mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore: perform several small frontend permissions refactors (#16735)
This commit is contained in:
@@ -10,6 +10,7 @@ import {
|
||||
import type { UpdateUserProfileRequest, User } from "api/typesGenerated";
|
||||
import { displaySuccess } from "components/GlobalSnackbar/utils";
|
||||
import { useEmbeddedMetadata } from "hooks/useEmbeddedMetadata";
|
||||
import { type Permissions, permissionChecks } from "modules/permissions";
|
||||
import {
|
||||
type FC,
|
||||
type PropsWithChildren,
|
||||
@@ -18,7 +19,6 @@ import {
|
||||
useContext,
|
||||
} from "react";
|
||||
import { useMutation, useQuery, useQueryClient } from "react-query";
|
||||
import { type Permissions, permissionChecks } from "./permissions";
|
||||
|
||||
export type AuthContextValue = {
|
||||
isLoading: boolean;
|
||||
|
||||
@@ -1,46 +0,0 @@
|
||||
import {
|
||||
Dialog,
|
||||
DialogContent,
|
||||
DialogDescription,
|
||||
DialogFooter,
|
||||
DialogHeader,
|
||||
DialogTitle,
|
||||
} from "components/Dialog/Dialog";
|
||||
import { Link } from "components/Link/Link";
|
||||
import type { FC, ReactNode } from "react";
|
||||
|
||||
export interface RequirePermissionProps {
|
||||
children?: ReactNode;
|
||||
isFeatureVisible: boolean;
|
||||
}
|
||||
|
||||
/**
|
||||
* Wraps routes that are available based on RBAC or licensing.
|
||||
*/
|
||||
export const RequirePermission: FC<RequirePermissionProps> = ({
|
||||
children,
|
||||
isFeatureVisible,
|
||||
}) => {
|
||||
if (!isFeatureVisible) {
|
||||
return (
|
||||
<Dialog open={true}>
|
||||
<DialogContent>
|
||||
<DialogHeader>
|
||||
<DialogTitle>
|
||||
You don't have permission to view this page
|
||||
</DialogTitle>
|
||||
</DialogHeader>
|
||||
<DialogDescription>
|
||||
If you believe this is a mistake, please contact your administrator
|
||||
or try signing in with different credentials.
|
||||
</DialogDescription>
|
||||
<DialogFooter>
|
||||
<Link href="/">Go to workspaces</Link>
|
||||
</DialogFooter>
|
||||
</DialogContent>
|
||||
</Dialog>
|
||||
);
|
||||
}
|
||||
|
||||
return <>{children}</>;
|
||||
};
|
||||
@@ -1,205 +0,0 @@
|
||||
import type { AuthorizationCheck } from "api/typesGenerated";
|
||||
|
||||
export type Permissions = {
|
||||
[k in PermissionName]: boolean;
|
||||
};
|
||||
|
||||
export type PermissionName = keyof typeof permissionChecks;
|
||||
|
||||
export const permissionChecks = {
|
||||
viewAllUsers: {
|
||||
object: {
|
||||
resource_type: "user",
|
||||
},
|
||||
action: "read",
|
||||
},
|
||||
updateUsers: {
|
||||
object: {
|
||||
resource_type: "user",
|
||||
},
|
||||
action: "update",
|
||||
},
|
||||
createUser: {
|
||||
object: {
|
||||
resource_type: "user",
|
||||
},
|
||||
action: "create",
|
||||
},
|
||||
createTemplates: {
|
||||
object: {
|
||||
resource_type: "template",
|
||||
any_org: true,
|
||||
},
|
||||
action: "update",
|
||||
},
|
||||
updateTemplates: {
|
||||
object: {
|
||||
resource_type: "template",
|
||||
},
|
||||
action: "update",
|
||||
},
|
||||
deleteTemplates: {
|
||||
object: {
|
||||
resource_type: "template",
|
||||
},
|
||||
action: "delete",
|
||||
},
|
||||
viewDeploymentValues: {
|
||||
object: {
|
||||
resource_type: "deployment_config",
|
||||
},
|
||||
action: "read",
|
||||
},
|
||||
editDeploymentValues: {
|
||||
object: {
|
||||
resource_type: "deployment_config",
|
||||
},
|
||||
action: "update",
|
||||
},
|
||||
viewUpdateCheck: {
|
||||
object: {
|
||||
resource_type: "deployment_config",
