock; slug frozen; bumps
structure_version) and delete=RESTRICT (refuses non-empty groups).
- group_members_repo: per-(user, group) role grants, mirroring app_members.
Hierarchy-aware authz (§5.3):
- AuthzRepo gains effective_app_role / effective_group_role (default to
direct membership / none, so the ~18 existing test stubs are untouched);
the Postgres impl resolves each via one depth-bounded recursive CTE that
MAXes the app's own row with every ancestor group_members row.
- can(): the Member path now folds inherited group roles, so a group_admin
on any ancestor is implicitly app_admin beneath it. New Capability
variants InstanceCreateGroup / Group{Read,Write,Admin}; group caps carry
no app_id (bound API keys can't manage groups). 8 new unit tests.
Admin API:
- groups_api: group CRUD + reparent (admin at both source and destination
parent, §5.6) + per-group members, all capability-gated.
- apps: POST /apps takes an optional parent group (default root); app
responses carry group_id; my_role now reflects the effective role.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -98,6 +98,30 @@ impl AppRole {
|
||||
_ => None,
|
||||
}
|
||||
}
|
||||
|
||||
/// Authority rank: higher = more authority. Used to fold the highest
|
||||
/// effective role across an app's own membership and every ancestor
|
||||
/// group membership (hierarchy-aware RBAC). Defined explicitly rather
|
||||
/// than via a derived `Ord` because the variant declaration order
|
||||
/// (`AppAdmin` first) is the reverse of authority order.
|
||||
#[must_use]
|
||||
pub const fn precedence(self) -> u8 {
|
||||
match self {
|
||||
Self::AppAdmin => 3,
|
||||
Self::Editor => 2,
|
||||
Self::Viewer => 1,
|
||||
}
|
||||
}
|
||||
|
||||
/// The more-authoritative of two roles. `app_admin > editor > viewer`.
|
||||
#[must_use]
|
||||
pub fn max(self, other: Self) -> Self {
|
||||
if self.precedence() >= other.precedence() {
|
||||
self
|
||||
} else {
|
||||
other
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// API-key scope. Exactly seven values; new scopes need a blueprint
|
||||
|
||||
Reference in New Issue
Block a user