Repository navigation
Conversation
Resolve the caller's reach the way rest-api does and keep the tenants list, lookups and creates inside it. PLACE_TENANCY_ENFORCE switches between refusing and logging. Builds against the models tenancy branch until models #332 merges.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
staff-api half of multi-tenancy (under PPT-526). Pairs with PlaceOS/models#332 and PlaceOS/rest-api#451. Draft until the set has been through a clean install on the test cluster.
What this does
Tenant administration stays inside the caller's organisations. Today an admin on any domain lists and edits every tenant on the cluster.
Utils::Tenancyresolves the caller's reach the same way rest-api does (management partner staff: everything; a partner's staff organisation: that partner's organisations; otherwise the caller's own organisation; live grants widen it) and expresses it as the hostnames of the domains in reach.GET /tenantslists only tenants on those domains. Show, update, delete, limits and early-checkin routes answer 404 for a tenant on a domain outside reach, so foreign ids look unknown. Create refuses a domain outside reach.current_*routes, bookings, events and guests are untouched: they were already scoped by the request's domain.PLACE_TENANCY_ENFORCE(default off) switches between refusing and logging, as in rest-api.Verification
spec/controllers/tenants_scope_spec.cr: a domain with no organisation reaches nothing; management staff reach every tenant; an ordinary organisation's admin lists, reads, edits and creates only on its own domains; a grant into another organisation widens reach.Plan: https://gist.github.com/camreeves/3fabfff92bcdef77a1dcb4b8d8ebfe7b