8000 fix: improve permissions checks in organization settings by aslilac · Pull Request #16849 · coder/coder · GitHub
[go: up one dir, main page]

Skip to content

fix: improve permissions checks in organization settings #16849

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 3 commits into from
Mar 7, 2025
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 16 additions & 5 deletions site/src/pages/GroupsPage/GroupsPage.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ import { Loader } from "components/Loader/Loader";
import { SettingsHeader } from "components/SettingsHeader/SettingsHeader";
import { Stack } from "components/Stack/Stack";
import { useFeatureVisibility } from "modules/dashboard/useFeatureVisibility";
import { RequirePermission } from "modules/permissions/RequirePermission";
import { type FC, useEffect } from "react";
import { Helmet } from "react-helmet-async";
import { useQuery } from "react-query";
Expand Down Expand Up @@ -54,16 +55,26 @@ export const GroupsPage: FC = () => {
return <Loader />;
}

const helmet = (
<Helmet>
<title>{pageTitle("Groups")}</title>
</Helmet>
);

const permissions = permissionsQuery.data?.[organization.id];
if (!permissions) {
return <ErrorAlert error={permissionsQuery.error} />;

if (!permissions?.viewGroups) {
return (
<>
{helmet}
<RequirePermission isFeatureVisible={false} />
</>
);
}

return (
<>
<Helmet>
<title>{pageTitle("Groups")}</title>
</Helmet>
{helmet}

<Stack
alignItems="baseline"
Expand Down
25 changes: 20 additions & 5 deletions site/src/pages/OrganizationSettingsPage/IdpSyncPage/IdpSyncPage.tsx 8000
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,7 @@ import { Link } from "components/Link/Link";
import { Paywall } from "components/Paywall/Paywall";
import { useFeatureVisibility } from "modules/dashboard/useFeatureVisibility";
import { useOrganizationSettings } from "modules/management/OrganizationSettingsLayout";
import { RequirePermission } from "modules/permissions/RequirePermission";
import { type FC, useEffect, useState } from "react";
import { Helmet } from "react-helmet-async";
import { useMutation, useQueries, useQuery, useQueryClient } from "react-query";
Expand All @@ -31,8 +32,7 @@ export const IdpSyncPage: FC = () => {
const { organization: organizationName } = useParams() as {
organization: string;
};
const { organizations } = useOrganizationSettings();
const organization = organizations?.find((o) => o.name === organizationName);
const { organization, organizationPermissions } = useOrganizationSettings();
const [groupField, setGroupField] = useState("");
const [roleField, setRoleField] = useState("");

Expand Down Expand Up @@ -80,6 +80,23 @@ export const IdpSyncPage: FC = () => {
return <EmptyState message="Organization not found" />;
}

const helmet = (
<Helmet>
<title>
{pageTitle("IdP Sync", organization.display_name || organization.name)}
</title>
</Helmet>
);

if (!organizationPermissions?.viewIdpSyncSettings) {
return (
<>
{helmet}
<RequirePermission isFeatureVisible={false} />
</>
);
}

const patchGroupSyncSettingsMutation = useMutation(
patchGroupSyncSettings(organizationName, queryClient),
);
Expand All @@ -103,9 +120,7 @@ export const IdpSyncPage: FC = () => {

return (
<>
<Helmet>
<title>{pageTitle("IdP Sync")}</title>
</Helmet>
{helmet}

<div className="flex flex-col gap-12">
<header className="flex flex-row items-baseline justify-between">
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ import { displayError, displaySuccess } from "components/GlobalSnackbar/utils";
import { Stack } from "components/Stack/Stack";
import { useAuthenticated } from "contexts/auth/RequireAuth";
import { useOrganizationSettings } from "modules/management/OrganizationSettingsLayout";
import { RequirePermission } from "modules/permissions/RequirePermission";
import { type FC, useState } from "react";
import { Helmet } from "react-helmet-async";
import { useMutation, useQuery, useQueryClient } from "react-query";
Expand Down Expand Up @@ -54,7 +55,7 @@ const OrganizationMembersPage: FC = () => {
const [memberToDelete, setMemberToDelete] =
useState<OrganizationMemberWithUserData>();

if (!organization || !organizationPermissions) {
if (!organization) {
return <EmptyState message="Organization not found" />;
}

Expand All @@ -66,6 +67,15 @@ const OrganizationMembersPage: FC = () => {
</Helmet>
);

if (!organizationPermissions) {
return (
<>
{helmet}
<RequirePermission isFeatureVisible={false} />
</>
);
}

return (
<>
{helmet}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ import { EmptyState } from "components/EmptyState/EmptyState";
import { useEmbeddedMetadata } from "hooks/useEmbeddedMetadata";
import { useDashboard } from "modules/dashboard/useDashboard";
import { useOrganizationSettings } from "modules/management/OrganizationSettingsLayout";
import { RequirePermission } from "modules/permissions/RequirePermission";
import type { FC } from "react";
import { Helmet } from "react-helmet-async";
import { useQuery } from "react-query";
Expand All @@ -15,7 +16,7 @@ const OrganizationProvisionersPage: FC = () => {
const { organization: organizationName } = useParams() as {
organization: string;
};
const { organization } = useOrganizationSettings();
const { organization, organizationPermissions } = useOrganizationSettings();
const { entitlements } = useDashboard();
const { metadata } = useEmbeddedMetadata();
const buildInfoQuery = useQuery(buildInfo(metadata["build-info"]));
Expand All @@ -25,16 +26,29 @@ const OrganizationProvisionersPage: FC = () => {
return <EmptyState message="Organization not found" />;
}

