From 4d5acf6f52f44f3f0cb07ea18cbe6ff9df0226ef Mon Sep 17 00:00:00 2001 From: Ruben Fiszel Date: Mon, 9 Jan 2023 16:07:29 +0100 Subject: [PATCH] creator of group is also automatically a member --- backend/windmill-api/src/groups.rs | 28 ++++++++++++++++++++++------ 1 file changed, 22 insertions(+), 6 deletions(-) diff --git a/backend/windmill-api/src/groups.rs b/backend/windmill-api/src/groups.rs index f4603db99a..937fe8b3cc 100644 --- a/backend/windmill-api/src/groups.rs +++ b/backend/windmill-api/src/groups.rs @@ -204,6 +204,16 @@ async fn create_group( .execute(&mut tx) .await?; + sqlx::query_as!( + Group, + "INSERT INTO usr_to_group (workspace_id, usr, group_) VALUES ($1, $2, $3) ON CONFLICT DO NOTHING", + &w_id, + &authed.username, + ng.name, + ) + .execute(&mut tx) + .await?; + audit_log( &mut tx, &authed.username, @@ -282,7 +292,9 @@ async fn delete_group( ) -> Result { let mut tx = user_db.begin(&authed).await?; - require_is_owner(&name, &authed.username, &authed.groups, &w_id, &db).await?; + if !authed.is_admin { + require_is_owner(&name, &authed.username, &authed.groups, &w_id, &db).await?; + } not_found_if_none(get_group_opt(&mut tx, &w_id, &name).await?, "Group", &name)?; sqlx::query!( @@ -321,8 +333,9 @@ async fn update_group( Json(eg): Json, ) -> Result { let mut tx = user_db.begin(&authed).await?; - - require_is_owner(&name, &authed.username, &authed.groups, &w_id, &db).await?; + if !authed.is_admin { + require_is_owner(&name, &authed.username, &authed.groups, &w_id, &db).await?; + } not_found_if_none(get_group_opt(&mut tx, &w_id, &name).await?, "Group", &name)?; sqlx::query_as!( @@ -357,8 +370,9 @@ async fn add_user( Json(Username { username: user_username }): Json, ) -> Result { let mut tx = user_db.begin(&authed).await?; - - require_is_owner(&name, &authed.username, &authed.groups, &w_id, &db).await?; + if !authed.is_admin { + require_is_owner(&name, &authed.username, &authed.groups, &w_id, &db).await?; + } not_found_if_none(get_group_opt(&mut tx, &w_id, &name).await?, "Group", &name)?; @@ -394,7 +408,9 @@ async fn remove_user( Json(Username { username: user_username }): Json, ) -> Result { let mut tx = user_db.begin(&authed).await?; - require_is_owner(&name, &authed.username, &authed.groups, &w_id, &db).await?; + if !authed.is_admin { + require_is_owner(&name, &authed.username, &authed.groups, &w_id, &db).await?; + } not_found_if_none(get_group_opt(&mut tx, &w_id, &name).await?, "Group", &name)?; if &name == "all" {