fix(server): doc owner and default role permission (#10281)
This commit is contained in:
@@ -60,6 +60,9 @@ test.before(async () => {
|
|||||||
// which will keep the test process alive to timeout.
|
// which will keep the test process alive to timeout.
|
||||||
stalledInterval: 100,
|
stalledInterval: 100,
|
||||||
},
|
},
|
||||||
|
queue: {
|
||||||
|
defaultJobOptions: { delay: 1000 },
|
||||||
|
},
|
||||||
},
|
},
|
||||||
}),
|
}),
|
||||||
JobModule.forRoot(),
|
JobModule.forRoot(),
|
||||||
|
|||||||
@@ -613,6 +613,8 @@ export class PermissionService {
|
|||||||
}),
|
}),
|
||||||
]);
|
]);
|
||||||
|
|
||||||
|
const defaultPageRole = pageEntity?.defaultRole ?? DocRole.Manager;
|
||||||
|
|
||||||
if (
|
if (
|
||||||
// Page role exists, check it first
|
// Page role exists, check it first
|
||||||
(roleEntity && roleEntity.type >= role) ||
|
(roleEntity && roleEntity.type >= role) ||
|
||||||
@@ -625,7 +627,7 @@ export class PermissionService {
|
|||||||
workspaceRoleEntity.type !== WorkspaceRole.External &&
|
workspaceRoleEntity.type !== WorkspaceRole.External &&
|
||||||
Math.max(
|
Math.max(
|
||||||
roleEntity?.type ?? Number.MIN_SAFE_INTEGER,
|
roleEntity?.type ?? Number.MIN_SAFE_INTEGER,
|
||||||
pageEntity?.defaultRole ?? Number.MIN_SAFE_INTEGER
|
defaultPageRole
|
||||||
) >= role)
|
) >= role)
|
||||||
) {
|
) {
|
||||||
return true;
|
return true;
|
||||||
@@ -638,9 +640,7 @@ export class PermissionService {
|
|||||||
? WorkspaceRole[workspaceRoleEntity.type]
|
? WorkspaceRole[workspaceRoleEntity.type]
|
||||||
: undefined,
|
: undefined,
|
||||||
pageRole: roleEntity ? DocRole[roleEntity.type] : undefined,
|
pageRole: roleEntity ? DocRole[roleEntity.type] : undefined,
|
||||||
pageDefaultRole: pageEntity
|
pageDefaultRole: DocRole[defaultPageRole],
|
||||||
? DocRole[pageEntity.defaultRole]
|
|
||||||
: undefined,
|
|
||||||
requiredRole: DocRole[role],
|
requiredRole: DocRole[role],
|
||||||
action,
|
action,
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -155,7 +155,8 @@ export class WorkspaceDocResolver {
|
|||||||
|
|
||||||
constructor(
|
constructor(
|
||||||
private readonly prisma: PrismaClient,
|
private readonly prisma: PrismaClient,
|
||||||
private readonly permission: PermissionService
|
private readonly permission: PermissionService,
|
||||||
|
private readonly models: Models
|
||||||
) {}
|
) {}
|
||||||
|
|
||||||
@ResolveField(() => [DocType], {
|
@ResolveField(() => [DocType], {
|
||||||
@@ -209,7 +210,12 @@ export class WorkspaceDocResolver {
|
|||||||
},
|
},
|
||||||
});
|
});
|
||||||
|
|
||||||
if (!doc) {
|
if (doc) {
|
||||||
|
return doc;
|
||||||
|
}
|
||||||
|
|
||||||
|
await this.tryFixDocOwner(workspace.id, docId);
|
||||||
|
|
||||||
return {
|
return {
|
||||||
docId,
|
docId,
|
||||||
workspaceId: workspace.id,
|
workspaceId: workspace.id,
|
||||||
@@ -219,9 +225,6 @@ export class WorkspaceDocResolver {
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
return doc;
|
|
||||||
}
|
|
||||||
|
|
||||||
@Mutation(() => DocType, {
|
@Mutation(() => DocType, {
|
||||||
deprecationReason: 'use publishDoc instead',
|
deprecationReason: 'use publishDoc instead',
|
||||||
})
|
})
|
||||||
@@ -331,6 +334,58 @@ export class WorkspaceDocResolver {
|
|||||||
|
|
||||||
return this.permission.revokePublicPage(docId.workspace, docId.guid);
|
return this.permission.revokePublicPage(docId.workspace, docId.guid);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
private async tryFixDocOwner(workspaceId: string, docId: string) {
|
||||||
|
const exists = await this.models.doc.exists(workspaceId, docId);
|
||||||
|
|
||||||
|
// skip if doc not even exists
|
||||||
|
if (!exists) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
const owner = await this.prisma.workspaceDocUserPermission.findFirst({
|
||||||
|
where: {
|
||||||
|
workspaceId,
|
||||||
|
docId,
|
||||||
|
type: DocRole.Owner,
|
||||||
|
},
|
||||||
|
});
|
||||||
|
|
||||||
|
// skip if owner of already exists
|
||||||
|
if (owner) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
// try snapshot.createdBy first
|
||||||
|
const snapshot = await this.prisma.snapshot.findUnique({
|
||||||
|
select: {
|
||||||
|
createdBy: true,
|
||||||
|
},
|
||||||
|
where: {
|
||||||
|
workspaceId_id: {
|
||||||
|
workspaceId,
|
||||||
|
id: docId,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
});
|
||||||
|
|
||||||
|
let fixedOwner = snapshot?.createdBy;
|
||||||
|
|
||||||
|
// try workspace.owner
|
||||||
|
if (!fixedOwner) {
|
||||||
|
const owner = await this.permission.getWorkspaceOwner(workspaceId);
|
||||||
|
fixedOwner = owner.id;
|
||||||
|
}
|
||||||
|
|
||||||
|
await this.prisma.workspaceDocUserPermission.create({
|
||||||
|
data: {
|
||||||
|
workspaceId,
|
||||||
|
docId,
|
||||||
|
userId: fixedOwner,
|
||||||
|
type: DocRole.Owner,
|
||||||
|
},
|
||||||
|
});
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@Resolver(() => DocType)
|
@Resolver(() => DocType)
|
||||||
|
|||||||
Reference in New Issue
Block a user