mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: promote MinimumImplicitMember experiment to GA (#27472)
Promotes the `minimum-implicit-member` experiment to GA and removes it.
## What changes
- The `minimum-implicit-member` experiment constant, its
`RoleOptions.MinimumImplicitMember` toggle, and the global
`rbac.MinimumImplicitMember()` accessor are deleted. The minimal-member
behavior is now the only behavior: `organization-member` and
`organization-service-account` carry only the floor (read-self records,
notifications, and similar) and grant **no workspace permissions**.
Workspace access lives exclusively on the
`organization-workspace-access` role.
- The experiment gate on customizing `default_org_member_roles` (`PATCH
/organizations/{org}`) is removed; the built-in-roles-only validation
remains.
- The dashboard's Default Roles section and the implied-roles display on
the members page are no longer experiment-gated.
- Admin docs: new "Default member roles" section in
`docs/admin/users/organizations.md`, cross-linked from
`groups-roles.md`.
## Why this is safe for existing deployments
Migration `000516` (shipped earlier) backfilled
`default_org_member_roles` with `['organization-workspace-access']` on
every organization. Members therefore keep exactly the effective
permissions they had with the experiment off; the workspace elevation
flows through the default role instead of being baked into
`organization-member`.
**Rollback caveat:** rolling back past this release restores the bundled
elevation, silently re-granting workspace access to members of
organizations that cleared their default roles.
## Review
Deep-review R1 findings are addressed in `chore: address deep-review
findings` (copy fixes, read-only Default Roles for viewers, removable
overlapping explicit grants, RBAC prose restoration, test
de-tautologizing, docs). Point-by-point disposition is in the PR
comments.
---
Generated by Coder Agents on behalf of @Emyrk.
This commit is contained in:
@@ -31,6 +31,11 @@ Roles determine which actions users can take within the platform.
|
||||
A user may have one or more roles. All users have an implicit Member role that
|
||||
may use personal workspaces.
|
||||
|
||||
Whether organization members can create and use workspaces is controlled per
|
||||
organization through its default member roles. See
|
||||
[Default member roles](./organizations.md#default-member-roles) for how to
|
||||
remove workspace operations from the default member set.
|
||||
|
||||
## Custom Roles
|
||||
|
||||
> [!NOTE]
|
||||
|
||||
@@ -120,6 +120,38 @@ their organization. Users can be in multiple organizations.
|
||||
|
||||

|
||||
|
||||
## Default member roles
|
||||
|
||||
> [!NOTE]
|
||||
> Editing default member roles requires a Premium license.
|
||||
> ([learn more](https://coder.com/pricing#compare-plans)).
|
||||
|
||||
Each organization carries a `default_org_member_roles` list of built-in role
|
||||
names. Coder unions this list into every member's effective roles at request
|
||||
time, so changes propagate to all current and future members on their next
|
||||
request without re-issuing tokens or editing per-user role assignments.
|
||||
|
||||
The default value is `["organization-workspace-access"]`. With that default,
|
||||
every organization member can read, build, ssh into, and execute commands in
|
||||
workspaces they own. Removing `organization-workspace-access` from the list
|
||||
creates organization members that cannot create or use workspaces unless the
|
||||
role is assigned to them directly, which is useful for restricted accounts
|
||||
that should only hold the minimal member permissions.
|
||||
|
||||
To edit the default roles in the dashboard, go to
|
||||
**Admin settings** > **Organizations** > **Roles** > **Default Roles**, or
|
||||
set `default_org_member_roles` via
|
||||
`PATCH /organizations/{organization}`.
|
||||
|
||||
### Limitations
|
||||
|
||||
- `default_org_member_roles` accepts built-in role names only. Custom
|
||||
organization roles are rejected; assign them directly to members instead.
|
||||
- Removing a role from the list removes it from every member that does not
|
||||
hold the role through a direct assignment, including existing members.
|
||||
Review the per-organization [audit log](../security/audit-logs.md) if you
|
||||
need to trace who changed the defaults.
|
||||
|
||||
## Next steps
|
||||
|
||||
- [Organizations - best practices](../../tutorials/best-practices/organizations.md)
|
||||
|
||||
Reference in New Issue
Block a user