feat(admin): scope groups to specific GitHub orgs/users

Add an optional owners[] field to groups (super-admin only). When set,
only webhook events whose repository owner or organization login matches
enter that group's routes; empty owners means no restriction, keeping
existing routes backward compatible.

- types: Group.owners?, groups.ts groupAcceptsOwners()
- webhook.ts eventOwners() extracts repo owner + org login
- discord.ts dispatch skips routes whose group rejects the event owner
- admin-routes.ts validateGroups() validates owners list
This commit is contained in:
RhenCloud 2026-08-02 08:15:49 +08:00
parent 667b8038af
commit 537f4cbb84
No known key found for this signature in database
GPG key ID: A574A617378C4E0B
5 changed files with 46 additions and 1 deletions

View file

@ -29,6 +29,17 @@ export function isGroupAdmin(group: Group, userId: string, login: string): boole
return identityMatches(group.adminIds ?? [], userId, login);
}
/**
* Whether an event originating from `owners` (org/user logins) is allowed into
* this group. A group with no owner restriction accepts everything.
*/
export function groupAcceptsOwners(group: Group, owners: string[]): boolean {
const restrict = (group.owners ?? []).map((s) => s.trim().toLowerCase()).filter(Boolean);
if (restrict.length === 0) return true;
const seen = owners.map((s) => s.trim().toLowerCase()).filter(Boolean);
return seen.some((o) => restrict.includes(o));
}
export interface AccessScope {
isSuper: boolean;
/** Groups the user may view/edit. When isSuper, this is every group. */