mirror of
https://github.com/ReCloudStudio/WebHooker.git
synced 2026-09-22 16:11:29 +00:00
feat(admin): role-based group members (owner/admin/viewer), invites and audit log
- Group model: members[] with roles owner/admin/viewer; legacy adminIds
resolve to owners (backward compatible); last-owner and self-demotion
guards
- Unified permission middleware (src/web/auth.ts): requireAnyAccess,
requireGroup(Role), bearerAuthMiddleware replace per-route loadScope
- Single-use 7-day invite links (invite:{token}); accept via /admin/invite
or the OAuth callback; self-signup personal group via ALLOW_SELF_SIGNUP
- D1 audit_logs (migration 0005): login/logout, group/route/member/invite
changes; GET /admin/api/audit; scheduled prune after AUDIT_RETENTION_DAYS
- Env: ALLOW_SELF_SIGNUP, AUDIT_RETENTION_DAYS
This commit is contained in:
parent
f8cb3a4ddb
commit
9b8533cabc
10 changed files with 964 additions and 153 deletions
28
src/types.ts
28
src/types.ts
|
|
@ -17,6 +17,13 @@ export interface Env {
|
|||
TELEGRAM_TOKEN?: string;
|
||||
TELEGRAM_WEBHOOK_SECRET?: string;
|
||||
TELEGRAM_RICH_HEADER_HOST?: string;
|
||||
/**
|
||||
* When enabled ("1"/"true"), GitHub users without any group access get a
|
||||
* personal group on first login instead of being blocked.
|
||||
*/
|
||||
ALLOW_SELF_SIGNUP?: string;
|
||||
/** Audit log retention in days (default 90). */
|
||||
AUDIT_RETENTION_DAYS?: string;
|
||||
ASSETS?: Fetcher;
|
||||
KV: KVNamespace;
|
||||
DB: D1Database;
|
||||
|
|
@ -72,14 +79,31 @@ export interface Route {
|
|||
discordRoleIds?: string[];
|
||||
}
|
||||
|
||||
export type GroupRole = "owner" | "admin" | "viewer";
|
||||
|
||||
export interface GroupMember {
|
||||
/**
|
||||
* GitHub login (case-insensitive). Ids are matched when stored, logins
|
||||
* otherwise; identityMatches handles both.
|
||||
*/
|
||||
login: string;
|
||||
role: GroupRole;
|
||||
}
|
||||
|
||||
export interface Group {
|
||||
id: string;
|
||||
name: string;
|
||||
/**
|
||||
* GitHub user ids or logins (case-insensitive) allowed to manage this group.
|
||||
* Super admins (ADMIN_USER_IDS) always have access regardless of this list.
|
||||
* Deprecated legacy field: GitHub user ids or logins allowed to manage this
|
||||
* group. Kept for backward compatibility — when `members` is absent, these
|
||||
* are normalized to `members` with role "owner". New writes use `members`.
|
||||
*/
|
||||
adminIds: string[];
|
||||
/**
|
||||
* Group members with roles. Roles: owner (manage group + members + invites),
|
||||
* admin (manage routes), viewer (read-only). Super admins always bypass.
|
||||
*/
|
||||
members?: GroupMember[];
|
||||
/**
|
||||
* GitHub organization/user logins (case-insensitive) whose webhook events are
|
||||
* allowed into this group's routes. Empty/omitted = no owner restriction.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue