fix(server): doc owner and default role permission (#10281)

This commit is contained in:
liuyi
2025-02-19 16:29:46 +08:00
committed by GitHub
parent 61ee5531f4
commit 521ee9d374
3 changed files with 72 additions and 14 deletions

View File

@@ -60,6 +60,9 @@ test.before(async () => {
// which will keep the test process alive to timeout. // which will keep the test process alive to timeout.
stalledInterval: 100, stalledInterval: 100,
}, },
queue: {
defaultJobOptions: { delay: 1000 },
},
}, },
}), }),
JobModule.forRoot(), JobModule.forRoot(),

View File

@@ -613,6 +613,8 @@ export class PermissionService {
}), }),
]); ]);
const defaultPageRole = pageEntity?.defaultRole ?? DocRole.Manager;
if ( if (
// Page role exists, check it first // Page role exists, check it first
(roleEntity && roleEntity.type >= role) || (roleEntity && roleEntity.type >= role) ||
@@ -625,7 +627,7 @@ export class PermissionService {
workspaceRoleEntity.type !== WorkspaceRole.External && workspaceRoleEntity.type !== WorkspaceRole.External &&
Math.max( Math.max(
roleEntity?.type ?? Number.MIN_SAFE_INTEGER, roleEntity?.type ?? Number.MIN_SAFE_INTEGER,
pageEntity?.defaultRole ?? Number.MIN_SAFE_INTEGER defaultPageRole
) >= role) ) >= role)
) { ) {
return true; return true;
@@ -638,9 +640,7 @@ export class PermissionService {
? WorkspaceRole[workspaceRoleEntity.type] ? WorkspaceRole[workspaceRoleEntity.type]
: undefined, : undefined,
pageRole: roleEntity ? DocRole[roleEntity.type] : undefined, pageRole: roleEntity ? DocRole[roleEntity.type] : undefined,
pageDefaultRole: pageEntity pageDefaultRole: DocRole[defaultPageRole],
? DocRole[pageEntity.defaultRole]
: undefined,
requiredRole: DocRole[role], requiredRole: DocRole[role],
action, action,
}; };

View File

@@ -155,7 +155,8 @@ export class WorkspaceDocResolver {
constructor( constructor(
private readonly prisma: PrismaClient, private readonly prisma: PrismaClient,
private readonly permission: PermissionService private readonly permission: PermissionService,
private readonly models: Models
) {} ) {}
@ResolveField(() => [DocType], { @ResolveField(() => [DocType], {
@@ -209,7 +210,12 @@ export class WorkspaceDocResolver {
}, },
}); });
if (!doc) { if (doc) {
return doc;
}
await this.tryFixDocOwner(workspace.id, docId);
return { return {
docId, docId,
workspaceId: workspace.id, workspaceId: workspace.id,
@@ -219,9 +225,6 @@ export class WorkspaceDocResolver {
}; };
} }
return doc;
}
@Mutation(() => DocType, { @Mutation(() => DocType, {
deprecationReason: 'use publishDoc instead', deprecationReason: 'use publishDoc instead',
}) })
@@ -331,6 +334,58 @@ export class WorkspaceDocResolver {
return this.permission.revokePublicPage(docId.workspace, docId.guid); return this.permission.revokePublicPage(docId.workspace, docId.guid);
} }
private async tryFixDocOwner(workspaceId: string, docId: string) {
const exists = await this.models.doc.exists(workspaceId, docId);
// skip if doc not even exists
if (!exists) {
return;
}
const owner = await this.prisma.workspaceDocUserPermission.findFirst({
where: {
workspaceId,
docId,
type: DocRole.Owner,
},
});
// skip if owner of already exists
if (owner) {
return;
}
// try snapshot.createdBy first
const snapshot = await this.prisma.snapshot.findUnique({
select: {
createdBy: true,
},
where: {
workspaceId_id: {
workspaceId,
id: docId,
},
},
});
let fixedOwner = snapshot?.createdBy;
// try workspace.owner
if (!fixedOwner) {
const owner = await this.permission.getWorkspaceOwner(workspaceId);
fixedOwner = owner.id;
}
await this.prisma.workspaceDocUserPermission.create({
data: {
workspaceId,
docId,
userId: fixedOwner,
type: DocRole.Owner,
},
});
}
} }
@Resolver(() => DocType) @Resolver(() => DocType)