Granting was a checklist of every user on each plugin's page, so "what may
this person use?" meant opening every plugin in turn — and the answer lived
on N pages while the connector half of it already lived on one. Both grant
sections now sit together on #users/{id}: same row list, same disabled chip,
same replace-the-whole-set save. The plugin's own page keeps a read-only
roster of who holds it, linking back to each person.
- db: plugin_access::set_for_user, the per-user twin of set_for_user on
mcp_catalog_access; set_access stays as the inverse read model
- PluginManager: list_grants_for_user / set_grants_for_user, which omit and
reject manages_own_access plugins (a box that controls nothing is worse
than no box)
- GET/PUT /api/users/{id}/plugins, mounted next to /users/{id}/connectors;
PUT /api/plugins/{id}/access is gone, GET remains as the roster
No push after the write, unlike a connector grant: that one gates a runtime
snapshotted at login, while a plugin grant is re-read from plugin_access on
every request that depends on it (sidebar pages, /plugins/mine, and each
inbound channel message), so a revoke lands with no bus event.
Docs updated with where access is granted, and why mobile-connector is
absent from that list.
This commit is contained in:
@@ -1268,6 +1268,21 @@ mod tests {
|
||||
assert!(!plugin_access::has_access(&pool, "telegram", "u1").await.unwrap());
|
||||
assert_eq!(plugin_access::users_for_plugin(&pool, "telegram").await.unwrap(), vec!["u2"]);
|
||||
|
||||
// The Users-page write path: one user's grants across every plugin. A
|
||||
// blanket replace, and scoped to that user — u2's telegram grant stands.
|
||||
plugin_access::set_for_user(&pool, "u1", &["comfyui".to_string(), "honcho".to_string()])
|
||||
.await.unwrap();
|
||||
assert_eq!(
|
||||
plugin_access::plugin_ids_for_user(&pool, "u1").await.unwrap(),
|
||||
vec!["comfyui", "honcho"],
|
||||
);
|
||||
assert!(plugin_access::has_access(&pool, "telegram", "u2").await.unwrap());
|
||||
plugin_access::set_for_user(&pool, "u1", &["honcho".to_string()]).await.unwrap();
|
||||
assert_eq!(plugin_access::plugin_ids_for_user(&pool, "u1").await.unwrap(), vec!["honcho"]);
|
||||
plugin_access::set_for_user(&pool, "u1", &[]).await.unwrap();
|
||||
assert!(plugin_access::plugin_ids_for_user(&pool, "u1").await.unwrap().is_empty());
|
||||
assert!(plugin_access::has_access(&pool, "telegram", "u2").await.unwrap());
|
||||
|
||||
plugin_user_configs::set(&pool, "telegram", "u2", &serde_json::json!({"linked": true})).await.unwrap();
|
||||
assert_eq!(
|
||||
plugin_user_configs::get(&pool, "telegram", "u2").await.unwrap(),
|
||||
|
||||
@@ -83,8 +83,39 @@ pub async fn revoke(pool: &SqlitePool, plugin_id: &str, user_id: &str) -> Result
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// Replaces the full access list for a plugin in one shot (the admin UI's
|
||||
/// "who can use this" checklist).
|
||||
/// Replaces a user's full plugin-grant list in one shot — the Users-page form
|
||||
/// ("which plugins may this person use"), the per-user twin of
|
||||
/// [`super::mcp_catalog_access::set_for_user`].
|
||||
///
|
||||
/// A blanket replace is correct because the form is fed the **complete** set of
|
||||
/// grantable plugins: every registered plugin except the binding-managed ones
|
||||
/// (`Plugin::manages_own_access`), and those never read this table — their
|
||||
/// access is their own pairing — so clearing a stale row for one is a no-op.
|
||||
///
|
||||
/// Nothing has to be pushed after this write: unlike an MCP grant, which gates
|
||||
/// a runtime snapshotted at login, a plugin grant is re-read from here on every
|
||||
/// request and every inbound channel message, so a revoke takes effect at once.
|
||||
pub async fn set_for_user(pool: &SqlitePool, user_id: &str, plugin_ids: &[String]) -> Result<()> {
|
||||
let mut tx = pool.begin().await?;
|
||||
sqlx::query("DELETE FROM plugin_access WHERE user_id = ?")
|
||||
.bind(user_id)
|
||||
.execute(&mut *tx)
|
||||
.await?;
|
||||
for plugin_id in plugin_ids {
|
||||
sqlx::query("INSERT OR IGNORE INTO plugin_access (plugin_id, user_id) VALUES (?, ?)")
|
||||
.bind(plugin_id)
|
||||
.bind(user_id)
|
||||
.execute(&mut *tx)
|
||||
.await?;
|
||||
}
|
||||
tx.commit().await?;
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// Replaces the full access list for a plugin in one shot (the plugin-shaped
|
||||
/// twin of [`set_for_user`]). No UI writes through this any more — "who may use
|
||||
/// what" is edited on the user's page — but it is the honest inverse of the
|
||||
/// read model and the cheapest way to set a plugin's audience from a test.
|
||||
pub async fn set_access(pool: &SqlitePool, plugin_id: &str, user_ids: &[String]) -> Result<()> {
|
||||
let mut tx = pool.begin().await?;
|
||||
sqlx::query("DELETE FROM plugin_access WHERE plugin_id = ?")
|
||||
|
||||
Reference in New Issue
Block a user