const helmet = (
<Helmet>
<title>
{pageTitle(
"Provisioners",
organization.display_name || organization.name,
)}
</title>
</Helmet>
);

if (!organizationPermissions?.viewProvisioners) {
return (
<>
{helmet}
<RequirePermission isFeatureVisible={false} />
</>
);
}

return (
<>
<Helmet>
<title>
{pageTitle(
"Provisioners",
organization.display_name || organization.name,
)}
</title>
</Helmet>
{helmet}
<OrganizationProvisionersPageView
showPaywall={!entitlements.features.multiple_organizations.enabled}
error={provisionersQuery.error}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,9 +7,12 @@ import { EmptyState } from "components/EmptyState/EmptyState";
import { displaySuccess } from "components/GlobalSnackbar/utils";
import { displayError } from "components/GlobalSnackbar/utils";
import { useOrganizationSettings } from "modules/management/OrganizationSettingsLayout";
import { RequirePermission } from "modules/permissions/RequirePermission";
import type { FC } from "react";
import { Helmet } from "react-helmet-async";
import { useMutation, useQueryClient } from "react-query";
import { useNavigate } from "react-router-dom";
import { pageTitle } from "utils/page";
import { OrganizationSettingsPageView } from "./OrganizationSettingsPageView";

const OrganizationSettingsPage: FC = () => {
Expand All @@ -24,36 +27,58 @@ const OrganizationSettingsPage: FC = () => {
deleteOrganization(queryClient),
);

if (!organization || !organizationPermissions?.editSettings) {
if (!organization) {
return <EmptyState message="Organization not found" />;
}

const helmet = (
<Helmet>
<title>
{pageTitle("Settings", organization.display_name || organization.name)}
</title>
</Helmet>
);

if (!organizationPermissions?.editSettings) {
return (
<>
{helmet}
<RequirePermission isFeatureVisible={false} />
</>
);
}

const error =
updateOrganizationMutation.error ?? deleteOrganizationMutation.error;

return (
<OrganizationSettingsPageView
organization={organization}
error={error}
onSubmit={async (values) => {
const updatedOrganization =
await updateOrganizationMutation.mutateAsync({
organizationId: organization.id,
req: values,
});
navigate(`/organizations/${updatedOrganization.name}/settings`);
displaySuccess("Organization settings updated.");
}}
onDeleteOrganization={async () => {
try {
await deleteOrganizationMutation.mutateAsync(organization.id);
displaySuccess("Organ F438 ization deleted");
navigate("/organizations");
} catch (error) {
displayError(getErrorMessage(error, "Failed to delete organization"));
}
}}
/>
<>
{helmet}
<OrganizationSettingsPageView
organization={organization}
error={error}
onSubmit={async (values) => {
const updatedOrganization =
await updateOrganizationMutation.mutateAsync({
organizationId: organization.id,
req: values,
});
navigate(`/organizations/${updatedOrganization.name}/settings`);
displaySuccess("Organization settings updated.");
}}
onDeleteOrganization={async () => {
try {
await deleteOrganizationMutation.mutateAsync(organization.id);
displaySuccess("Organization deleted");
navigate("/organizations");
} catch (error) {
displayError(
getErrorMessage(error, "Failed to delete organization"),
);
}
}}
/>
</>
);
};

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@ import { EmptyState } from "components/EmptyState/EmptyState";
import { TabLink, Tabs, TabsList } from "components/Tabs/Tabs";
import { useSearchParamsKey } from "hooks/useSearchParamsKey";
import { useOrganizationSettings } from "modules/management/OrganizationSettingsLayout";
import { RequirePermission } from "modules/permissions/RequirePermission";
import type { FC } from "react";
import { Helmet } from "react-helmet-async";
import { pageTitle } from "utils/page";
Expand All @@ -16,26 +17,32 @@ const ProvisionersPage: FC = () => {
});

if (!organization || !organizationPermissions?.viewProvisionerJobs) {
return <EmptyState message="Organization not found" />;
}

const helmet = (
<Helmet>
<title>
{pageTitle(
"Provisioners",
organization.display_name || organization.name,
)}
</title>
</Helmet>
);

if (!organizationPermissions?.viewProvisioners) {
return (
<>
<Helmet>
<title>{pageTitle("Provisioners")}</title>
</Helmet>
<EmptyState message="Organization not found" />
{helmet}
<RequirePermission isFeatureVisible={false} />
</>
);
}

return (
<>
<Helmet>
<title>
{pageTitle(
"Provisioners",
organization.display_name || organization.name,
)}
</title>
</Helmet>
{helmet}

<div className="flex flex-col gap-12">
<header className="flex flex-row items-baseline justify-between">
Expand Down
Loading
0