|
||||
},
|
||||
action: "read",
|
||||
},
|
||||
viewExternalAuthConfig: {
|
||||
object: {
|
||||
resource_type: "deployment_config",
|
||||
},
|
||||
action: "read",
|
||||
},
|
||||
viewDeploymentStats: {
|
||||
object: {
|
||||
resource_type: "deployment_stats",
|
||||
},
|
||||
action: "read",
|
||||
},
|
||||
readWorkspaceProxies: {
|
||||
object: {
|
||||
resource_type: "workspace_proxy",
|
||||
},
|
||||
action: "read",
|
||||
},
|
||||
editWorkspaceProxies: {
|
||||
object: {
|
||||
resource_type: "workspace_proxy",
|
||||
},
|
||||
action: "create",
|
||||
},
|
||||
createOrganization: {
|
||||
object: {
|
||||
resource_type: "organization",
|
||||
},
|
||||
action: "create",
|
||||
},
|
||||
viewAnyGroup: {
|
||||
object: {
|
||||
resource_type: "group",
|
||||
},
|
||||
action: "read",
|
||||
},
|
||||
createGroup: {
|
||||
object: {
|
||||
resource_type: "group",
|
||||
},
|
||||
action: "create",
|
||||
},
|
||||
viewAllLicenses: {
|
||||
object: {
|
||||
resource_type: "license",
|
||||
},
|
||||
action: "read",
|
||||
},
|
||||
viewNotificationTemplate: {
|
||||
object: {
|
||||
resource_type: "notification_template",
|
||||
},
|
||||
action: "read",
|
||||
},
|
||||
viewOrganizationIDPSyncSettings: {
|
||||
object: {
|
||||
resource_type: "idpsync_settings",
|
||||
},
|
||||
action: "read",
|
||||
},
|
||||
|
||||
viewAnyMembers: {
|
||||
object: {
|
||||
resource_type: "organization_member",
|
||||
any_org: true,
|
||||
},
|
||||
action: "read",
|
||||
},
|
||||
editAnyGroups: {
|
||||
object: {
|
||||
resource_type: "group",
|
||||
any_org: true,
|
||||
},
|
||||
action: "update",
|
||||
},
|
||||
assignAnyRoles: {
|
||||
object: {
|
||||
resource_type: "assign_org_role",
|
||||
any_org: true,
|
||||
},
|
||||
action: "assign",
|
||||
},
|
||||
viewAnyIdpSyncSettings: {
|
||||
object: {
|
||||
resource_type: "idpsync_settings",
|
||||
any_org: true,
|
||||
},
|
||||
action: "read",
|
||||
},
|
||||
editAnySettings: {
|
||||
object: {
|
||||
resource_type: "organization",
|
||||
any_org: true,
|
||||
},
|
||||
action: "update",
|
||||
},
|
||||
viewAnyAuditLog: {
|
||||
object: {
|
||||
resource_type: "audit_log",
|
||||
any_org: true,
|
||||
},
|
||||
action: "read",
|
||||
},
|
||||
viewDebugInfo: {
|
||||
object: {
|
||||
resource_type: "debug_info",
|
||||
},
|
||||
action: "read",
|
||||
},
|
||||
} as const satisfies Record<string, AuthorizationCheck>;
|
||||
|
||||
export const canViewDeploymentSettings = (
|
||||
permissions: Permissions | undefined,
|
||||
): permissions is Permissions => {
|
||||
return (
|
||||
permissions !== undefined &&
|
||||
(permissions.viewDeploymentValues ||
|
||||
permissions.viewAllLicenses ||
|
||||
permissions.viewAllUsers ||
|
||||
permissions.viewAnyGroup ||
|
||||
permissions.viewNotificationTemplate ||
|
||||
permissions.viewOrganizationIDPSyncSettings)
|
||||
);
|
||||
};
|
||||
|
||||
/**
|
||||
* Checks if the user can view or edit members or groups for the organization
|
||||
* that produced the given OrganizationPermissions.
|
||||
*/
|
||||
export const canViewAnyOrganization = (
|
||||
permissions: Permissions | undefined,
|
||||
): permissions is Permissions => {
|
||||
return (
|
||||
permissions !== undefined &&
|
||||
(permissions.viewAnyMembers ||
|
||||
permissions.editAnyGroups ||
|
||||
permissions.assignAnyRoles ||
|
||||
permissions.viewAnyIdpSyncSettings ||
|
||||
permissions.editAnySettings)
|
||||
);
|
||||
};
|
||||
Reference in New Issue
Block a user