mirror of
https://github.com/discourse/discourse.git
synced 2026-08-09 21:23:14 +08:00
Followup 5823e4e3b2,
this commit allows the addition of users along with
groups to access control lists, modifying DAccessControl
to support selecting a user or group from the same
search input.
Shown here is a mix of user & group permissions in the
`DAccessControl` component:
<img width="611" height="664" alt="image"
src="https://github.com/user-attachments/assets/c25e13b0-8885-4ce7-972c-5116f3acb094"
/>
When the search opens, we show the site's groups that
the user can see as preloaded values, showing only the
group name for clarity:
<img width="612" height="389" alt="image"
src="https://github.com/user-attachments/assets/df93a94b-918e-4fed-b045-ac72f02aca41"
/>
When searching a GET request is sent and users are included
in search results.
<img width="608" height="404" alt="image"
src="https://github.com/user-attachments/assets/ff17e6c0-2505-480e-ae25-e6f8309555bc"
/>
---------
Co-authored-by: Jordan Vidrine <jordan@jordanvidrine.com>
36 lines
1 KiB
Ruby
Vendored
36 lines
1 KiB
Ruby
Vendored
# frozen_string_literal: true
|
|
|
|
module Jobs
|
|
class CleanupAclsForDeleted < ::Jobs::Base
|
|
def execute(args)
|
|
group_id = args[:group_id]
|
|
user_id = args[:user_id]
|
|
return if group_id.blank? && user_id.blank?
|
|
|
|
if group_id.present?
|
|
AccessControlList.where("allowed_group_ids @> ARRAY[?]::bigint[]", group_id).update_all(
|
|
[
|
|
"allowed_group_ids = array_remove(allowed_group_ids, ?), updated_at = ?",
|
|
group_id,
|
|
Time.zone.now,
|
|
],
|
|
)
|
|
end
|
|
|
|
if user_id.present?
|
|
AccessControlList.where("allowed_user_ids @> ARRAY[?]::bigint[]", user_id).update_all(
|
|
[
|
|
"allowed_user_ids = array_remove(allowed_user_ids, ?), updated_at = ?",
|
|
user_id,
|
|
Time.zone.now,
|
|
],
|
|
)
|
|
end
|
|
|
|
# Delete all ACLs that have no grantees left
|
|
AccessControlList.where(
|
|
"allowed_group_ids = '{}'::bigint[] AND allowed_user_ids = '{}'::bigint[]",
|
|
).delete_all
|
|
end
|
|
end
|
|
end
|