mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
fix: allow group members to read group information (#14200)
* - allow group members to read basic Group info - allow group members to see they are part of the group, but not see that information about other members - add a GetGroupMembersCountByGroupID SQL query, which allows group members to see members count without revealing other information about the members - add the group_members_expanded db view - rewrite group member queries to use the group_members_expanded view - add the RBAC ResourceGroupMember and add it to relevant roles - rewrite GetGroupMembersByGroupID permission checks - make the GroupMember type contain all user fields - fix type issues coming from replacing User with GroupMember in group member queries - add the MemberTotalCount field to codersdk.Group - display `group.total_member_count` instead of `group.members.length` on the account page
This commit is contained in:
@@ -1,30 +1,14 @@
|
||||
-- name: GetGroupMembers :many
|
||||
SELECT * FROM group_members;
|
||||
SELECT * FROM group_members_expanded;
|
||||
|
||||
-- name: GetGroupMembersByGroupID :many
|
||||
SELECT
|
||||
users.*
|
||||
FROM
|
||||
users
|
||||
-- If the group is a user made group, then we need to check the group_members table.
|
||||
LEFT JOIN
|
||||
group_members
|
||||
ON
|
||||
group_members.user_id = users.id AND
|
||||
group_members.group_id = @group_id
|
||||
-- If it is the "Everyone" group, then we need to check the organization_members table.
|
||||
LEFT JOIN
|
||||
organization_members
|
||||
ON
|
||||
organization_members.user_id = users.id AND
|
||||
organization_members.organization_id = @group_id
|
||||
WHERE
|
||||
-- In either case, the group_id will only match an org or a group.
|
||||
(group_members.group_id = @group_id
|
||||
OR
|
||||
organization_members.organization_id = @group_id)
|
||||
AND
|
||||
users.deleted = 'false';
|
||||
SELECT * FROM group_members_expanded WHERE group_id = @group_id;
|
||||
|
||||
-- name: GetGroupMembersCountByGroupID :one
|
||||
-- Returns the total count of members in a group. Shows the total
|
||||
-- count even if the caller does not have read access to ResourceGroupMember.
|
||||
-- They only need ResourceGroup read access.
|
||||
SELECT COUNT(*) FROM group_members_expanded WHERE group_id = @group_id;
|
||||
|
||||
-- InsertUserGroupsByName adds a user to all provided groups, if they exist.
|
||||
-- name: InsertUserGroupsByName :exec
|
||||
|
||||
Reference in New Issue
Block a user