dorfteich/apps/api/src/grants/grants.controller.ts
Claude Fable 5 0c6494f209
All checks were successful
CD / Build and push images (push) Successful in 2m54s
CI / Lint, typecheck, test (push) Successful in 2m25s
CI / Auth e2e pack (push) Successful in 2m58s
CI / Build container images (push) Has been skipped
CD / Deploy to Test (push) Successful in 9s
CD / Smoke tests against Test (push) Successful in 1m12s
CD / Promote to Int (push) Successful in 12s
Enforce permissions in API guards and retire interim access (#52)
Every route now declares its access rule explicitly and is enforced
through the shared resolution algorithm (permissions.md):

- PermissionGuard + decorators (@RequiresPondRole, @RequiresPagePermission,
  @RequiresAttachmentPermission, @AuthenticatedOnly) applied to every
  route; a route-enumeration test proves full coverage alongside
  @Public()/Site-Admin-guarded routes.
- 404/403 policy (documented in README conventions): denied reads answer
  404 (existence hiding), denied writes on readable things answer 403;
  trash views need write capability (ADR 0013).
- PermissionService resolves page/pond questions via the shared resolver,
  with an in-process pond-context cache (grants + label parents) that is
  invalidated on every grant/label-tree change and TTL-bounded as a
  multi-process safety net. Grant changes also fire pond_access_changed
  for collab revalidation (#39/#53).
- shared: pond-scope resolution (hasPondRole, canSeePond) next to the
  page resolver; grant wire schemas + GrantView.
- Owner Pond-Admin grants: migration backfill for all existing ponds,
  created transactionally with every new pond (shared + personal + seed).
- Grant CRUD under /ponds/:id/grants (pond_admin-gated) with structural
  and referential validation, last-admin protection, audit logs.
- InterimAccessService deleted; page lists, search, backlinks, phantom
  links, and trash listings are filtered per page through the resolver;
  collab tokens are now truly ro for readers.
- Fixture-matrix e2e (reader/editor/pond admin/foreign, label-deny,
  authenticated-subject, revoke-then-immediate-deny cache test).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PGdhRiwU1WRL4XxJfZYipY
2026-07-09 16:31:41 +02:00

50 lines
1.6 KiB
TypeScript

import { Body, Controller, Delete, Get, HttpCode, Param, Post, Req } from '@nestjs/common';
import {
CreateGrantInput,
GrantView,
createGrantInputSchema,
grantOfInput,
} from '@dorfteich/shared';
import { AuthedRequest } from '../auth/auth.guard';
import { ZodValidationPipe } from '../common/zod-validation.pipe';
import { RequiresPondRole } from '../permissions/permission.decorators';
import { GrantsService } from './grants.service';
/**
* Grant management (issue #52): a pond's grants are its Pond Admins'
* business — members and their roles (permissions.md). The member-management
* UI on top of this arrives with #54.
*/
@Controller('ponds/:pondId/grants')
export class GrantsController {
constructor(private readonly grants: GrantsService) {}
@Get()
@RequiresPondRole('pond_admin', { idParam: 'pondId' })
async list(@Param('pondId') pondId: string): Promise<GrantView[]> {
return this.grants.listGrants(pondId);
}
@Post()
@RequiresPondRole('pond_admin', { idParam: 'pondId' })
async create(
@Param('pondId') pondId: string,
@Body(new ZodValidationPipe(createGrantInputSchema)) input: CreateGrantInput,
@Req() request: AuthedRequest,
): Promise<GrantView> {
return this.grants.createGrant(request.user!, pondId, grantOfInput(input));
}
@Delete(':grantId')
@HttpCode(204)
@RequiresPondRole('pond_admin', { idParam: 'pondId' })
async remove(
@Param('pondId') pondId: string,
@Param('grantId') grantId: string,
@Req() request: AuthedRequest,
): Promise<void> {
await this.grants.deleteGrant(request.user!, pondId, grantId);
}
}