Skip to content

feat: PPT-526 scope tenant administration to the caller's organisations - #390

Draft
camreeves wants to merge 2 commits into
masterfrom
PPT-526-tenancy
Draft

camreeves wants to merge 2 commits into
masterfrom
PPT-526-tenancy

Conversation

@camreeves

Copy link
Copy Markdown
Contributor

staff-api half of multi-tenancy (under PPT-526). Pairs with PlaceOS/models#332 and PlaceOS/rest-api#451. Draft until the set has been through a clean install on the test cluster.

What this does

Tenant administration stays inside the caller's organisations. Today an admin on any domain lists and edits every tenant on the cluster.

  • Utils::Tenancy resolves the caller's reach the same way rest-api does (management partner staff: everything; a partner's staff organisation: that partner's organisations; otherwise the caller's own organisation; live grants widen it) and expresses it as the hostnames of the domains in reach.
  • GET /tenants lists only tenants on those domains. Show, update, delete, limits and early-checkin routes answer 404 for a tenant on a domain outside reach, so foreign ids look unknown. Create refuses a domain outside reach.
  • The current_* routes, bookings, events and guests are untouched: they were already scoped by the request's domain.
  • PLACE_TENANCY_ENFORCE (default off) switches between refusing and logging, as in rest-api.

Verification

  • spec/controllers/tenants_scope_spec.cr: a domain with no organisation reaches nothing; management staff reach every tenant; an ordinary organisation's admin lists, reads, edits and creates only on its own domains; a grant into another organisation widens reach.
  • The existing tenants spec is unchanged and runs with enforcement off.

Plan: https://gist.github.com/camreeves/3fabfff92bcdef77a1dcb4b8d8ebfe7b

@github-actions github-actions Bot added the type: enhancement new feature or request label Oct 7, 2026
Resolve the caller's reach the way rest-api does and keep the tenants list,
lookups and creates inside it. PLACE_TENANCY_ENFORCE switches between
refusing and logging. Builds against the models tenancy branch until
models #332 merges.
@github-actions github-actions Bot added type: enhancement new feature or request and removed type: enhancement new feature or request labels Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type: enhancement new feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant